Royco Day
Total reward
$30,000
No deposit required
Status
Live
Findings submitted
10
Start date
10 Aug 2026
End date
17 Aug 2026
KYC
Required to join
Royco is a non-custodial yield structuring protocol that splits any yield source into Senior, Junior, and Senior Liquidity Provider tranches, letting depositors choose their risk and liquidity profile.
- Senior Tranche (ST): earns the least yield but benefits from seniority and secondary liquidity.
- Junior Tranche (JT): earns the highest yield by serving as first-loss capital and receives a risk premium paid by Senior, in addition to the base asset yield.
- Senior Liquidity Provider (SLP): earns a premium and trading fees by providing secondary liquidity for the Senior tranche.
Yield flows from the ST to both JT and SLP, paying for Senior's coverage and liquidity.
Prize Distribution and Scoring
-
Total Prize Pool: $30,000
-
The prize distribution has 2 possible triggers:
- If one or more valid Medium severity findings are found, the total pot size is $7,500
- If one or more valid High severity findings are found, the total pot size is $30,000
-
Only High and Medium findings will be considered for the rewards
-
This competition will be judged by Cantina-appointed judges, follow the standard judging rules.
-
Scoring described in the competition scoring page.
-
Findings Severities described in detail on our docs page.
Documentation
Scope
- Repository: roycoprotocol/royco-day
- Commit:
fa6d24971a5b1993e4d067fc223c85c8139346c0 - Files: the
src/directory
In-Scope Impacts
- Funds sent to non-whitelisted addresses, or to addresses not specified by whitelisted addresses
- Funds permanently locked / unrecoverable
Build Instructions
forge buildMandatory POC Rule
- The mandatory POC rule applies to this competition.
- All Critical/High/Medium findings require a valid coded POC before the end of the competition.
Out of Scope
- Previous security reports
- Expected behaviors such as trusted/untrusted roles and/or any accepted risks
- Automated findings by Lightchaser
- Oracle, NAV, or share price manipulation
- Whitelisted parties behaving maliciously (assumed trusted, funds recoverable)
- Incorrect amounts sent to whitelisted parties or their specified recipients (reversible)
- External protocol bugs
- Centralization risks
- MEV, gas griefing, frontrunning
- Frontend or off-chain components
Previous Audits
Prior security reviews of this codebase are available in the audit/ directory of the repository. Issues already reported in these reviews are out of scope.
- Tomer Security first report — TBD
Contact Us
For any issues or concerns regarding this competition, please reach out to the Cantina core team through the Cantina Discord.