Disclosure process
- Safely disclose issue and applicable proof-of-concept or steps for reproduction to security@audius.co
- We determine severity of issue together, following informal CVSS guidelines (example), producing classification (low, medium, high, critical)
- Bounty is paid out
- Fix is produced, rolled out, and reporter can disclose issue publicly
- We produce & publish documentation of issue
Bounty
Smart Contracts (Ethereum, Solana)
- "Critical" - Please Contact Our Team
- "High" - $20,000+
- "Medium" - $5,000
- "Low" - $0 - $1,000
Websites & Apps
- "Critical" - $5,000
- "High" - $2,000
- "Medium" - $500
- "Low" - $0 - $100
Smart Contract Assets
- Registry: 0xd976d3b4f4e22a238c1A736b6612D22f17b6f64C
- Token: 0x18aAA7115705e8be94bfFEBDE57Af9BFc265B998
- Governance: 0x4DEcA517D6817B6510798b7328F2314d3003AbAC
- Staking: 0xe6D97B2099F142513be7A2a068bE040656Ae4591
- DelegateManager: 0x4d7968ebfD390D5E7926Cb3587C39eFf2F9FB225
- ClaimsManager: 0x44617F9dCEd9787C3B06a05B35B4C779a2AA1334
- ServiceTypeManager: 0x9EfB0f4F38aFbb4b0984D00C126E97E21b8417C5
- ServiceProviderFactory: 0xD17A9bc90c582249e211a4f4b16721e7f65156c8
- EthRewardsManager: 0x5aa6B99A2B461bA8E97207740f0A689C5C39C3b0
- WormholeClient: 0x6E7a1F7339bbB62b23D44797b63e4258d283E095
- TrustedNotifierManager: 0x6f08105c8CEef2BC5653640fcdbBE1e7bb519D39
- Claimable Tokens: Ewkv3JahEFRKkcJmpoKB7pXbnUHwjAyXiwEo4ZY2rezQ
- Rewards Manager: DDZDcYdQFEMwcu2Mwo75yGFjJ1mUQyyXLWzhZLEVFcei
Not eligible for reward
- Third-party applications that use Audius APIs
- XSS requiring legacy browsers
- Self-XSS
- SSL/TLS best practices
- Missing HTTP header which does not lead to a direct vulnerability
- Missing cookie flags, unless the absence can be abused by a legitimate workflow
- Clickjacking without demonstration of impact
- Account enumeration through brute-force attacks
- CSV command execution
- Best practice recommendations with no proof-of-concept
- Token reuse, password poisoning, or account revocation with regard to the documented security considerations in Hedgehog
- Any denial of service attacks