Lithium Finance · Vulnerability Disclosure
Lith Vulnerability Disclosure
Vulnerability disclosure
Lithium Finance runs a coordinated vulnerability disclosure program on Hackerone.
CompanyCryptoDeFiOraclesNFTAsset ValuationSmart ContractsMachine-LearningDAOBlockchain
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-07-19'
method: searched
source: https://lith.finance/docs-sub/guides/bug-bounty
program: Lithium Finance Bug Bounty
scope_type: smart-contracts
policy:
- https://lith.finance/docs-sub/guides/bug-bounty
contact: []
contact_note: >-
The published program does not name a disclosure email or a third-party
platform (no HackerOne/Bugcrowd/Immunefi listing found). Reports are directed
through the project's own channels (Discord/Telegram).
scope:
description: >-
Vulnerabilities and bugs in the Lithium smart contracts, with primary
interest in preventing loss of user funds — either direct draining of locked
funds or social-engineering attacks that redirect users or force them to sign
a transaction.
repository: https://github.com/Lithium-Finance/lithium-smart-contracts
severity_scale:
- level: Critical
reward_usd: 1000
definition: >-
Issues that could impact numerous users and have serious reputational, legal
or financial implications (e.g. permanently locking contracts or taking funds
from all users).
- level: High
reward_usd: 500
definition: >-
Issues that impact individual users where exploitation would pose
reputational, legal or moderate financial risk to the user.
- level: Medium
reward_usd: 200
definition: >-
Issues where the risk involved is relatively small and does not pose a threat
to user funds.
- level: Low/Informational
reward_usd: 0
definition: >-
Issues that do not pose an immediate risk but are relevant to security best
practices.
rewards:
currency: LITH or USDT
max_usd: 1000
cap_rule: >-
Final reward for critical smart-contract vulnerabilities is capped at 10% of
the funds at risk based on the vulnerability reported.
risk_rating_methodology: OWASP risk rating methodology
requirements:
- All bug reports must include a Proof of Concept demonstrating how the vulnerability
can be exploited to be eligible for a reward.
out_of_scope:
- Attacks the reporter has already exploited themselves, leading to damage
- Attacks requiring access to leaked keys/credentials
- Attacks requiring access to privileged addresses (governance, strategist)
- Incorrect data supplied by third-party oracles
- Basic economic governance attacks (e.g. 51% attack)
- Lack of liquidity
- Best practice critiques
- Sybil attacks
prohibitions:
- Any testing with mainnet or public testnet contracts
evidence:
- source: https://lith.finance/docs-sub/guides/bug-bounty
kind: bug-bounty-policy
status: 200
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lith-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.