Lithium Finance · Vulnerability Disclosure

Lith Vulnerability Disclosure

Vulnerability disclosure

Lithium Finance runs a coordinated vulnerability disclosure program on Hackerone.

CompanyCryptoDeFiOraclesNFTAsset ValuationSmart ContractsMachine-LearningDAOBlockchain
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

lith-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
source: https://lith.finance/docs-sub/guides/bug-bounty
program: Lithium Finance Bug Bounty
scope_type: smart-contracts
policy:
- https://lith.finance/docs-sub/guides/bug-bounty
contact: []
contact_note: >-
  The published program does not name a disclosure email or a third-party
  platform (no HackerOne/Bugcrowd/Immunefi listing found). Reports are directed
  through the project's own channels (Discord/Telegram).
scope:
  description: >-
    Vulnerabilities and bugs in the Lithium smart contracts, with primary
    interest in preventing loss of user funds — either direct draining of locked
    funds or social-engineering attacks that redirect users or force them to sign
    a transaction.
  repository: https://github.com/Lithium-Finance/lithium-smart-contracts
severity_scale:
- level: Critical
  reward_usd: 1000
  definition: >-
    Issues that could impact numerous users and have serious reputational, legal
    or financial implications (e.g. permanently locking contracts or taking funds
    from all users).
- level: High
  reward_usd: 500
  definition: >-
    Issues that impact individual users where exploitation would pose
    reputational, legal or moderate financial risk to the user.
- level: Medium
  reward_usd: 200
  definition: >-
    Issues where the risk involved is relatively small and does not pose a threat
    to user funds.
- level: Low/Informational
  reward_usd: 0
  definition: >-
    Issues that do not pose an immediate risk but are relevant to security best
    practices.
rewards:
  currency: LITH or USDT
  max_usd: 1000
  cap_rule: >-
    Final reward for critical smart-contract vulnerabilities is capped at 10% of
    the funds at risk based on the vulnerability reported.
  risk_rating_methodology: OWASP risk rating methodology
requirements:
- All bug reports must include a Proof of Concept demonstrating how the vulnerability
  can be exploited to be eligible for a reward.
out_of_scope:
- Attacks the reporter has already exploited themselves, leading to damage
- Attacks requiring access to leaked keys/credentials
- Attacks requiring access to privileged addresses (governance, strategist)
- Incorrect data supplied by third-party oracles
- Basic economic governance attacks (e.g. 51% attack)
- Lack of liquidity
- Best practice critiques
- Sybil attacks
prohibitions:
- Any testing with mainnet or public testnet contracts
evidence:
- source: https://lith.finance/docs-sub/guides/bug-bounty
  kind: bug-bounty-policy
  status: 200

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lith-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.