Lithium Finance · Vulnerability Disclosure

Lith Vulnerability Disclosure

Vulnerability disclosure

Lithium Finance runs a coordinated vulnerability disclosure program on Hackerone.

CompanyCryptoDeFiOraclesNFTAsset ValuationSmart ContractsMachine LearningDAOBlockchain
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

lith-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-19'
method: searched
source: https://lith.finance/docs-sub/guides/bug-bounty
program: Lithium Finance Bug Bounty
scope_type: smart-contracts
policy:
- https://lith.finance/docs-sub/guides/bug-bounty
contact: []
contact_note: >-
  The published program does not name a disclosure email or a third-party
  platform (no HackerOne/Bugcrowd/Immunefi listing found). Reports are directed
  through the project's own channels (Discord/Telegram).
scope:
  description: >-
    Vulnerabilities and bugs in the Lithium smart contracts, with primary
    interest in preventing loss of user funds — either direct draining of locked
    funds or social-engineering attacks that redirect users or force them to sign
    a transaction.
  repository: https://github.com/Lithium-Finance/lithium-smart-contracts
severity_scale:
- level: Critical
  reward_usd: 1000
  definition: >-
    Issues that could impact numerous users and have serious reputational, legal
    or financial implications (e.g. permanently locking contracts or taking funds
    from all users).
- level: High
  reward_usd: 500
  definition: >-
    Issues that impact individual users where exploitation would pose
    reputational, legal or moderate financial risk to the user.
- level: Medium
  reward_usd: 200
  definition: >-
    Issues where the risk involved is relatively small and does not pose a threat
    to user funds.
- level: Low/Informational
  reward_usd: 0
  definition: >-
    Issues that do not pose an immediate risk but are relevant to security best
    practices.
rewards:
  currency: LITH or USDT
  max_usd: 1000
  cap_rule: >-
    Final reward for critical smart-contract vulnerabilities is capped at 10% of
    the funds at risk based on the vulnerability reported.
  risk_rating_methodology: OWASP risk rating methodology
requirements:
- All bug reports must include a Proof of Concept demonstrating how the vulnerability
  can be exploited to be eligible for a reward.
out_of_scope:
- Attacks the reporter has already exploited themselves, leading to damage
- Attacks requiring access to leaked keys/credentials
- Attacks requiring access to privileged addresses (governance, strategist)
- Incorrect data supplied by third-party oracles
- Basic economic governance attacks (e.g. 51% attack)
- Lack of liquidity
- Best practice critiques
- Sybil attacks
prohibitions:
- Any testing with mainnet or public testnet contracts
evidence:
- source: https://lith.finance/docs-sub/guides/bug-bounty
  kind: bug-bounty-policy
  status: 200