Bug Bounty
Guidelines
Ethical Standards
The Ethos bug bounty aligns with our mission to reward ethical behavior. Although we outline guidelines and rules, the ultimate consideration in our bug bounty program will be: did you behave ethically?
We cannot foresee every possibility, and although security researchers are the best at breaking rules, we reserve the right to deny or reduce participation or benefits due to ethical concerns.
Specifically:
Adhere to ethical standards and legal guidelines. Any actions that compromise the integrity, privacy, or availability of systems beyond what is necessary for testing are strictly prohibited.
No harm: Ensure that your testing does not negatively impact users or infrastructure.
Do not threaten, blackmail, dox, or otherwise create a negative environment for Ethos staff or users.
Do not communicate with the Ethos staff or users outside of designated vulnerability reporting channels.
Bug bounty reward edibility is ultimately up to the discretion of Ethos staff and any bug bounty management services.
Scope and Testing Environment
Web Services
When possible, conduct tests in test environments.
Full Denial of Service attacks are prohibited against app.ethos.network.
Avoid testing with external dependencies and third-party systems not controlled by Ethos, such as:
Twitter / X
Cloudflare
Intercom
Alchemy
Moralis
Notify Ethos staff if you will be conducting tests that may lead to increased load. If your tests increase infrastructure costs or cause Ethos to hit API rate limits, then this is sufficient reason to disqualify any bug bounty rewards.
web
app.ethos.network
echo
api.ethos.network
markets
ethos.markets
Smart Contracts
Replicating tests on public mainnet is prohibited. All testing should be conducted on local forks of either testnet or mainnet. If necessary, notify the Ethos team before testing on base sepolia.
Responsible Disclosure
Do not publicly disclose vulnerabilities before they are resolved.
Do not discuss (publicly or otherwise) any aspect of a submitted vulnerability before resolution.
Use private, official reporting channels to submit your findings. Ie, Ethos public discord does not qualify.
Never exploit a vulnerability or threaten to do so.
Do not attempt to rescue funds without explicit written consent.
Publicly known bugs or bugs reported in a previous audit are not eligible.
Do not try to cajole Ethos regarding severity or payment.
You may publish details about your submission after resolution or a maximum of 30 days.
Report a Vulnerability
Address urgent issues or questions to: [email protected]
Submissions must include:
Clear explanation of the vulnerability
Reproduction instructions or working Proof of Concept (PoC)
Impact assessment on users and platform
One vulnerability per report
English language only
Rewards and Disputes
Web Services
Critical
$1,000 USD
High
$500 USD
Medium
$50 USD
Low / Info
Positive Ethos Review
Severity and resolution are strictly determined by the Ethos team. Payment can be made in either FIAT or USDC/USDT.
Smart Contracts
Critical - Contract Drain
10% of contract value
High - Financial Impact
$5,000 USD
Medium - Data Integrity
$250 USD
Low / Info
Positive Ethos Review
Eligibility and Scoring
Web Services
Critical severity findings include:
Disclosure of Ethos application Attestation signature private keys
Trigger transactions, intercept, drain, withdraw, or otherwise impact user funds
High severity findings include:
Redirect users to invalid Ethereum addresses prior to submitting a transaction
Cause users to attest invalid social media or external accounts, or take over existing attestations (without compromising the underlying account)
Force users to vouch for you or others
Medium severity findings include:
Claim XP for social media accounts you do not control
Force users to review you or others
Low / Info severity findings include:
Anything that impacts the generation or calculation of score or XP
The following issues are considered 'known' and ineligible for rewards.
Smart Contracts
Critical severity
Complete loss of contract balance funds without limitations or external conditions
High severity
Definite and significant loss of funds without limitations of external conditions
Definite and significant freezing of funds for >1 year without limitations of external conditions
Medium severity
Loss of user funds under specific circumstances
Freezing of funds for >1 month
Modification of user submitted data, such as review titles.
Low/Info severity
Anything that requires special circumstances such as a rogue admin, long period of time,
The following issues are considered 'known' and are ineligble for rewards.
Safe Harbor
Ethos will adhere to "safe harbor" protections; we will not pursue legal action against known ethical security researchers ("whitehats") attempting to defend Ethos against active exploitation. To qualify for safe harbor protections, notify Ethos of your intent and what attack you are defending against by notifying us at [email protected] and we will confirm safe harbor status.
Note: without written acknowledgement from Ethos staff, safe harbor is not guaranteed.
Ethos requires that you return 90% of recovered funds within 24 hours to qualify for Safe Harbor protections. Recovered funds may be transferred to 0x9C98258da66Ed095948CE4774e541C9FE978e946
Last updated