Security
The security of Auctus protocol is our highest priority. To ensure top-notch security, Auctus protocol smart contracts were audited by Open Zeppelin and have undergone rigorous internal testing. We also have an ongoing bug bounty program where community members can report any bugs or vulnerabilities.
Audits
ACO has completed a full audit with Open Zeppelin. The link to the audit report can be found below.
Bug Bounty
The bug bounty covers any of the core smart contracts deployed on mainnet. The code can be found at: https://github.com/AuctusProject/aco
Rewards
The bounty program will pay out rewards according to the severity of a vulnerability. The final reward amount is at the sole discretion of Auctus.
Reward | Severity | Examples |
$5,000 - $15,000 | Critical |
|
$2,000 - $5,000 | High |
|
$1,000 - $2,000 | Medium |
|
$0 - $1,000 | Low |
|
Reporting / Disclosures
Please report any findings only to contact@auctus.org with full details about any vulnerability and steps / code to reproduce. Allow us time to review and remediate any findings before public disclosure.
Ineligible Findings
Duplicate vulnerabilities. Only the first reporter will be rewarded.
Findings already known as part of a formal audit
Front end bugs;
DDOS attack;
Spamming;
Automated tools
Compromising or misusing third party systems or services.
Last updated