Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug Bounty: up to 50 ETH] Reality.eth v2 #34

Open
clesaege opened this issue Feb 13, 2021 · 0 comments
Open

[Bug Bounty: up to 50 ETH] Reality.eth v2 #34

clesaege opened this issue Feb 13, 2021 · 0 comments

Comments

@clesaege
Copy link
Member

This is a deployed contract, do not post potential vulnerabilities there unless we give you the permission to or formally reject your vulnerability.

Reality.eth

This is a bug bounty on the Reality.eth contract.
Bugs are rewarded up to 50 ETH according to this classification:

  • Critical Bugs: 50 ETH
    for bugs with a high likelihood of allowing an attacker to make the oracle return the wrong answer.
  • Major Bugs: 25 ETH
    for bugs that can lock a non negligible amount user funds or enable stealing a non negligible amount of user funds.
  • Minor Bugs: 2 ETH
    for smaller bugs which can still produce a non negligible amount of harm to users.

Issues which do not result in a contract redeployment can only be classified as minor.

If you find a bug you can send a mail to [email protected]. In case of dispute about the classification of a bug, Kleros will be used to solve it.

Reality.eth

Reality.eth is a crowd-sourced on-chain smart contract oracle system by Reality Keys.
You can find the documentation there. Note that some parts of the documentation may only apply to the previous version of Reality.eth.

This contract is deployed on the xDAI chain.

Bounty

Bounty Rules

  • If you have any questions, don't hesitate to ask on the slack channel (slack.kleros.io #smart-contract-review) or by sending a mail to [email protected] .
  • This bounty may be advertised on multiple platforms. Bounties are only awarded to the first person finding the bug irrespective of the platform.
  • Posting vulnerabilities publicly, even on this github, before being allowed or having your vulnerability formally rejected is forbidden and would void your claim for rewards.
  • Good luck and have fun hunting!
  • Note that we are aware that the variables storing time are uint32 and a new version will need to be redeployed before the end of the century.

Extra info

Extra information are given for informational purpose. This allows you to see the bigger picture of what the contract is made for.

  • Frontend, be sure to be connected to the xDAI network.
  • Omen, a prediction market relying on the reality.eth oracle. Be sure to be connected to the xDAI network.
  • Kleros connectors to arbitrate on Reality.eth disputes. Connector on xDAI and connector on mainnet. Those have their separate bounty.
@clesaege clesaege pinned this issue Feb 13, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant