Get ready for a new audit competition with Raft Finance! Up to $80K in prizes

1 year ago 33
BOOK THIS SPACE FOR AD
ARTICLE AD

Starting May 11, 2023, 18:00:00 GMT, to May 18, 2023, 18:00:00 GMT.

HatsFinance

Join our global hunt for Raft finance! Spot the bug and win a juicy reward 🤑

We welcome all experience levels; whether you are a seasoned security veteran or amateur, show us what you got! Prizes will be given based on the severity level of each vulnerability found.

About the Competition

Starting May 11, a new vault will open in the Hats dApp — “Raft finance Audit competition”. Participants can check the contracts in scope and start searching for bugs.

Raft is an immutable and decentralized lending protocol that allows people to take stablecoin loans against capital-efficient collateral. Raft’s first stablecoin is called R.

Stay up-to-date with the competition, chat with the team, and get your questions answered by joining the dedicated Discord channel on the Hats server. All audit reports will be published in our Discord on the day of the competition. Don’t miss the latest updates and insights — join now and be the first to know!

High Severity:

The total prize pool for High severities will be ~$60K USDC. The total High severity reward will be divided between all accepted issues. However, there is a max reward cap of $15k for a single high submission; each new issue gets 1 point.

For a submission to be considered a HIGH-risk vulnerability:
High-severity vulnerability description:

Issues that lead to the loss of user funds. Such issues include:

- Direct theft of any user funds, whether at rest or in motion

- Long-term freezing of user funds

- Theft or long-term freezing of unclaimed yield or other assets

- Protocol insolvency

Medium Severity:

The total prize pool of Medium severity will be ~$16K USDC. Each new issue gets 1 point. The total Medium severity reward will be divided between all accepted issues.

Medium severity vulnerability description:

Issues that lead to an economic loss but do not lead to direct loss of on-chain assets. Examples are:

Gas griefing attacks (make users overpay for gas)Attacks that make essential functionality of the contracts temporarily unusable or inaccessibleShort-term freezing of user funds

Low severity:

The total prize pool of Low severity will be ~$2K USDC. Each new issue gets 1 point. The total Low severity reward will be divided between all accepted issues.

Low severity vulnerability description:

Issues where the behavior of the contracts differs from the intended behavior (as described in the docs and by common sense), but no funds are at risk.

Gas Saving:

The total prize pool of Gas Saving severity will be ~$2K USDC.

This competition will reward participants with ideas to maximize gas savings.

- 50% of the Gas saving severity reward is for gas optimization on `managePosition` function in `PositionManager` contract.- 50% of the Gas saving severity reward is for gas optimization on `liquidation` function in `PositionManager` contract (the prize will get the best optimization for each of these two, and we accept only if it is 5% better than the current)The guidelines are as follows:

- Submissions should be forks of our repository, with the test suite unchanged.

- Optimizations should use solidity (no inline assembly)

- Entries will be measured on the total average amount of gas used for each function (i.e., the sum of all numbers in the “avg” column), as reported by the hardhat-gas-reporter when running the tests in the repository.

Reporters will not receive a bounty for any known issue, such as:

Issues mentioned in any previous audit reportsVulnerabilities that were already made public (either by HATs or by a third party)“Centralization risks” that are known and/or explicitly coded into the protocol (e.g. an administrator can upgrade crucial contracts and steal all funds)Attacks that require access to leaked private keys or trusted addressesIssues that are not responsibly disclosed (issues should typically be reported through our platform)

Submission Guidelines — High/Medium/Low severities:

SUBMISSION GUIDELINES:

Submissions should be made using our dApp in the “Raft finance audit competition” vault.You can submit one on-chain submission mentioning all issues found on the repo.Please send a plain ASCII following the following format:

[TITLE]: a short description of the issue.
SEVERITY (either High, Medium or Low; see the rules)
[A LINK TO THE GITHUB ISSUE]
— A concise GitHub issue describing the problem should be created in the project repository -> The repo will be open during the competition. (https://github.com/tempusfinance/raft-contracts/releases/tag/hatsfinance-audit-1)

- Submission should contain a PR (linked to the issue) with at least one test demonstrating the problem and, if possible, a possible fix.

The title should match the title of the on-chain submission in the Dapp.
GitHub submission:
Description — Describe the context and the effect of the vulnerability.
Attack scenario — Describe how the vulnerability can be exploited.

Attachment -

Proof of Concept (PoC) File: You must provide a file containing a proof of concept (PoC) that demonstrates the vulnerability you have discovered.Revised Code File (Optional): If possible, please provide a second file containing the revised code that offers a potential fix for the vulnerability. This file should include the following information:Comment with a clear explanation of the proposed fix.The revised code with your suggested changes.Any additional comments or explanations that clarify how the fix addresses the vulnerability.

Recommendation — Describe a patch or a potential fix for the vulnerability.

*Due to the native of the audit competition mechanism, the report will not be encrypted.

Evaluation of Audit Competition

Each eligible bug submission receives 1 point in their severity category. Based on the number of eligible submissions, prize pools are divided.
Important note: A Max reward cap of $15k for a single High severity submission only.
For example, suppose there is 1 high-severity issue and 3 medium-severity issues. In that case, submitters of the medium-severity vulnerabilities will be awarded $5.3K each and the submitter of the high-severity vulnerability gets $15k.

Evaluation:

The first participant to submit an issue following guidelines gets a bounty for that issue (issues already received or out of scope will not receive a reward)The competition starts on May 11 at 18:00 GMT and ends on May 18 at 18:00 GMT.Issues that we are aware of (as witnessed by any open issues in the repository) will not be eligible for the bug bounty.

Compensation and Impact

A prize pool of $80K USDC and NFT rewards from our hacker collection will be distributed among security researchers who submit eligible vulnerability disclosures.

Compensation payment timeline:

Ten days after the competition ends, we will announce a winner list.Alongside the winner announcement post, submitters can send disputes to the committee team and request clarification. They can also involve the Hats security team in the process. The goal is to facilitate honest and professional debate regarding disputed submissions.Between 7–14 days after the announcement, we will publish a split contract where the winners can claim their rewards.

Security researchers play a crucial role in fostering trust and confidence in web3 technologies, paving the way for mass adoption. By participating in this competition, security researchers can gain recognition for their work, raise their profile, and make valuable connections in the web3 security ecosystem. Ultimately, they can contribute to creating a more secure and equitable community.

Join the Raft finance Audit Competition today and be a part of the movement to secure the future of web3 and decentralized finance. Check the Hats Finance dApp for more information and in-scope contracts.

Stay tuned and check Hats dApp: https://app.hats.finance/vaults

Read Entire Article