infinifi-protocol
Bounty Range
$15,000 - $100,000
external program
Bounty Range
$15,000 - $100,000
external program
infiniFi is building the future of decentralized finance by recreating modern banking infrastructure—on-chain. By merging liquid and illiquid assets into a capital-efficient system with transparent fractional reserves, infiniFi delivers superior yields to depositors without increasing systemic risk. Founded in 2024, infiniFi is backed by top Web3 investors and is integrated with major protocols like AAVE, Pendle, and Ethena.
No Unauthorized Testing on Production Environments: Do not test vulnerabilities on mainnet or public testnet deployments without prior authorization. Use local test environments or private test setups.
No Public Disclosure Without Consent: Do not publicly disclose details of any vulnerability before it has been addressed and you have received written permission to disclose.
No Exploitation or Data Exfiltration: Do not exploit the vulnerability beyond the minimum steps necessary to demonstrate the issue. Do not access private data, engage in social engineering, or disrupt service.
No Conflict of Interest: Individuals currently or formerly employed by Infinifi, or those who contributed to the development of the affected code, are ineligible to participate.
Report must include:
Reports should be made as soon as possible—ideally within 24 hours of discovery.
To be eligible for a reward, you must:
You must also be of legal age in your jurisdiction and not be a resident in a country under sanctions or restrictions, as required by applicable laws.
Vulnerabilities are classified using two factors: Impact and Likelihood. The combination of these factors determines the severity and guides the reward amount.
| Severity Level | Impact: Critical | Impact: High | Impact: Medium | Impact: Low |
|---|---|---|---|---|
| Likelihood: High | Critical | High | Medium | Low |
| Likelihood: Medium | High | High | Medium | Low |
| Likelihood: Low | Medium | Medium | Low | Informational |
Note: Please note that the POC is mandatory for all Critical and High Submissions.
| Risk Score | Payout Range |
|---|---|
| Critical | Larger of $50,000 or 10% of funds at risk up to $100K |
| High | Up to $15,000 |
| Risk Score | Payout Range |
|---|---|
| Critical | Larger of $50,000 or 10% of funds at risk up to $100K |
| High | Up to $15,000 |
Note: Actual reward amounts are determined at Infinifi's sole discretion. Factors influencing payout include quality of report, completeness, and the severity and exploitability of the vulnerability.
By submitting a report, you grant Infinifi the rights necessary to investigate, mitigate, and disclose the vulnerability. Reward decisions and eligibility are at the sole discretion of Infinifi. The terms, conditions, and scope of this Program may be revised at any time. All participants are responsible for reviewing the latest version before submitting a report.