Kiln Web / Infra
Bounty Range
$1,000 - $100,000
external program
Kiln is a staking platform that enable one to stake directly, or whitelabel staking into their product.
It allows individuals or clients to stake crypto assets, manually or programmatically, while maintaining custody of their funds in your existing solution, such as Fireblocks, Copper, or Ledger.
| Severity | Max. Reward |
|---|---|
| Critical | $100,000 |
| High | $8,000 |
| Medium | $2,500 |
| Low | $1,000 |
No Unauthorized Testing on Production Environments: Do not test vulnerabilities on mainnet or public testnet deployments without prior authorization. Use local test environments or private test setups.
No Public Disclosure Without Consent: Do not publicly disclose details of any vulnerability before it has been addressed and you have received written permission to disclose.
No Exploitation or Data Exfiltration: Do not exploit the vulnerability beyond the minimum steps necessary to demonstrate the issue. Do not access private data, engage in social engineering, or disrupt service.
No Conflict of Interest: Individuals currently or formerly employed by Kiln, or those who contributed to the development of the affected code, are ineligible to participate.
Please report vulnerabilities directly through the Spearbit/Cantina platform. Please include:
Reports should be made as soon as possible—ideally within 24 hours of discovery.
To be eligible for a reward, you must:
You must also be of legal age in your jurisdiction and not be a resident in a country under sanctions or restrictions, as required by applicable laws.
The following testing and reporting activities are strictly prohibited:
By submitting a report, you grant Kiln the rights necessary to investigate, mitigate, and disclose the vulnerability. Reward decisions and eligibility are at the sole discretion of Kiln. The terms, conditions, and scope of this Program may be revised at any time. All participants are responsible for reviewing the latest version before submitting a report.