Kuru Bug Bounty
Bounty Range
$5,000 - $50,000
external program
Kuru is a smart aggregator and fully on-chain order book decentralized exchange (DEX) built on Monad. Kuru is dedicated to building the trading hub for Monad, allowing users to access all of Monad's liquidity with our smart aggregator, Kuru Flow, and bringing a performant central-limit orderbook to the EVM for the first time along with integrated discovery features, a trading terminal, user liquidity provision, and token launchpad.
Powered by Monad's globally decentralized network, Kuru unifies liquidity across the ecosystem with our hybrid integrated CLOB-AMM model that preserves composability and democratizes access to liquidity provisioning.
Vulnerabilities are classified using two factors: Impact and Likelihood. The combination of these factors determines the severity and guides the reward amount.
| Severity Level | Impact: Critical | Impact: High | Impact: Medium | Impact: Low |
|---|---|---|---|---|
| Likelihood: High | Critical | High | Medium | Low |
| Likelihood: Medium | High | High | Medium | Low |
| Likelihood: Low | Medium | Medium | Low | Informational |
Impact Definitions:
Likelihood Definitions:
| Severity | Maximum Reward |
|---|---|
| Critical | $50,000 |
| High | $25,000 |
| Medium | $5,000 |
No Unauthorized Testing on Production Environments: Do not test vulnerabilities on mainnet or public testnet deployments without prior authorization. Use local test environments or private test setups.
No Public Disclosure Without Consent: Do not publicly disclose details of any vulnerability before it has been addressed and you have received written permission to disclose.
No Exploitation or Data Exfiltration: Do not exploit the vulnerability beyond the minimum steps necessary to demonstrate the issue. Do not access private data, engage in social engineering, or disrupt service.
No Conflict of Interest: Individuals currently or formerly employed by Kuru, or those who contributed to the development of the affected code, are ineligible to participate.
You must report vulnerabilities directly to Cantina. Please include:
Reports should be made as soon as possible—ideally within 24 hours of discovery.
To be eligible for a reward, you must:
You must also be of legal age in your jurisdiction and not be a resident in a country under sanctions or restrictions, as required by applicable laws.
By submitting a report, you grant Kuru the rights necessary to investigate, mitigate, and disclose the vulnerability. Reward decisions and eligibility are at the sole discretion of Kuru. The terms, conditions, and scope of this Program may be revised at any time. All participants are responsible for reviewing the latest version before submitting a report.