Makina Contracts
Bounty Range
$50,000 - $500,000
external program
The Makina protocol introduces a novel architecture for onchain strategy execution that addresses fundamental limitations in existing vault infrastructure. Through its hub-and-spoke multi-chain design, Makina enables sophisticated cross-chain strategies while maintaining strict security guarantees and operational efficiency. The protocol's core innovation, MakinaVM, provides a flexible yet controlled execution environment that allows strategies to interact with any external protocol without requiring custom adapters. Combined with a comprehensive governance framework featuring multiple stakeholder roles and timelocked controls, Makina establishes a new paradigm for trustless, scalable, and capital-efficient onchain asset management. This paper presents the protocol's architecture, security model, and key innovations that enable institutional-grade strategy execution across multiple networks.
No Unauthorized Testing on Production Environments: Do not test vulnerabilities on mainnet or public testnet deployments without prior authorization. Use local test environments or private test setups.
No Public Disclosure Without Consent: Do not publicly disclose details of any vulnerability before it has been addressed and you have received written permission to disclose.
No Exploitation or Data Exfiltration: Do not exploit the vulnerability beyond the minimum steps necessary to demonstrate the issue. Do not access private data, engage in social engineering, or disrupt service.
No Conflict of Interest: Individuals currently or formerly employed by Makina, or those who contributed to the development of the affected code, are ineligible to participate.
Please report vulnerabilities directly through the Spearbit/Cantina platform. Please include:
Reports should be made as soon as possible—ideally within 24 hours of discovery.
To be eligible for a reward, you must:
You must also be of legal age in your jurisdiction and not be a resident in a country under sanctions or restrictions, as required by applicable laws.
Vulnerabilities are classified using two factors: Impact and Likelihood. The combination of these factors determines the severity and guides the reward amount.
Risk Classification Matrix
| Severity Level | Impact: Critical | Impact: High | Impact: Medium | Impact: Low |
|---|---|---|---|---|
| Likelihood: High | Critical | High | Medium | Low |
| Likelihood: Medium | High | High | Medium | Low |
| Likelihood: Low | Medium | Medium | Low | Informational |
Impact Definitions:
Likelihood Definitions:
Maximum Reward: $500,000 (Critical severity)
Reward Tiers:
By submitting a report, you grant Makina the rights necessary to investigate, mitigate, and disclose the vulnerability. Reward decisions and eligibility are at the sole discretion of Makina. The terms, conditions, and scope of this Program may be revised at any time. Participants are responsible for reviewing the latest version before submitting a report.