USDai
Bounty Range
$100,000 - $100,000
external program
USDai is an $PYUSD-backed stablecoin. Staked USDai (sUSDai) is a yield-bearing vault token backed by USDai $PYUSD yield from PayPal's incentives and loans against GPUs.
Do not test vulnerabilities on mainnet or public testnet deployments without prior authorization. Use local test environments or private test setups.
Do not publicly disclose details of any vulnerability before it has been addressed and you have received written permission to disclose.
Do not exploit the vulnerability beyond the minimum steps necessary to demonstrate the issue. Do not access private data, engage in social engineering, or disrupt service.
Individuals currently or formerly employed by USDai, or those who contributed to the development of the affected code, are ineligible to participate.
Please report vulnerabilities directly through the Spearbit/Cantina platform. Please include:
Reports should be made as soon as possible—ideally within 24 hours of discovery.
To be eligible for a reward, you must:
You must also be of legal age in your jurisdiction and not be a resident in a country under sanctions or restrictions, as required by applicable laws.
For USDai contract repo the following contracts at the commit: 5ef4905a9ca11ff751039fde037b351b12737f9d
For USDai loan router contract repo the following contracts at the commit: 59adf3e208c897b0f04059f186bc28f7f1e75e14
Vulnerabilities are classified using two factors: Impact and Likelihood. The combination of these factors determines the severity and guides the reward amount.
| Severity Level | Impact: Critical | Impact: High | Impact: Medium | Impact: Low |
|---|---|---|---|---|
| Likelihood: High | Critical | High | Medium | Low |
| Likelihood: Medium | High | High | Medium | Low |
| Likelihood: Low | Medium | Medium | Low | Informational |
Core Smart Contract Code
| Risk Score | Payout Range |
|---|---|
| Critical | Up to $100,000 + additional rewards |
| High | Up to $50,000 |
| Medium | Up to $10,000 |
| Low | Discretionary |
Note: Actual reward amounts are determined at USDai's sole discretion. Factors influencing payout include quality of report, completeness, and the severity and exploitability of the vulnerability.
By submitting a report, you grant USDai the rights necessary to investigate, mitigate, and disclose the vulnerability. Reward decisions and eligibility are at the sole discretion of USDai. The terms, conditions, and scope of this Program may be revised at any time. All participants are responsible for reviewing the latest version before submitting a report.