Bug Bounty
In addition to regular audits, we have a bug bounty program for the Azoth main contracts on Ethereum.
Introduction
At Azoth, we prioritize the security and integrity of our blockchain-based RWA (Real-World Asset) platform. To ensure the highest level of protection for our users and assets, we invite security researchers, ethical hackers, and the broader community to participate in our Bug Bounty Program.
This program rewards individuals who responsibly disclose vulnerabilities in our smart contracts, web applications, APIs, and other critical infrastructure.
2. Scope & Eligibility
In-Scope Targets
β Smart Contracts (Ethereum, Arbitrum and other supported chains) β Web Application (https://azoth.finance) β Mobile App (coming soon) β API Endpoints (REST) β Blockchain-Related Issues (e.g., governance, oracle manipulation)
Out-of-Scope
β Third-party services (unless directly integrated with Azoth) β Phishing/Social Engineering (unless it exploits a technical flaw) β Low-severity UI/UX issues (e.g., typos, minor display glitches) β Theoretical vulnerabilities without PoC
Eligibility:
Participants must follow responsible disclosure guidelines.
Publicly disclosing a vulnerability before approval will disqualify you.
Azoth team members and auditors are ineligible.
3. Vulnerability Classification & Rewards
Rewards are based on severity (CVSS v3.1) and impact.
Severity
Examples
Reward (Points)
Critical (9.0+)
Smart contract theft, fund loss, private key leak
5,000β5,000β50,000
High (7.0-8.9)
Unauthorized access, oracle manipulation
2,000β2,000β5,000
Medium (4.0-6.9)
Logic errors, improper access control
500β500β2,000
Low (0.1-3.9)
Minor bugs, informational findings
100β100β500
Note:
Rewards may be adjusted based on exploit complexity.
Duplicate reports receive no reward (first submitter wins).
4. Submission Process
Identify a vulnerability within the scope.
Submit a report via email to: security@azoth.finance
Include:
Description of the issue
Steps to reproduce (with screenshots/video if possible)
Impact assessment
Suggested fix (optional but appreciated)
Await response (we aim to acknowledge within 48 hours).
Fix validation β Our team will verify and may request additional details.
Reward payment β After confirmation, rewards are paid in USDC/ETH or other agreed methods.
5. Rules & Legal
Do not exploit vulnerabilities (e.g., stealing funds, disrupting services).
No public disclosure before Azoth approves it.
Comply with laws β Ethical hacking only.
No spam/low-effort reports (they will be ignored).
Azoth reserves the right to modify program terms at any time.
6. Contact
For questions, contact: π§ security@azoth.finance π Azoth Security Portal
Thank you for helping secure Azoth! π
Last updated