Sovryn announces $1.25 million bug bounty program

Bonus payouts are available for smart-contract- and blockchain-related bugs

Fake ladybug on a circuit board

Bitcoin trading and lending platform Sovryn has announced its biggest bug bounty program. The announcement comes after the company raised an equivalent of $10 million in bitcoin through its governance token presale.

The bounty, launched in partnership with Immunefi, will offer white-hat hackers a whopping $1.25 million to unearth security vulnerabilities in the Sovryn smart contract.

“Throughout the proposal drafting process for SIP-8, the Sovryn team and community have provided valuable feedback and sharing ideas on how to improve the program, said Immunefi co-founder Travin Keith.

Keith continued, “the program will incentivize white hats to look through the code as well as incentivizing black hats to disclose bugs, instead of exploiting them."

According to the bounty’s official page, payouts will adhere to Immunefi’s vulnerability severity classification system. 

For smart contract and blockchain vulnerabilities, the bounties range from $2,200 for low-risk issues to as much as $1 million for critical flaws. Sovryn will cap the $1 million bounties at 10% of the funds at risk. 

Sovryn will also pay a bonus for smart-contract- and blockchain-related bugs reported within the first three weeks of the bounty program. The special reward starts at 25% and is split into seven-day rounds. The bonus reduces by five percentage points at the end of each round until it reaches 10% in the final bonus round.

Website and app vulnerabilities have lower payouts that range from $2,200 for medium-severity vulnerabilities to $22,140 for critical issues.There’s no bonus for finding these vulnerabilities in the first three weeks.  

Rewards are payable in bitcoin, but the Sovryn team may decide to have “up to 50% of the reward payable in schedule of values (SOV) tokens according to a vesting schedule dependent on the amount paid out.”

Casting light on the most rewarding vulnerabilities, Sovryn said the company is especially interested in receiving news about missing access controls, consensus failures, logic errors, susceptibility to block timestamp manipulation, remote code execution, clickjacking, and cryptography problems. 

Sovryn also clarified that in case two or more reports suggest the same vulnerability, only the first complete bug report will receive the reward. “The final reward amount is capped at 10% of the funds at risk based on the vulnerability reported," the company said.

“The Sovryn developer team/community takes security seriously and this successful presale has allowed us to take that to the next level, encouraging thousands of hackers to try to penetrate our decentralized protocol. Forged in the white-hot fire of this testing, the armor of our security will emerge all the strong,” added Sovryn co-founder Edan Yago.

Featured Resources

Modern governance: The how-to guide

Equipping organisations with the right tools for business resilience

Free Download

Cloud operational excellence

Everything you need to know about optimising your cloud operations

Watch now

A buyer’s guide to board management software

How the right software can improve your board’s performance

The real world business value of Oracle autonomous data warehouse

Lead with a 417% five-year ROI

Download now

Recommended

UK's first government cyber strategy aims to bolster public sector defences
cyber security

UK's first government cyber strategy aims to bolster public sector defences

25 Jan 2022
IT Pro Podcast: Learning to live with risk
Sponsored

IT Pro Podcast: Learning to live with risk

25 Jan 2022
Russia's "politically motivated" REvil raid could be used as leverage, experts warn
ransomware

Russia's "politically motivated" REvil raid could be used as leverage, experts warn

17 Jan 2022
Meta files lawsuit to uncover hackers targeting Facebook, WhatsApp
phishing

Meta files lawsuit to uncover hackers targeting Facebook, WhatsApp

21 Dec 2021

Most Popular

How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

6 Jan 2022
How to speed up Windows 11
Microsoft Windows

How to speed up Windows 11

7 Jan 2022
Solving cyber security's diversity problem
Careers & training

Solving cyber security's diversity problem

5 Jan 2022