Cointime

Download App
iOS & Android

Uniswap unveils $15.5M core contracts bug bounty ahead of v4 launch

Cointime Official

From cointelegraph by Tristan Greene

Uniswap Labs announced the launch of what it deems “the largest bounty in history” ahead of the Uniswap v4 release. 

The bounty program, currently underway, features payouts ranging from $2,000 up to the full $15.5 million purse for the discovery of unique vulnerabilities resulting in code change.

In order to achieve the highest payouts, bounty hunters will need to uncover a critical flaw or exploit in the Uniswap v4 core contracts code, per the terms of the program. 

  Uniswap Labs announces “the largest bug bounty ever” on X.com. Source: Uniswap Labs

“Introducing the largest bug bounty in history. We're rewarding up to $15.5M to anyone that finds a critical vulnerability in v4 core contracts. Find a critical bug, become a millionaire.”

Bug bounty

It’s unclear if this is the biggest bounty program in history. For comparison, bug bounty platform Immunefi reportedly paid out a $14.82 million bounty in 2021 as part of its ongoing security efforts. 

Related: Immunefi suspends TrustSec amid bug bounty dispute 

Other notable bounty payouts include Google’s highest-ever vulnerability discovery payout of $605,000 in 2022, a year in which the company paid out a reported total of $12 million. And, more recently, Microsoft announced $4 million in cloud and AI bounties. 

Based on available data, Uniswap’s $15.5 million bounty would become the largest in recent memory if it were claimed in a single payout. 

However, according to Uniswap Labs, over 500 researchers participated in its previously held $2.35 million security competition for the unreleased v4, and no critical vulnerabilities were found. The firm said the $15.5 million program is “an extra step to ensure v4 is as secure as possible.”

The maximum payout of $15.5 million is only available to researchers who discover unique vulnerabilities in the Uniswap v4 core contracts code that result in code change. 

A table demonstrating top payout requirements for Uniswap Lab’s $15.5 millionbounty program. Source: Uniswap Labs/Cantina

Vulnerabilities deemed “critical” will be eligible for the top payout, according to the program’s details, while those labeled “high” could qualify for a payment of up to $1 million. Payouts dip to $100,000 for “medium” risk vulnerabilities and those for low-risk vulnerability findings will be paid out on a “discretionary” basis. 

Beyond the core contracts code, the program also covers vulnerabilities in “other contracts,” other websites, back ends, and Uniswap v4 wallet codes. 

Magazine: Make Ethereum feel like Ethereum again: Based rollups explained

Comments

All Comments

Recommended for you

  • Crypto literacy at ‘dangerously low’ levels, new report warns

    The crypto community’s financial literacy rate is estimated at 25%, lagging the financial literacy average in the United States by half, according to a new report.

  • Managing Your Crypto Portfolio in Q4

    No matter how far along you are in your crypto investment journey, it is worth taking the following steps in Q4 to get the best results in both 2024 and beyond.

  • How low can the Bitcoin price go?

    Bitcoin price is down 10.5% from its new all-time highs, and several market analysts expect BTC to bottom in the $85,000 to $90,000 range.

  • Did 8% Bitcoin price drop change bulls' chance of BTC hitting $100K?

    Bitcoin unexpectedly fell under $92,000 on Nov. 25. Do bulls still have a chance to rally to $100,000?

  • Understanding Aleo: A Comprehensive Overview

    The rise of smart contract-enabled blockchains has enabled the development of unique decentralized applications and increased transparency in financial transactions. However, although transparency is beneficial for some use cases, the need for onchain privacy has also grown. This has given rise to an influx of applications and blockchains prioritizing privacy through the implementation of cryptographic primitives such as zero-knowledge proofs, ring signatures, and multi-party computation (MPC).

  • Touching Distance

    Following a flurry of consistent new ATHs, Bitcoin is just a stone's throw away from reaching a price of $100k per coin. Explosive price action tends to result in a significant increase in the unrealized profit of holders, and Long-Term Holders are ramping up their distribution in response.

  • Decentralised Compute

    On LLM Training, GPUs, Data Centres, and where Crypto fits in

  • U.S. consumer confidence improves again in November, reaching a two-year high

    Dana M. Peterson, Chief Economist of the World Large Enterprises Federation, said, "US consumer confidence continued to improve in November, reaching the highest level in the past two years. The growth in November was mainly due to consumers' more positive assessment of the current situation, especially in the labor market. Compared with October, consumers' optimism about future employment opportunities has also greatly increased, reaching the highest level in nearly three years. At the same time, consumers' expectations for future business conditions have not changed, while their optimism about future income has slightly declined." Earlier, the US Conference Board Consumer Confidence Index for November recorded 111.7, a new high since July 2023.

  • FD Technologies Posts Wider Loss, Debt Surges 84% Before First Derivatives Sale

    The company reports a challenging 6 months, with revenue down 7% to £118.2m and adjusted EBITDA falling 26% to £10.5m. FD Technologies recently announced its plan to sell its First Derivative business to EPAM Systems for £230 million.

  • Starknet: Phase 1 of STRK staking is now live on the mainnet

    Starknet announced that the first stage of STRK staking has officially launched on the mainnet.