Skip to content
KIMP

Bug bounty

The KIMP bug bounty opens at mainnet. Scope, severity principles and responsible disclosure guidance.

The KIMP bug bounty opens at mainnet. Until then, security researchers are welcome to review the testnet contracts on GIWA Sepolia once their addresses are published and report issues through responsible disclosure. Reward amounts and program terms will be published in these docs when the bounty opens.

Scope at opening#

The bounty will cover the KIMP core contracts deployed on GIWA mainnet:

  • KimpIndex and KimpReporterRegistry
  • KimpMarket and KimpPool
  • KimpVerifiedGate
  • KimpStaking and KimpBuyback

The following are out of scope:

  • GIWA chain infrastructure, the sequencer, Dojang and up.id, which are operated by third parties
  • Source exchanges and FX providers
  • This website, except where a flaw could directly cause loss of user funds
  • Issues that require control of the guardian Safe or the timelock
  • Known issues listed in published audit reports

Severity principles#

Severity will be assessed by impact on user funds and on index integrity:

SeverityExample impact
CriticalTheft or permanent freezing of collateral or pool assets
CriticalManipulation of the finalized index without holding reporter quorum
HighIncorrect settlement, liquidation or NAV accounting
HighBypass of the Verified Lane gate or position limits
MediumTemporary denial of service on markets or withdrawals
LowIncorrect events, view functions or minor accounting drift

Responsible disclosure#

  1. 1Do not exploit a vulnerability beyond what is needed to prove it. Use a local fork or testnet.
  2. 2Do not disclose the issue publicly until it has been fixed.
  3. 3Report by direct message to @KimpGiwa on X. Include a short description and a way to share details privately. Do not post details in public replies.
  4. 4Allow reasonable time for a fix. The guardian can pause markets while a fix is prepared.

Payouts#

Payouts will be made from the treasury, which is governance-controlled. Researchers may be asked to confirm they are not a restricted person. No payout will be made for an issue that was exploited against users.