Bug Bounty Program
Megapot is committed to the security of our protocol and the safety of user funds. We invite security researchers to help identify vulnerabilities in our smart contracts through our bug bounty program.
Review our Security policy for PGP key, safe harbor terms, and general reporting guidelines.
Program Overview
Maximum Reward
$50,000 USDC
Reward Calculation
10% of funds at risk, capped per severity tier
Platform
Self-administered (submit via email)
Scope
Smart contracts deployed on Base
Rewards by Severity
Rewards are based on the Immunefi Vulnerability Severity Classification System v2.3, which prioritizes the impact of successful exploits.
Critical
Direct theft of funds, permanent freezing of funds, protocol insolvency
$25,000 – $50,000
High
Theft of unclaimed yield, temporary freezing of funds
$2,500 – $25,000
Medium
Unbounded gas consumption, contract unable to operate due to logic errors
$100 – $2,500
Critical Severity Examples
Direct theft of LP deposits or player funds
Manipulation of drawing outcomes or winning numbers
Unauthorized minting or transfer of ticket NFTs
Exploiting the entropy provider to predict or influence randomness
High Severity Examples
Theft of unclaimed referral fees or winnings
Temporary freezing of LP withdrawals beyond the normal settlement period
Manipulation of share calculations to extract excess value
Medium Severity Examples
Unbounded loops or storage operations that cause non-purchase transactions to exceed block gas limits
Logic errors that prevent contract functionality without fund loss
Theoretical governance parameterizations that could lead to protocol degradation
Low Severity Examples
Minor calculation errors that don't result in fund loss
UI/contract state inconsistencies
In-Scope Assets
All smart contracts deployed on Base (Chain ID: 8453) are in scope:
Out of Scope
The following are not eligible for rewards:
Third-party dependencies: Issues in external contracts (Pyth Network, USDC, etc.) not deployed by Megapot
Frontend/web application: Vulnerabilities in megapot.io website or API
Theoretical vulnerabilities: Issues without a working proof of concept
Best practices: Gas optimizations, code style, or informational findings
Known limitations: Documented protocol mechanics (e.g., LP withdrawal timing, drawing locks)
Social engineering: Phishing, social engineering, or physical attacks
Griefing and denial of service: Attacks requiring excessive capital or transactions with no economic benefit to the attacker, including known griefing vectors documented in prior audits
Submission Requirements
Required Information
All submissions must include:
Description: Clear explanation of the vulnerability
Impact assessment: What can an attacker achieve? What funds are at risk?
Proof of Concept: Working exploit code or detailed reproduction steps
Affected contracts: Specific contract addresses and functions
Suggested fix (optional): Recommended remediation approach
Submission Process
Email: Send your report to security@megapot.io
Encryption: Use our PGP key for sensitive reports
Subject line:
[BUG BOUNTY] Brief description of vulnerabilityResponse time: We will acknowledge receipt within 24 hours
Report Format
Disclosure Policy
Coordinated Disclosure
We practice coordinated disclosure to protect users:
Acknowledgment
Within 24 hours of submission
Initial assessment
Within 5 business days
Fix development
Up to 90 days, depending on severity
Reward decision
Within 14 days of fix deployment
Public disclosure
After fix is deployed and users are protected
Confidentiality
Do not disclose the vulnerability publicly until we confirm the fix is deployed
Do not share details with third parties without our written consent
Premature disclosure will result in forfeiture of the bounty and potential legal action
Researcher Recognition
With your permission, we will publicly acknowledge your contribution:
Listed in our security acknowledgments
Optional: credited in the fix commit or security advisory
Safe Harbor
Megapot commits to the following for good-faith security research:
Legal Protection
We will not initiate legal action against researchers who:
Act in good faith to avoid privacy violations, destruction of data, and service interruption
Only interact with accounts you own or with explicit permission of the account holder
Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue
Report vulnerabilities promptly and provide reasonable time for remediation
Do not engage in extortion or threats
Authorized Testing
Good-faith security research under this policy is considered authorized conduct. We will not pursue civil or criminal action, or support prosecution by others, for accidental, good-faith violations of this policy.
Testing Guidelines
Allowed:
Testing on local forks or testnets
Interacting with your own accounts on mainnet
Reading public contract state
Not Allowed:
Testing on mainnet with other users' funds
Any action that could harm real users or their funds
Interfering with live drawings or settlements
Denial of service attacks against production infrastructure
Eligibility
To be eligible for a reward, you must:
Not be a current or former employee, contractor, or auditor of Megapot or Coordination, Inc.
Not have previously reported the same vulnerability
Comply with all testing and disclosure guidelines
Complete KYC verification before payout (required for rewards over $1,000)
Provide a valid wallet address for USDC payment on Base
Reward Determination
Factors Affecting Rewards
Rewards are determined by the Megapot security team based on:
Severity
Primary factor; see severity tiers above
Funds at risk
10% of realistically exploitable funds, capped by tier
Quality of report
Clear PoC and detailed writeup may increase reward
Novelty
First reporter receives full reward; duplicates receive partial or no reward
Fix complexity
Complex fixes requiring protocol changes may warrant higher rewards
Reward Process
Validation: We verify the vulnerability is real and in scope
Severity assessment: We classify the severity based on impact
Fix development: We develop and test a fix
Reward calculation: We determine the reward based on the factors above
Payout: Reward paid in USDC on Base within 14 days of fix deployment
Disputes
If you disagree with our severity assessment or reward decision, you may request a review. Send your appeal to security@megapot.io with additional context. Our decision after review is final.
Contact
For general support or non-security issues, contact team@megapot.io.
Last updated

