
Spark
Spark is a DeFi Lending protocol deployed on ethereum. Bug bounty program with rewards up to $5,000,000 for verified smart contract vulnerabilities.
ETHDeFi LendingPoC RequiredTriaged
Verified ProgramKYC Not RequiredPoC RequiredPrimacy of ImpactTriaged
Max Bounty$5,000,000
Min Bounty$5,000
PayoutUSDC
Findings0
Accepted0
Chains1
TVL$2.2B
Live SinceNov 2023
5 Audit Reports Available
Spark ALM Curve Controller Audit for MakerDAO Sky 10 March 2025 - 21 March 2025Cantina
2025-MarMakerDAO Spark PSM3 Governance Audit MakerDAO 16 October 2024 - 18 October 2024Cantina
2024-OctMakerDAO Spark ALM Init Script Audit MakerDAO 16 October 2024 - 18 October 2024Cantina
2024-OctSpark ALM CCTP & Swap Logic Audit MakerDAO 18 September 2024 - 19 September 2024Cantina
2024-SepSpark PSM3 Contract Security Audit MakerDAO 21 August 2024 - 22 August 2024Cantina
2024-Aug01Severity & Rewards
02Program Rules
- 01Proof of Concept is required for all submissions. Reports without a working PoC demonstrating the vulnerability will not be considered.
- 02KYC is not required for this program. Pseudonymous submissions are accepted.
- 03This program follows Primacy of Impact โ valid findings are rewarded based on demonstrated impact regardless of whether the specific attack vector was previously known.
- 04Submissions are triaged by the security team. Expect initial response within 48 hours of submission.
- 05Only previously unreported vulnerabilities are eligible. Duplicate submissions will be closed.
- 06Vulnerabilities must be reported through the WhiteClaws platform. Public disclosure before resolution disqualifies the submission.
- 07Testing must not disrupt live protocol operations. Use mainnet forks or testnets for Proof of Concept execution.
- 08For Critical severity findings, the security team may arrange direct communication for expedited resolution.
โ IN SCOPE
- โLending and borrowing smart contracts
- โLiquidation mechanism and parameters
- โInterest rate model implementation
- โCollateral management and pricing oracles
- โFlash loan functionality
โ OUT OF SCOPE
- โFrontend applications
- โOff-chain infrastructure
โ Protocol Information
Bounty program indexed and verified by WhiteClawsProgram data sourced from on-chain analysis and public bounty disclosures.