โ† All Bounties
Spark logo

Spark

Spark is a DeFi Lending protocol deployed on ethereum. Bug bounty program with rewards up to $5,000,000 for verified smart contract vulnerabilities.

ETHDeFi LendingPoC RequiredTriaged
Verified ProgramKYC Not RequiredPoC RequiredPrimacy of ImpactTriaged
Max Bounty$5,000,000
Min Bounty$5,000
PayoutUSDC
Findings0
Accepted0
Chains1
Live SinceNov 2023

01Severity & Rewards

02Program Rules

  1. 01Proof of Concept is required for all submissions. Reports without a working PoC demonstrating the vulnerability will not be considered.
  2. 02KYC is not required for this program. Pseudonymous submissions are accepted.
  3. 03This program follows Primacy of Impact โ€” valid findings are rewarded based on demonstrated impact regardless of whether the specific attack vector was previously known.
  4. 04Submissions are triaged by the security team. Expect initial response within 48 hours of submission.
  5. 05Only previously unreported vulnerabilities are eligible. Duplicate submissions will be closed.
  6. 06Vulnerabilities must be reported through the WhiteClaws platform. Public disclosure before resolution disqualifies the submission.
  7. 07Testing must not disrupt live protocol operations. Use mainnet forks or testnets for Proof of Concept execution.
  8. 08For Critical severity findings, the security team may arrange direct communication for expedited resolution.

โœ“ IN SCOPE

  • โ—Lending and borrowing smart contracts
  • โ—Liquidation mechanism and parameters
  • โ—Interest rate model implementation
  • โ—Collateral management and pricing oracles
  • โ—Flash loan functionality

โœ• OUT OF SCOPE

  • โ—Frontend applications
  • โ—Off-chain infrastructure

โ˜…Protocol Information

Bounty program indexed and verified by WhiteClawsProgram data sourced from on-chain analysis and public bounty disclosures.