Scope
- SaucerSwap testnet contracts and GitHub repositories
- SaucerSwap testnet interface
- SaucerSwap Mobile App (iOS and Android)
- SaucerSwap mainnet contracts and production environment (testing restricted to testnet, which mirrors mainnet)
- Third-party contracts not directly associated with SaucerSwap
- Known issues from previous audit and bug bounty reports
- UI, cosmetic, usability, or informational findings without a demonstrated path to material loss of user or protocol funds
- Third-party applications using SaucerSwap contracts
- Any findings that rely on Denial of Service (DoS) or Distributed Denial of Service (DDoS)
- Phishing, social engineering, or attacks requiring collusion from SaucerSwap staff or third-party support
- Physical access, stolen/unlocked devices, SIM-swap, device-level malware, or OS/kernel exploits unrelated to the app
- Repackaged or modified app builds, emulator-only issues, or jailbreak-only read-only file access (unless chained to unauthorized signing that could cause material loss of funds, in which case it is evaluated under High)
- Vulnerabilities in third-party libraries without demonstrable impact on SaucerSwap Mobile
Rewards
The program uses the following four-level severity scale, based on the OWASP risk rating methodology. Only Critical or High vulnerabilities that meet the material loss of funds requirement and all other program conditions are eligible for a bounty payout. Reputational, legal, or other non-financial impacts alone do not qualify. Medium and Informational findings are not eligible for a bounty payout, even when they result in a code or configuration change.
SaucerSwap Labs will determine rewards based on the bug’s severity and its potential for exploitation. Rewards may be disbursed in U.S. dollars, cryptocurrency, or a mix of both.
Disclosure
Report vulnerabilities to [email protected]. An acknowledgment will be sent within two to three business days. Do not disclose the bug publicly until it is resolved and permitted by SaucerSwap Labs. For payout consideration, provide enough information to reproduce the vulnerability and assess its potential financial impact, including:- Conditions required for reproducing the bug
- Step-by-step guide or proof of concept for reproduction
- Potential consequences if exploited, including the funds at risk and how the exploit could cause material loss
- Suggested remediation (optional)
Eligibility
To be eligible for a reward under this program, you must meet the following conditions:- Uniqueness: Discover a previously unreported, non-public vulnerability that is not already known to our team, is within the scope of the program, and could cause material loss of user or protocol funds.
- First disclosure: Be the first to disclose the unique vulnerability to [email protected], and adhere to the program’s disclosure requirements.
- Detailed reporting: Provide comprehensive information that enables our engineers to reproduce and remedy the vulnerability.
- Non-exploitation: Do not exploit the vulnerability in any form, including publicizing it or seeking other forms of profit, except under this program.
- Non-publicization: Do not disclose the vulnerability to the public or any third party without our explicit approval.
- Ethical conduct: Make a good faith effort to prevent privacy violations, data destruction, service interruption, or any degradation of in-scope assets.
- Lawful behavior: Do not engage in any unlawful conduct during the disclosure process, such as making threats or demands.
- Age requirement: Must be at least 18 years of age. If younger, you may participate with the consent of a parent or guardian.
- Legal compliance: Cannot be subject to U.S. sanctions or reside in a U.S.-embargoed country.
- Non-affiliation: Cannot be a current or former employee, vendor, or contractor who contributed to the development of the affected code.
- Complete compliance: Must comply with all other eligibility requirements specified in this program.
Other terms
By submitting a report, you grant SaucerSwap Labs the rights necessary to validate and resolve the vulnerability. All reward decisions are at our sole discretion. The program’s terms may be changed at any time.History
A dedicated V3 testnet bug bounty ran from May 25 to June 1, 2026, ahead of the V3 order book mainnet launch; that program is now closed.Next steps
Security audits
Independent audit reports for every protocol release.
Contract deployments
Testnet contract IDs that fall within the program scope.