Bug bounty scope gap on highest-TVL contracts
Across Protocol's assessment for RD-F-183 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Across's self-hosted bug bounty explicitly states "All smart contracts and off-chain code (i.e. most of the code within the across-protocol repository) are within scope." The HubPool and all SpokePool contracts are the highest-TVL contracts and appear to be in scope per this blanket statement. The OFT TransportAdapter (LayerZero surface) is within the across-protocol/contracts repository and therefore in scope. No explicit exclusion of any high-TVL contract class identified. However: (1) the ...
Sources #
- URLhttps://docs.across.to/resources/bug-bountyretrieved 2026-04-28
- Across Protocol bug bounty — self-hosted, $1M critical maxhttps://www.bugbountydirectory.com/programs/acrossretrieved 2026-04-26
Methodology #
Determine whether the highest-TVL contracts of this protocol (especially shared primitives: OFT adapters, ZK verifiers, bridge inbox) are explicitly excluded from the protocol's active bug bounty scope.
See the full factor methodology and distribution across all protocols →