Disclosure channel exists
Aerodrome Finance's assessment for RD-F-175 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Velodrome Immunefi bug bounty (https://immunefi.com/bug-bounty/velodromefinance/) serves as de facto disclosure channel with $100K max payout and 54 assets in scope. Aerodrome contracts are NOT explicitly named in scope (Slipstream README states 'Velodrome has a live bug bounty hosted on Immunefi' — implied shared coverage). No SECURITY.md or security@ contact exists. No dedicated Aerodrome Immunefi program. Yellow: channel exists but scope ambiguity for Aerodrome-specific Base contracts; no active-monitoring evidence.
Sources #
- URLVelodrome Finance Bug Bounty — ImmunefiVelodrome Finance Immunefi bug bounty — $100K max, 54 assets in scoperetrieved 2026-05-04
- Aerodrome Finance contracts repo — no SECURITY.mdaerodrome-finance/contracts — security_md_present: false per data cache; GitHub root listing confirms no SECURITY.mdretrieved 2026-05-04
Methodology #
Determine whether the protocol publishes a public security disclosure channel (security@ email, Immunefi program, in-house disclosure page).
See the full factor methodology and distribution across all protocols →