defirisk.co
rubric v1.7.0

Ignored bounty disclosure

Venus Protocol's assessment for RD-F-008 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

No formal bug-bounty channel disclosure was ignored (no bounty program is confirmed). However, Code4rena 2023 M-10 audit finding was dismissed without remediation — the functional equivalent of an ignored disclosure. Two resulting exploits confirm the consequential nature of the dismissal. Applied to the audit-channel equivalent per factor spirit.

Sources #

Methodology #

Determine whether any prior post-mortem documents a disclosed vulnerability that was reported to the team and not actioned before exploit.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol venus factor RD-F-008 score yellow collected_at 2026-04-28 18:30:49