♒
Aquarius Guide
  • 👋Welcome to Aquarius
  • Developers
    • Integrating with Aquarius
    • Aquarius Soroban Functions
    • Code Examples
      • Prerequisites & Basics
      • Executing Swaps Through Optimal Path
      • Executing Swaps Through Specific Pool
      • Deposit Liquidity
      • Withdraw Liquidity
      • Get Pools Info
      • Claim LP Rewards
      • Add Fees To Swap
        • Deploying a New Fee Collector
        • Executing Swaps with Provider Fees
        • Claiming & Swapping Accumulated Fees
  • Ecosystem Overview
    • 🌐What is Stellar?
      • What are Lumens (XLM)?
      • What are Anchors?
      • What are Trustlines?
      • How much are network fees on Stellar?
      • What are network reserves?
      • Where to trade Stellar assets?
    • 🧮What is Soroban?
  • AQUA tokens
    • ♒What are AQUA tokens?
      • AQUAnomics
      • AQUA Wallets
      • Where can I buy AQUA?
  • ICE
    • 🧊ICE tokens: locking AQUA and getting benefits
    • ICE boosts - how to maximize LP rewards
  • Aquarius AMMs
    • 💱What are Aquarius AMMs?
      • Pools
        • Creating a Pool
        • Deposit & Withdraw Liquidity
      • Swap
      • System limitations
        • Aquarius AMM: Limitations in Support for Fee-on-Transfer, Rebasing, and Deflationary Tokens
        • Aquarius AMM: Token Address Migration Limitations and Mitigation Strategy
  • My Aquarius
    • 👤My Aquarius
      • Main Overview
      • Balances
      • My Liquidity
      • SDEX Rewards
      • Liquidity Votes
      • Governance Votes
      • Airdrop #2
      • ICE Locks
      • Payments History
  • Aquarius AQUA Rewards
    • 🗳️Aquarius voting
      • Aquarius voting: asset Flag Restrictions
    • 🪙SDEX Rewards
    • 🤖Aquarius AMM Rewards
  • Bribes
    • 🎁What are bribes?
      • What are the advantages of protocol level bribes?
  • Aquarius Governance
    • 🧑‍⚖️Aquarius Governance: Community-Led Decision Making
  • Airdrops
    • 1️⃣The Initial Airdrop
      • Am I Eligible For the Initial Airdrop?
      • How can I see if I am eligible?
      • What are Claimable Balances?
      • How is the Initial airdrop distributed?
      • Where can I find more information?
    • 🌠Airdrop #2
      • How could I have been eligible for Airdrop #2?
      • How can I see if I am eligible?
      • When was the Airdrop #2 snapshot?
      • Were there any CEX's taking part?
      • How big was Airdrop #2?
      • How will the airdrop be distributed and for how long?
      • Could I have increased my potential reward?
      • Where can I find more information?
  • Signers Guild
    • 📜What is the signers guild?
      • What percentage of the AQUA supply will be controlled by the Signers Guild?
      • Who will be in the Signers Guild?
      • How does the Signing process work?
      • What will be expected from a guild member?
      • How can I sign up for this position?
      • What are wallets that Guild members will manage?
      • How can I learn more about this?
  • Guides
    • ❔How to use AQUA Locker tool and get ICE tokens
    • ❔How to vote for markets on Aquarius
    • How to create bribes
    • ❔How to use Aquarius Governance
      • How to make a governance vote
      • How to create a proposal
    • ❔How to earn SDEX rewards
    • ❔How to earn AMM rewards
  • Technical Documents
    • 📜Audits
    • 🪲Bug Bounties
    • 🛄Claimable Balances
    • 🗳️The Aquarius Voting Mechanism
    • 🎁SDEX v2 proposal & algorithm
    • ⏩ICE Boost Formula
  • Useful Links
    • Aquarius Home
    • Liquidity Voting
    • Liquidity Rewards
    • Aquarius Bribes
    • ICE locker
    • Aquarius Governance
    • Airdrop #2
Powered by GitBook
On this page
  • What bugs can result in rewards?
  • How should I report potential bugs?
  • Eligibility
  1. Technical Documents

Bug Bounties

Receive AQUA for helping us squash bugs

PreviousAuditsNextClaimable Balances

Last updated 1 year ago

Part of keeping Aquarius’ constant growth is ensuring the protocol is operational, reliable, and consistently performing to the highest standards. Now and then, a bug inside the code or loopholes can cause issues, creating vulnerabilities to the Aquarius protocol.

Bug bounties reward those who find & raise vulnerabilities with the team, allowing fixes to be deployed and safeguarding Aquarius.

In the past, users have addressed potential bugs through governance, but this process is not needed if an issue affects the main goals of Aquarius. We have an allocated Bug Bounty fund tied to the , which we use to reward those who find vulnerabilities.

What bugs can result in rewards?

Reward considerations apply to most bugs found that can negatively impact Aquarius. We pay bounties at our discretion, with reward values depending on the severity & complexity of the issue.

While we can consider a lot of different issues for a bounty, the following issues would not come under our scope:

  • Bugs in any third party platform that interacts with Aquarius

  • Vulnerabilities already reported and/or discovered by the team or advisors

  • Any already-reported bugs by others in the community

Vulnerabilities that occur due to any of the following are also outside of the bug bounties scope:

  • Front end bugs

  • DDOS attacks

  • Spamming

  • Phishing

  • Compromise or misuse of third-party systems or services.

How should I report potential bugs?

Any vulnerability or bug discovered should be reported via private message to any of the admins of the Telegram, Discord, or Reddit channels or our bug reporting email address report@aqua.network.

The vulnerability must not be disclosed publicly or to any other person, entity, or email address before Aquarius has been notified and a fix deployed. The disclosure of a bug must be made preferably within 24 hours following its discovery. Once fixed, permission will be granted for public disclosure.

The more detailed a vulnerability report, the higher the likelihood of a reward and its value. Please provide as much information about the vulnerability as possible, including:

  • What conditions cause the bug to occur

  • The steps needed to reproduce the bug or, preferably, a proof of concept.

  • The potential implications of the vulnerability being abused.

Anyone who reports a unique, previously unreported, and publicly undisclosed vulnerability that results in a deployed fix by our developers will be recognized publicly for their contribution if they so choose.

Eligibility

To be eligible for a reward under this Program, you must:

  • Discover a previously unreported, non-public vulnerability that would result in loss of user’s funds or abuse of the Aquarius protocol, which is within the scope of this Program.

  • Be the first to disclose the unique vulnerability to the Aquarius team in compliance with the disclosure requirements above. If multiple users report similar vulnerabilities within 24 hours, rewards will be split at the discretion of Aquarius.

  • Provide sufficient information to enable our developers to reproduce and fix the vulnerability.

  • Not engage in any unlawful conduct when disclosing the bug to Aquarius, including through threats, demands, or any other coercive tactics.

  • Not exploit the vulnerability in any way, including making it public or obtaining a profit (other than a reward under this Program).

  • Make a good faith effort to avoid privacy violations, data destruction, interruption, or degradation of the Aquarius protocol.

  • Submit only one vulnerability per submission unless you need to chain vulnerabilities to provide impact regarding any of the vulnerabilities.

  • Not separately submit underlying vulnerabilities caused by a known issue already considered for a bug bounty.

  • Be at least 18 years of age or, if younger, submit your vulnerability with the consent of your parent or guardian.

  • Not be subject to US sanctions or reside in a US-embargoed country.

  • Not be one of our current or former employees, vendors, contractors, or employees of any of those vendors or contractors.

  • Comply with all the eligibility requirements of the Program.

Other Terms

By submitting your report, you grant Aquarius all rights, including intellectual property rights, needed to validate, mitigate, and disclose the vulnerability. All reward decisions, including eligibility, reward amounts, and how such rewards will be paid, are made at our discretion.

Aquarius may alter the terms and conditions of this Program at any time.

🪲
emergency fund