Bug Bounty Programme
Effective date: 21st July, 2026 Last updated: 21st July, 2026 Status: Active
1. Overview
Klima Protocol operates a standing, self-hosted bug bounty program covering vulnerabilities that place Protocol or user funds at risk. The program is intentionally narrow: it rewards Critical (and, at the Protocol's discretion, High) severity findings only.
We do not pay rewards for Medium, Low, or Informational findings. Researchers who responsibly disclose non-critical issues will be credited if desired, but no monetary reward will be issued. This structure exists so that researcher attention is concentrated where it protects users most.
This program is run under the Primacy of Rules: the terms on this page govern all submissions and payouts in full.
2. Scope
2.1 In-scope assets
Klima v2 mainnet deployment contracts on Base mainnet are in scope.
2.2 Out-of-scope assets
Legacy KlimaDAO (1.0) contracts on Polygon
Frontend websites, documentation sites, Discord, and other off-chain infrastructure
Third-party contracts and dependencies (e.g., Aerodrome pools, bridges, oracles not deployed by the Protocol), except insofar as a flaw in our integration with them causes a Critical impact
Testnet deployments and mock/test files
3. Rewardable impacts
Only the following impacts qualify for a monetary reward:
Critical
Direct theft of user or Protocol funds (principal), whether at rest or in motion
Permanent freezing or destruction of user or Protocol funds
Unauthorized minting of $kVCM or $K2
Unauthorized upgrade of any proxy, or takeover of admin/owner privileges
Manipulation of AAM pricing or accounting resulting in direct extraction of value from the Protocol
High (discretionary)
Theft or permanent loss of unclaimed yield or rewards
Temporary freezing of user funds requiring intervention to resolve
All other impacts — including griefing without attacker profit, gas inefficiencies, front-running of individual transactions, and theoretical issues — are not rewardable.
4. Rewards
Severity
Reward
Critical
10% of funds directly at risk, minimum $2,500, up to a maximum of $20,000
High
Up to $5,000, at the Protocol's sole discretion
"Funds at risk" is calculated as of the time and date the report is submitted.
Rewards are denominated in USD and paid in USDC on Base.
Where the vulnerable contract can be paused or upgraded to prevent the impact, only the initial attack (before intervention) is considered when calculating funds at risk, and severity may be adjusted accordingly.
If multiple reports describe the same underlying vulnerability, only the first valid submission (by timestamp) is eligible.
One reward per underlying root cause, regardless of the number of attack paths described.
5. Submission requirements
To be eligible for a reward, every submission must include:
A working proof of concept (PoC). A runnable test or script (e.g., Foundry/Hardhat fork test against Base mainnet state) demonstrating the exploit end-to-end. Descriptions, hypotheses, and AI-generated reports without a working PoC will be closed without review and are not eligible for reward.
A clear written description of the vulnerability, root cause, and impact.
The specific in-scope asset(s) affected.
A suggested remediation (optional but appreciated).
Submit to: security@klimaprotocol.com
We will acknowledge receipt within 3 business days and provide a substantive response (accepted / rejected / more information needed) within 14 days.
6. Rules of engagement
Security research conducted in good faith under this program is authorized, and the guidelines below exist to keep that research safe for you, for our users, and for the Protocol. We ask that you follow them:
No testing on mainnet or public testnets. All testing must be performed on local forks.
No denial-of-service attacks, spam, or automated traffic against Protocol infrastructure.
No phishing or social engineering against contributors, users, or partners.
No exploitation beyond the minimum necessary to demonstrate the vulnerability. Never access, modify, or exfiltrate funds or data belonging to others.
No public disclosure of an unpatched vulnerability. Coordinated disclosure only, after a fix is deployed and with the Protocol's written agreement.
Do not attempt to extort or condition disclosure on payment beyond the published reward terms.
Safe harbor
Klima Protocol considers security research conducted under this program in good faith to be authorized conduct. If you make a good-faith effort to comply with these guidelines, we will:
Consider your research authorized, and not pursue or support any legal action against you in connection with it;
Work with you to understand and resolve the issue quickly; and
Treat a good-faith, unintentional deviation from these guidelines as forgivable — an honest mistake in the course of good-faith research does not by itself forfeit safe-harbor protection, provided you did not cause harm to users or the Protocol, and you promptly disclose and remediate any such deviation.
Safe harbor does not extend to conduct that is not in good faith, including: theft or retention of funds beyond a demonstrated proof of concept, extortion or conditioning disclosure on payment beyond the published terms, deliberate harm to users, public disclosure of an unpatched vulnerability, or initiating an exploit. Nothing in this section is a waiver of any rights of third parties, and it cannot authorize conduct that violates applicable law; where a good-faith researcher nonetheless faces third-party or legal action, we will make clear publicly that their research was authorized under this program.
7. Ineligible findings
The following are explicitly not eligible for reward, regardless of framing:
Bugs already identified by auditors
Any finding without a working PoC
Issues in third-party dependencies or infrastructure
Theoretical vulnerabilities without a demonstrable, economically rational on-chain attack path
Attacks requiring privileged access (admin keys, multisig signers, governance majority); these are trust assumptions, not vulnerabilities, unless the report demonstrates how that access is obtained by an attacker
Attacks relying on external market conditions (e.g., oracle prices moving, liquidity being drained by third parties) without a Protocol-level flaw
Gas optimizations, code style, best-practice deviations, and informational findings
Vulnerabilities already mitigated by deployed pause/upgrade mechanisms where no funds can actually be lost
Sybil attacks on governance requiring capital outlay exceeding the attack's proceeds
Findings from automated scanners or AI tools submitted without validation and a working PoC
8. Eligibility
Open to anyone, except: current contributors and contractors of Klima Protocol / Klima Foundation; former contributors within 12 months of their engagement ending; and anyone who participated in the development or audit of the affected code.
Researchers must not be subject to sanctions (OFAC/UNSC) or resident in a jurisdiction where participation or payment would be unlawful.
Basic KYC (name, country of residence, wallet address) is required before payout of any Critical reward.
9. Payment process
Report validated and severity agreed.
Fix developed and deployed (researcher may be asked to verify the fix under embargo).
KYC completed.
Payment issued in USDC on Base to the researcher's provided address within 60 days of validation.
With the researcher's consent, credit published on the Security Acknowledgements page.
10. Lower severity findings
We genuinely appreciate reports of lower-severity issues, and we will:
Acknowledge and review them on a best-effort basis
Credit the researcher publicly (with consent)
We will not pay monetary rewards for them, negotiate exceptions, or respond to escalation attempts.
11. Program changes
Klima Protocol may amend scope, rewards, or terms at any time. Changes apply prospectively; submissions are governed by the terms in effect at the time of submission. Reward caps will be reviewed as Protocol grows.
Last updated
