> For the complete documentation index, see [llms.txt](https://docs.klimaprotocol.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.klimaprotocol.com/reference/bug-bounty-programme.md).

# Bug Bounty Programme

### 1. Overview

Klima Protocol operates a standing, self-hosted bug bounty program covering vulnerabilities that place Protocol or user funds at risk. The program is intentionally narrow: it rewards Critical (and, at the Protocol's discretion, High) severity findings only.

We do not pay rewards for Medium, Low, or Informational findings. Researchers who responsibly disclose non-critical issues will be credited if desired, but no monetary reward will be issued. This structure exists so that researcher attention is concentrated where it protects users most.

This program is run under the Primacy of Rules: the terms on this page govern all submissions and payouts in full.

### 2. Scope

#### 2.1 In-scope assets

Klima v2 mainnet deployment contracts on Base mainnet are in scope.&#x20;

#### 2.2 Out-of-scope assets

* Legacy KlimaDAO (1.0) contracts on Polygon
* Frontend websites, documentation sites, Discord, and other off-chain infrastructure
* Third-party contracts and dependencies (e.g., Aerodrome pools, bridges, oracles not deployed by the Protocol), except insofar as a flaw in our integration with them causes a Critical impact
* Testnet deployments and mock/test files

***

### 3. Rewardable impacts

Only the following impacts qualify for a monetary reward:

#### Critical

* Direct theft of user or Protocol funds (principal), whether at rest or in motion
* Permanent freezing or destruction of user or Protocol funds
* Unauthorized minting of $kVCM or $K2
* Unauthorized upgrade of any proxy, or takeover of admin/owner privileges
* Manipulation of AAM pricing or accounting resulting in direct extraction of value from the Protocol

#### High (discretionary)

* Theft or permanent loss of unclaimed yield or rewards
* Temporary freezing of user funds requiring intervention to resolve

All other impacts — including griefing without attacker profit, gas inefficiencies, front-running of individual transactions, and theoretical issues — are not rewardable.

***

### 4. Rewards

| Severity | Reward                                                                    |
| -------- | ------------------------------------------------------------------------- |
| Critical | 10% of funds directly at risk, minimum $2,500, up to a maximum of $20,000 |
| High     | Up to $5,000, at the Protocol's sole discretion                           |

* "Funds at risk" is calculated as of the time and date the report is submitted.
* Rewards are denominated in USD and paid in USDC on Base.
* Where the vulnerable contract can be paused or upgraded to prevent the impact, only the initial attack (before intervention) is considered when calculating funds at risk, and severity may be adjusted accordingly.
* If multiple reports describe the same underlying vulnerability, only the first valid submission (by timestamp) is eligible.
* One reward per underlying root cause, regardless of the number of attack paths described.

***

### 5. Submission requirements

To be eligible for a reward, every submission must include:

1. A working proof of concept (PoC). A runnable test or script (e.g., Foundry/Hardhat fork test against Base mainnet state) demonstrating the exploit end-to-end. Descriptions, hypotheses, and AI-generated reports without a working PoC will be closed without review and are not eligible for reward.
2. A clear written description of the vulnerability, root cause, and impact.
3. The specific in-scope asset(s) affected.
4. A suggested remediation (optional but appreciated).

Submit to: <security@klimaprotocol.com>

We will acknowledge receipt within 3 business days and provide a substantive response (accepted / rejected / more information needed) within 14 days.

***

### 6. Rules of engagement

Security research conducted in good faith under this program is authorized, and the guidelines below exist to keep that research safe for you, for our users, and for the Protocol. We ask that you follow them:

* No testing on mainnet or public testnets. All testing must be performed on local forks.
* No denial-of-service attacks, spam, or automated traffic against Protocol infrastructure.
* No phishing or social engineering against contributors, users, or partners.
* No exploitation beyond the minimum necessary to demonstrate the vulnerability. Never access, modify, or exfiltrate funds or data belonging to others.
* No public disclosure of an unpatched vulnerability. Coordinated disclosure only, after a fix is deployed and with the Protocol's written agreement.
* Do not attempt to extort or condition disclosure on payment beyond the published reward terms.

#### Safe harbor

Klima Protocol considers security research conducted under this program in good faith to be authorized conduct. If you make a good-faith effort to comply with these guidelines, we will:

* Consider your research authorized, and not pursue or support any legal action against you in connection with it;
* Work with you to understand and resolve the issue quickly; and
* Treat a good-faith, unintentional deviation from these guidelines as forgivable — an honest mistake in the course of good-faith research does not by itself forfeit safe-harbor protection, provided you did not cause harm to users or the Protocol, and you promptly disclose and remediate any such deviation.

Safe harbor does not extend to conduct that is not in good faith, including: theft or retention of funds beyond a demonstrated proof of concept, extortion or conditioning disclosure on payment beyond the published terms, deliberate harm to users, public disclosure of an unpatched vulnerability, or initiating an exploit. Nothing in this section is a waiver of any rights of third parties, and it cannot authorize conduct that violates applicable law; where a good-faith researcher nonetheless faces third-party or legal action, we will make clear publicly that their research was authorized under this program.

***

### 7. Ineligible findings

The following are explicitly not eligible for reward, regardless of framing:

* Bugs already identified by auditors
* Any finding without a working PoC
* Issues in third-party dependencies or infrastructure
* Theoretical vulnerabilities without a demonstrable, economically rational on-chain attack path
* Attacks requiring privileged access (admin keys, multisig signers, governance majority); these are trust assumptions, not vulnerabilities, unless the report demonstrates how that access is obtained by an attacker
* Attacks relying on external market conditions (e.g., oracle prices moving, liquidity being drained by third parties) without a Protocol-level flaw
* Gas optimizations, code style, best-practice deviations, and informational findings
* Vulnerabilities already mitigated by deployed pause/upgrade mechanisms where no funds can actually be lost
* Sybil attacks on governance requiring capital outlay exceeding the attack's proceeds
* Findings from automated scanners or AI tools submitted without validation and a working PoC

***

### 8. Eligibility

* Open to anyone, except: current contributors and contractors of Klima Protocol / Klima Foundation; former contributors within 12 months of their engagement ending; and anyone who participated in the development or audit of the affected code.
* Researchers must not be subject to sanctions (OFAC/UNSC) or resident in a jurisdiction where participation or payment would be unlawful.
* Basic KYC (name, country of residence, wallet address) is required before payout of any Critical reward.

***

### 9. Payment process

1. Report validated and severity agreed.
2. Fix developed and deployed (researcher may be asked to verify the fix under embargo).
3. KYC completed.
4. Payment issued in USDC on Base to the researcher's provided address within 60 days of validation.
5. With the researcher's consent, credit published on the Security Acknowledgements page.

***

### 10. Lower severity findings

We genuinely appreciate reports of lower-severity issues, and we will:

* Acknowledge and review them on a best-effort basis
* Credit the researcher publicly (with consent)

We will not pay monetary rewards for them, negotiate exceptions, or respond to escalation attempts.

***

### 11. Program changes

Klima Protocol may amend scope, rewards, or terms at any time. Changes apply prospectively; submissions are governed by the terms in effect at the time of submission. Reward caps will be reviewed as Protocol grows.

***

<br>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.klimaprotocol.com/reference/bug-bounty-programme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
