Created
August 16, 2026 00:32
-
-
Save joswell78/81c4f961bc91c411d3edd140e32b5334 to your computer and use it in GitHub Desktop.
Find Critical Vulnerabilities in Veilo Mainnet Smart Contracts for Fund Loss — Hermes autonomous code
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| **IMPROVED DRAFT:** | |
| --- | |
| <h2 class="heading-node">Find Critical Vulnerabilities in Veilo Mainnet Smart Contracts for Fund Loss</h2> | |
| <p class="text-node">Veilo Layer is an all-in-one privacy app for Solana that lets users send, swap, trade, buy and sell memecoins, access perps, use prediction markets, buy tokenized stocks, bridge assets, and interact with supported dApps privately through a wallet and browser extension.</p> | |
| <h2 class="heading-node">Mission</h2> | |
| <p class="text-node">Find critical vulnerabilities in Veilo’s mainnet smart contracts that could directly lead to user fund loss.</p> | |
| <h2 class="heading-node">Scope Detail</h2> | |
| <p class="text-node">We are looking for verifiable vulnerabilities that could cause:</p> | |
| <ul class="list-node"> | |
| <li><p class="text-node">Loss of user funds</p></li> | |
| <li><p class="text-node">Unauthorized withdrawals</p></li> | |
| <li><p class="text-node">Theft of user funds</p></li> | |
| <li><p class="text-node">Unauthorized movement of funds from Veilo contracts</p></li> | |
| <li><p class="text-node">Critical logic, accounting, access control, or withdrawal bugs that could allow funds to be extracted</p></li> | |
| </ul> | |
| <p class="text-node"><strong>Mainnet Rules:</strong></p> | |
| <ul class="list-node"> | |
| <li><p class="text-node">Mainnet contracts may be reviewed, analyzed, and tested safely.</p></li> | |
| <li><p class="text-node">Do not exploit mainnet, move real funds, attack users, manipulate balances, or put live funds at risk.</p></li> | |
| <li><p class="text-node">Valid proof can be shown through:</p> | |
| <ul class="list-node"> | |
| <li><p class="text-node">Mainnet contract analysis</p></li> | |
| <li><p class="text-node">Read-only calls</p></li> | |
| <li><p class="text-node">Transaction simulation</p></li> | |
| <li><p class="text-node">Local fork testing using mainnet state</p></li> | |
| <li><p class="text-node">Clear reproducible proof-of-concept</p></li> | |
| </ul> | |
| </li> | |
| </ul> | |
| <p class="text-node"><br>This bounty applies exclusively to Veilo’s deployed onchain Solana program and does not cover the website, browser extension, wallet interface, backend services, APIs, infrastructure, or other offchain components.<br></p> | |
| <p class="text-node"><strong>Out of Scope:</strong></p> | |
| <ul class="list-node"> | |
| <li><p class="text-node">UI-only bugs</p></li> | |
| <li><p class="text-node">Gas optimization</p></li> | |
| <li><p class="text-node">Theoretical issues without proof</p></li> | |
| <li><p class="text-node">Social engineering or phishing</p></li> | |
| <li><p class="text-node">DoS issues without fund loss</p></li> | |
| <li><p class="text-node">Duplicate or already known issues</p></li> | |
| <li><p class="text-node">Reports that require harming users or moving live funds</p></li> | |
| </ul> | |
| <h2 class="heading-node">Submission Requirements</h2> | |
| <p class="text-node">Submissions must include:</p> | |
| <ul class="list-node"> | |
| <li><p class="text-node">Affected mainnet contract or function</p></li> | |
| <li><p class="text-node">Clear explanation of the issue</p></li> | |
| <li><p class="text-node">How it leads to fund loss</p></li> | |
| <li><p class="text-node">Reproducible proof or simulation</p></li> | |
| <li><p class="text-node">Suggested fix</p></li> | |
| <li><p class="text-node">Confirmation that no live funds were moved or put at risk</p></li> | |
| <li><p class="text-node">Submissions must be in English.</p></li> | |
| </ul> | |
| <h2 class="heading-node">Submission Instructions</h2> | |
| <p class="text-node">Submit the report directly through the Superteam bounty submission page.</p> | |
| <p class="text-node">The submission should contain the complete technical report, proof-of-concept, simulation results, affected program instructions or functions, reproduction steps, impact assessment, and recommended remediation.</p> | |
| <p class="text-node">Any supporting files, scripts, transaction simulations, screenshots, videos, or private repositories must be accessible to the Veilo team for review.</p> | |
| <p class="text-node">Do not publish or publicly disclose any discovered vulnerability before Veilo has reviewed and resolved the issue.<br></p> | |
| <h2 class="heading-node">Judging Criteria</h2> | |
| <p class="text-node">The winning submission will be awarded for the most:</p> | |
| <ul class="list-node"> | |
| <li><p class="text-node">Valid vulnerability</p></li> | |
| <li><p class="text-node">Reproducible vulnerability</p></li> | |
| <li><p class="text-node">High-impact vulnerability</p></li> | |
| <li><p class="text-node">Vulnerability that shows a realistic path to loss of funds from Veilo’s mainnet contracts</p></li> | |
| <li><p class="text-node">Clarity and completeness of the explanation</p></li> | |
| <li><p class="text-node">Quality of the suggested fix</p></li> | |
| </ul> | |
| <h2 class="heading-node">Resources</h2> | |
| <ul class="list-node"> | |
| <li><p class="text-node">Mainnet Program — Veilo / privacy_pool: GYy4kM6GHhpgLCUscuABbzkD2ZbJ2fneYryaZ6Ch7fFU</p></li> | |
| <li><p class="text-node">Solscan: <a target="_blank" rel="noopener noreferrer" class="link" href="https://solscan.io/account/GYy4kM6GHhpgLCUscuABbzkD2ZbJ2fneYryaZ6Ch7fFU">solscan.io</a></p></li> | |
| <li><p class="text-node">Solana Explorer: <a target="_blank" rel="noopener noreferrer" class="link" href="https://explorer.solana.com/address/GYy4kM6GHhpgLCUscuABbzkD2ZbJ2fneYryaZ6Ch7fFU">explorer.solana.com</a></p></li> | |
| <li><p class="text-node">Application / Website: <a target="_blank" rel="noopener noreferrer" class="link" href="https://veilo.network">veilo.network</a></p></li> | |
| <li><p class="text-node">Product Documentation: <a target="_blank" rel="noopener noreferrer" class="link" href="https://docs.veilo.network">docs.veilo.network</a></p></li> | |
| <li><p class="text-node">Source Repository: <a target="_blank" rel="noopener noreferrer" class="link" href="https://github.com/VeiloSolana/privacy-program">github.com</a></p></li> | |
| </ul> | |
| <h2 class="heading-node">Reward Structure</h2> | |
| <ul class="list-node"> | |
| <li><p class="text-node">1st Place: 2,000 USDC</p></li> | |
| </ul> |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment