| Impact | Likelihood | Severity |
|---|---|---|
| High | High | Critical |
| High | Medium | Severe |
| High | Low | Moderate |
| Medium | High | Severe |
| Medium | Medium | Moderate |
| Medium | Low | Low |
| Low | High | Moderate |
| Low | Medium | Low |
Likelihood: Likelihood represents the possibility that a particular vulnerability is discovered and exploited.
Impact: Impact measures the loss caused by an attack using this vulnerability.
Severity: Severity indicates the magnitude of the vulnerability.
Likelihood and impact are divided into three levels: high, medium and low.
Severity is decided by likelihood and impact with four levels: critical, severe, moderate and low.
| Technical severity | Reward range |
|---|---|
| P1 - Critical | $ 1,001 or above |
| P2 - Severe | $ 501 - $ 1,000 |
| P3 - Moderate | $ 201 - $ 500 |
| P4 - Low | $ 10 - $ 200 |
ℹ️ https://github.com/TorchesFinance/torches-protocol
Vulnerabilities that could undermine the fund safety of any user or business runner, including:
- Vulnerabilities that could undermine the safety of any user's fund/fee.
- Vulnerabilities that could severely undermine trading or token economy.
- Vulnerabilities that could disrupt the governance of protocol.
Vulnerabilities with similar impact as P1 vulnerabilities, but are dependent on specific prerequisites, including:
- Vulnerabilities that could undermine or disrupt trading or token economy.
- Vulnerabilities that could disrupt or manipulate the oracle price feed service.
- Vulnerabilities that could cause user can not redeem their funds and rewards.
Vulnerabilities of critical functions, including:
- Failed to call deposit or withdraw funtcion of contracts.
- Config params mismatch.
Client and UI bugs, including:
- Web UI bugs.
- Failure to load data.
- Some query functions cannot be used.
Not including:
- Speculation without any evidence. Including but not limited to:
- Theoretical vulnerabilities.
- Use of known vulnerable libraries without actual proof of concept.
- Phishing (E.g. HTTP Basic Authentication Phishing).
- Internally known issues, duplicate issues, or issues which have already been made public.
Open new issues with template on github Repo
Wait for response ;-)
