Shade Protocol is a suite of interconnected, privacy-focused DeFi applications built on Secret Network. At its core is Silk, an overcollateralized stablecoin that offers native transactional privacy by default. Designed to protect user data while enabling powerful financial tools, Shade Protocol brings privacy-preserving DeFi infrastructure to the Secret Network ecosystem.
Program Overview Shade Protocol runs a security-focused bug bounty program to identify vulnerabilities within its privacy-preserving smart contracts, frontend applications, and voting mechanisms. The program is designed to enhance the security of its confidential DeFi infrastructure by encouraging responsible disclosures from the security community.
Reward Structure The program uses a 4-tier severity model with distinctions based on both the target type and impact. For critical smart contract vulnerabilities, rewards are capped at 10% of the potential economic damage, primarily based on the funds at risk. In scenarios involving repeatable attacks, only the first instance is considered—unless the contract in question cannot be upgraded or paused. High-severity smart contract vulnerabilities are capped at 100% of the affected funds.
For critical website and application vulnerabilities, the payout is 10,000 SHD only if the impact causes direct loss of funds, vote manipulation, or visual misrepresentation of votes or results. All other critical frontend or app issues that do not meet these criteria will be rewarded 1,000 SHD. Reward values are calculated based on on-chain conditions at the time the bug report is submitted.
Submission Requirements All bug reports must include a working proof of concept (PoC) and clear steps to reproduce the issue. The report must demonstrate real impact on an in-scope asset or system component. Reports without code or tangible outcomes will not qualify for rewards.
Payouts Bounties are denominated in USD-equivalent value and paid in SHD, the native token of Shade Protocol. Payouts are issued by the Shade team after successful validation and KYC compliance.