Bounty

BOUNTY PROGRAM

The security of the Dapp is our highest priority. All contract code and balances are publicly verifiable, and security researchers are eligible to receive a bug bounty for reporting undiscovered vulnerabilities.

AUDIT

Plenny encourages the community to audit our contracts and security; we also encourage the responsible disclosure of any issues.
The contracts and the oracle in the directory of the repository have been carefully audited by third-party experts.

SCOPE

In scope:
  • Being able to steal funds.
  • Being able to freeze funds or render them inaccessible by their owners.
  • Being able to perform attacks on the Dapp.
Out of scope:
  • The scope of our bounty program does not include known issues, already reported errors, problems of third-party applications or tools, and false positives. Our documentation shows extensive information about the intended behavior.

TERMS

  • If you comply with the terms when reporting a security issue, we will not initiate an investigation against you.
  • Avoid violating the privacy of others, disrupting our systems, destroying data, or harming user experience.
  • Keep the details of any discovered vulnerabilities confidential until they are publicly announced by Plenny.crypto.
  • Not engage in blackmail, extortion, breach of contract or any other unlawful conduct.
  • Rewards will be paid in Plenny, PL2.

SUBMISSIONS

Please use our contact form.
The submission must include clear and concise steps to reproduce the discovered vulnerability in either written or video format.

REWARDS

All reward determinations, including eligibility and payment amount, are made at sole discretion of Plenny.crypto.