Overview
Once you’ve found an attackable contract, execute your exploit and handle funds according to the Safe Harbor terms.Before Attacking
- Verify contract is in
UNDER_ATTACKorPROMOTION_REQUESTEDstate - Confirm contract is in the agreement’s scope
- Note the recovery address
- Understand the bounty terms
Execute Your Exploit
There are no restrictions on how you attack in-scope contracts:Handle Recovered Funds
If Retainable = true
Keep your bounty, send the rest:If Retainable = false
Send all funds to recovery:Multiple Token Types
Handle each token type:Bounty Calculation
- Recovered: $10M
- Percentage: 10%
- Cap: $5M
- Your Bounty: min($1M, $5M) = $1M
After the Attack
- Document everything: Keep transaction hashes, calculations
- Meet identity requirements: If required by the agreement
- Consider mainnet implications: If vulnerability exists on mainnet, contact the protocol privately
How to Claim Bounties
Learn more about bounty terms and caps