Rewards by threat level
Smart-contract
Threat description
- Missing zero address checks in critical functions
- Events not matching actual state changes: incorrect event emits
- Lack of input validation, allowing illogical or invalid parameter values.
Medium
up to
100 $USDT
High
up to
500 $USDT
Critical
up to
1000 $USDT
Rewards by threat level
Website
Low
up to
5 $USDT
Description
- Minor logical errors
- Modification of other users' data (including changes to browser local storage) without interacting with a connected wallet and requiring significant user interaction, such as:•IFrame causing changes to backend/browser state (must demonstrate impact via PoC)
- Redirection to broken or outdated links
- Temporary denial of user access to the target site, such as:•Login blocking•Cookie bombing, etc.
- Technical information leakage
Medium
up to
40 $USDT
High
up to
100 $USDT
Critical
up to
500 $USDT
Prohibited actions

Testing on mainnet without permission
Social engineering and phishing
Accessing other users' data
Public disclosure before a fix is implemented
Destructive attacks (DDoS, spam)
Report submission process
- 1Discover a vulnerability within the defined scope
- 2Prepare a detailed report with a Proof of Concept (PoC)
- 3Submit it via the official Google Form
- 4The team will review it within 5 business days
- 5Receive your reward in BoBe tokens upon confirmation
Report requirements
- 1Proof of Concept (PoC) for all severity levels
- 2Detailed reproduction steps
- 3Assessment of potential impact
- 4Remediation recommendations
Please note: This program applies only to the website
https://test.bobe.app
Other subdomains are not within scope.