Security
Bug bounty
How security reports will be rewarded.
Programme at a glance
Bounty terms, including rewards and the severity matrix, are published together with the mainnet deployment. Until then, report issues privately.
Scope
Planned scope: BarrierCore, BarrierLegs, oracle and calendar, token engine, Backstop, Omni and Credit wrappers.
Out of scope
- Third-party contracts (Chainlink, LayerZero, Morpho, Stock Tokens, USDG).
- The website, unless it leads to loss of funds.
- Issues needing a compromised governance key.
Rules of engagement
- Do not test on mainnet with real funds.
- Do not disclose before a fix ships.
- One issue per report.
Safe harbour
Good-faith research within these rules will not be pursued.
How to report now
Send a DM to @getberrier asking for a private channel. Do not post details publicly.