{"id":"4db6dd3f-e0bf-43cf-8835-3892423b790b","engagementId":"acbbb7c1-71e0-449a-aec6-46896e60b5ad","data":{"brief":{"id":"80aec9c1-a882-4b3e-b282-0ec7f447ef98","name":"Electroneum Smart Chain (ETN-SC) — EVM-Compatible Blockchain","tagline":"Help secure Electroneum's next-gen Layer 1 blockchain — a high-speed, EVM-compatible platform with instant finality, cross-chain bridging, and on-chain governance.","description":"\u003ch2\u003eProgram Overview\u003c/h2\u003e\n\n\u003cp\u003eElectroneum invites the security research community to test and help secure the Electroneum Smart Chain (ETN-SC), a next-generation EVM-compatible Layer 1 blockchain built for speed, scalability, and real-world utility.\u003c/p\u003e\n\n\u003cp\u003eETN-SC is designed to power the future of digital payments and decentralized applications. It leverages the Istanbul Byzantine Fault Tolerant (IBFT) consensus mechanism for instant finality and high throughput, while maintaining full compatibility with Ethereum tooling and smart contracts.\u003c/p\u003e\n\n\u003cp\u003eThis bounty program focuses on identifying vulnerabilities across the ETN-SC ecosystem. This includes the core blockchain protocol, RPC endpoints, smart contract deployment, validator operations, governance mechanisms, and the official block explorer. \u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003ch2\u003eProgram Rules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eWhen conducting blockchain research, please do not enact any discovered exploits in order to create a POC, for example, minting new tokens, moving users balances around or otherwise affect our user’s ability to conduct their usual operations on the blockchain and maintain their wallet balances.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eThis program relates to our production environments, behaviour that compromises the stability and integrity of the site is out of scope. For example, do not target other user's data (use one of your other sets of credentials), delete/remove/edit parts of the site, engage in any sort of DoS attack, and/or compromise any target's ability to function for other users. If you believe that you have found a vulnerability of this nature, please stop further testing and report it.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ePlease read thoroughly the code relevant to your submission before making submissions, ensuring that the vulnerability is realistic and relates to production code or scenarios. Also please do not relay proof of concepts found with AI tools without reviewing them yourself first.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Electroneum not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Electroneum, you can report it to this engagement, and is appreciated. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eCreating reports for the Smartchain Blockchain\u003c/h2\u003e\n\n\u003cp\u003eOur Smart chain Blockchain codebase (\u003ca href=\"https://github.com/electroneum/electroneum-sc/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/electroneum/electroneum-sc/\u003c/a\u003e), which contains the smart blockchain code and the code for the accompanying suite of utility programs (the blockchain client/daemon, the RPC wallet client, the command line wallet and tools for importing and exporting the blockchain). Please understand that the old legacy blockchain (\u003ca href=\"https://github.com/electroneum/electroneum\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/electroneum/electroneum\u003c/a\u003e) is NOT covered under this Bugcrowd program, there is a separate program for this part of the project.\u003c/p\u003e\n\n\u003ch2\u003eEligible Submission Types\u003c/h2\u003e\n\n\u003cp\u003eThe only vulnerability or bug submissions that will be unequivocally triaged according to the Bugcrowd taxonomy and paid out will be ones that are able to probably generate one of the following outcomes:\u003cbr\u003e\nA) Minting of new tokens or burning of tokens through a currently unknown mechanism.\u003cbr\u003e\nB) Gaming the consensus algorithm in order to gain monetary advantage or completely shut down the network or significantly affect the regularity of blocks being published to the main chain.\u003cbr\u003e\nC) Stealing other’s tokens or revealing their wallet private keys.\u003cbr\u003e\nD) Changing the blockchain data of the past and having the network accept these changes.\u003cbr\u003e\nE) Any vulnerability that allows an attacker to trick an exchange or other third party about the reality of information pertaining to transactions or blocks, by way of altering how this information is displayed in a wallet or the blockchain explorer.\u003c/p\u003e\n\n\u003cp\u003eResearchers need to explain the impact according to this list mentioned above.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eIf you have found what you believe to be a highly serious exploit that is not covered by one of these categories of outcome, please still reach out to us, as we may nonetheless award you a payout at our discretion if we believe that the vulnerability is significant enough, in that it poses a threat of a magnitude comparable to those outlined in the above categories.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch3\u003eExcluded Submission Types\u003c/h3\u003e\n\n\u003cp\u003eWhen reporting vulnerabilities, please consider (1) attack scenario / exploitability, and (2) security impact of the bug. The following issues are excluded from this engagement:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eNon-security impacting UX issues.\u003c/li\u003e\n\u003cli\u003eDeprecated Third Party Open-Source libraries are not in scope. For our own supported and actively maintained open-source libraries, we accept vulnerability reports through Bugcrowd.\u003c/li\u003e\n\u003cli\u003eVulnerabilities or weaknesses in third party applications that integrate with Electroneum.\u003c/li\u003e\n\u003cli\u003eVulnerabilities associated with creating an emulator for the mining environment that do not demonstrate the ability to dramatically increase mining function or show other security impact.\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions.\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept.\u003c/li\u003e\n\u003cli\u003eAny type of injection without demonstrating a vulnerability.\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption of our service (DoS).\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\u003c/li\u003e\n\u003cli\u003ePassword complexity-related issues\u003c/li\u003e\n\u003cli\u003eRate limiting related issues.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cp\u003eThe following are considered out of scope unless a clear and demonstrable impact on network security, consensus integrity, or user funds is shown:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTheoretical vulnerabilities without a working proof-of-concept or real-world exploitability\u003c/li\u003e\n\u003cli\u003eAttacks requiring unrealistic validator collusion or assumptions that break the trust model without technical execution\u003c/li\u003e\n\u003cli\u003eCrashes or panics in development or debug builds that do not affect production deployments\u003c/li\u003e\n\u003cli\u003eCompiler crashes (e.g., Solidity or Vyper) caused by malformed or intentionally corrupted input\u003c/li\u003e\n\u003cli\u003eSmart contract vulnerabilities in unaudited or third-party contracts not deployed or maintained by Electroneum\u003c/li\u003e\n\u003cli\u003eAttacks requiring full control over the network or unrealistic network conditions (e.g., eclipse attacks without a feasible setup)\u003c/li\u003e\n\u003cli\u003eConsensus splits caused by non-standard forks or unsupported client versions\u003c/li\u003e\n\u003cli\u003eKnown issues already documented in the GitHub repository or public roadmap\u003c/li\u003e\n\u003cli\u003eBug reports based solely on fixes already publicly committed to Ethereum or other upstream blockchains\u003c/li\u003e\n\u003cli\u003eThird-party services, infrastructure, or dependencies not maintained by Electroneum and not part of the blockchain scope\u003c/li\u003e\n\u003cli\u003eDoS attacks that do not impact consensus, validator liveness, or user funds\u003c/li\u003e\n\u003cli\u003eSocial engineering, phishing, or physical attacks\u003c/li\u003e\n\u003cli\u003eWe will not accept reports based on bugfixes that have already publicly been committed to Ethereum or any other EVM chain derived from Ethereum's codebase\u003c/li\u003e\n\u003cli\u003eWe will not accept submissions for which the issue is publicly well known and discussed upstream in the community of Ethereum or any Ethereum fork, despite not being fixed\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eImportant Notes for Researchers\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eYour report must clearly explain how the vulnerability leads to one of the outcomes listed above.\u003c/li\u003e\n\u003cli\u003eIf your finding does not fall into these categories but you believe it poses a critical risk, please still submit it. We may award a bounty at our discretion if the issue is of comparable severity.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eOther Related Programs\u003c/h2\u003e\n\n\u003cp\u003ePlease also checkout our other Bug Bounty Programs:\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://bugcrowd.com/engagements/myapp-mbb-og\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eElectroneum Wallet: Gateway to the ETN Cryptocurrency\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://bugcrowd.com/engagements/legacy-blockchain-mbb-og\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eElectroneum Legacy Blockchain: EOL\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://bugcrowd.com/engagements/anytask-mbb-og\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAnyTask: Freelancer Platform\u003c/a\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"356c62c4-37de-426b-9ee7-273e5442c421","name":"In scope","targets":[{"id":"6062be3f-f1bc-4343-920b-38bf4f1da740","uri":"https://github.com/electroneum/electroneum-sc/","name":"Smartchain Blockchain","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c22af5b6-d952-4810-a58c-51a0709b2040","sortOrder":0},"sortOrder":0,"tags":[{"id":"d8e93657-68c0-4b47-ae77-d3c15602dd5b","name":"Cryptocurrency","targetId":"6062be3f-f1bc-4343-920b-38bf4f1da740"}],"recentChangeFlags":null},{"id":"76eee80a-2acc-4b15-8bc8-d75d7fa0af81","uri":"https://blockexplorer.electroneum.com","name":"Smartchain Block Explorer","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f2a422e0-ef48-48db-9eac-c1f5241c8856","sortOrder":1},"sortOrder":1,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"76eee80a-2acc-4b15-8bc8-d75d7fa0af81"}],"recentChangeFlags":null},{"id":"456827f6-1138-429f-99fc-e9393efca880","uri":"https://testnet-blockexplorer.electroneum.com","name":"Smartchain Staging Block Explorer","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"bfd46cfc-6a2e-4ffa-b25b-da79b7e4da1c","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"456827f6-1138-429f-99fc-e9393efca880"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"49f10d8c-b07a-48f8-9f43-9209c60eb71b","p1MaxCents":1200000,"p1MinCents":500000,"p2MaxCents":600000,"p2MinCents":400000,"p3MaxCents":85000,"p3MinCents":60000,"p4MaxCents":25000,"p4MinCents":20000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":5000,"max":12000},"2":{"min":4000,"max":6000},"3":{"min":600,"max":850},"4":{"min":200,"max":250},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"acbbb7c1-71e0-449a-aec6-46896e60b5ad","code":"smartchain-mbb-og","state":"in_progress","endsAt":null,"bountyId":"207462fd-dab4-4ce2-9e1c-7134ce0eca4c","startsAt":"2025-07-08T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/engagement_brief_logos/engagement_brief/logo/80aec9c1-a882-4b3e-b282-0ec7f447ef98/11f3a1eb-61ad-43a3-a07a-6697efeca896.png","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-07-08T18:00:01.914Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/smartchain-mbb-og","changelogs":"/engagements/smartchain-mbb-og/changelog","submissions":null,"announcements":"/engagements/smartchain-mbb-og/announcements","hallOfFame":"/engagements/smartchain-mbb-og/hall_of_fames","crowdstream":"/engagements/smartchain-mbb-og/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/smartchain-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=smartchain-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/smartchain-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/smartchain-mbb-og/changelog","publishedAt":"2026-01-05T13:56:31.373Z","engagementChangelogUrl":"/engagements/smartchain-mbb-og/changelog/4db6dd3f-e0bf-43cf-8835-3892423b790b","createUserFeedbacksUrl":"/engagements/smartchain-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/smartchain-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}