| Scope is precise |
In-scope contracts, chains, frontends, domains, APIs, and excluded assets. |
Security lead |
Researchers can tell whether a report belongs in the program. |
Critical off-chain or frontend paths are excluded by accident. |
| Severity is calibrated |
Rubric tied to funds at risk, governance impact, user deception, and operational compromise. |
Security lead |
Triage decisions are consistent and explainable. |
Frontend, oracle, or governance impact is undervalued. |
| Safe testing rules are clear |
Allowed PoC rules, fork guidance, rate limits, and user harm boundaries. |
Legal and security |
Researchers can prove impact without touching user funds or secrets. |
Testing guidance is vague and creates conflict during real reports. |