> For the complete documentation index, see [llms.txt](https://wiki.fishingfrenzy.co/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://wiki.fishingfrenzy.co/official-docs/bug-bounty.md).

# Bug Bounty

We recognise the importance and value of security researchers' efforts to keep our community safe. We encourage responsible disclosure of security vulnerabilities via our bug bounty program.&#x20;

### Policy

* Do not share reports to any blog or social network if not approved by Fishing Frenzy
* While researching, refrain from:
  * Doing automated testing, denial of service
  * Spamming, spoofing, phishing
  * Social engineering of staff or  contractors
  * Any physical attempts
  * Performing further attacks once you have proof of an attack
  * Bulk downloading / extracting exposed data beyond the need for proof of concept

### Rewards

{% hint style="info" %}
We are eager to work with security researchers to ensure all findings are fairly rewarded. We may award additional rewards for exceptional reports. All reward amounts are at our full discretion.&#x20;
{% endhint %}

<table><thead><tr><th width="141.63671875">Severity</th><th width="436.53125">Definition</th><th>Typical Amount </th></tr></thead><tbody><tr><td>Critical (P1)</td><td><p>Direct, high-impact vulnerabilities that allow attackers to cause large-scale financial loss to the company or players, extract or duplicate assets, manipulate game economy, or completely break core gameplay systems.</p><p></p><p>Examples:</p><ul><li>Minting unlimited NFTs without paying</li><li>Unauthorized transfer of smart contract funds</li></ul></td><td>1000 RON - 10000+ RON**</td></tr><tr><td>High (P2)</td><td><p>Significant vulnerabilities that impact game economy, player trust, or company revenue, but require specific conditions to execute, or cause losses at smaller scale compared to P1.</p><p></p><ul><li>Manipulating leaderboard rewards</li><li>Buying or obtaining premium items for free </li><li>Duplication of assets requiring moderate effort</li></ul></td><td>200 RON - 1000 RON</td></tr><tr><td>Medium (P3)</td><td><p>Vulnerabilities that cause minor or limited financial impact, or affect fairness and trust but do not lead to direct major monetary loss. </p><p></p><p>Examples</p><ul><li>Claiming duplicate rewards</li><li>Minor inconsistencies in reward calculations </li><li>Bugs allowing for faster than intended level-up</li></ul></td><td>50 RON - 200 RON</td></tr><tr><td>Low (P4)</td><td><p>Very low-impact issues that are primarily cosmetic, informational, or theoretical</p><p></p><p>Examples</p><ul><li>Typographical errors</li><li>Visual errors </li></ul></td><td>0 RON</td></tr></tbody></table>

**\*\* Bounty will vary widely based on severity and impact**

### Reporting

If you have identified a security vulnerability please do the following:

* Email <support@uncharted.gg> and include the following information:
  * Your contact details (name, email)
  * Full proof of concept (step by step to reproduce) and impact
  * Any files **uploaded to Google Drive** that can help reproduce the flaw (screenshots, images, source code, scripts)
* Open up a support ticket in [Discord](https://discord.gg/unchartedgg) to alert our mods if it is time sensitive

### Eligibility

* Vulnerabilities have a working proof of concept that shows how it can be exploited
* First user to bring the issue to our attention, before we are aware of it
* Do not abuse the issue
* Certain types of issues will be ineligible and out of scope, such as:

  * Internally known issues, duplicate issues, or issues which have already been made public
  * Theoretical vulnerabilities without proof of concept
  * Vulnerabilities with third party software such as Privy wallet (see their [bug bounty program](https://www.privy.io/vulnerability-disclosure)) or marketplaces such as Ronin Marketplace&#x20;
  * Incorrect data supplied by third party oracles
  * Sybil attacks or fake user generation

### Assets in Scope

**Smart contracts:**

0x9c76fc5Bd894E7F51c422F072675c876d5998A9e

0x6d5104435be31A51a8261056c347824481632FaB

0x77CE5148b7ad284e431175Ad7258B54A64816da6

0x87a699a08D57142d46c909B7f2df49D44D87211F

0x4079da822E8972982b8569e38cdF719A21069934

0xc4537D98b3d4A2A8EC79aaEFb19b4ceB72953Fcd

0xC69f7434D4B336E68AcBbde4101B7990E7d6B3b3

0xDDA950223EAD838C21838109a2f550C964A23C5b

**Web/App:**

* <https://fishingfrenzy.co&#x20>;
