Security policy and vulnerability disclosure
BullBearSwap takes reports of security issues privately, fixes them, and credits the reporter.
This page is the reporting contact the security review (docs/security/SECURITY_REVIEW_2026_09_08.md)
did not carry. Please do not post exploit details publicly before a fix is live.
How to report
Please DM your submission on our social channels or Telegram: @bullbearswap on X, or
@bullbearswap on Telegram. Email works too: security@bullbearswap.com (subject
[BBS security] <one-line summary>); use it for long write-ups, attachments or a fork replay
that does not fit a DM.
- Include: the affected component (contract address and chain, or the app URL), steps to reproduce (an anvil fork replay is ideal), the impact you believe it has, and an address for the reward.
- Do not post details in public replies or group chats; a DM or the email is private, a thread is not.
- Email replies come from the team's Proton Mail address; the security@ address is a forward to it. If you need encryption, ask for our PGP key first and we will reply with it.
You will get a human acknowledgement within 48 hours and a severity assessment within 7 days. We will tell you when the fix ships and agree a disclosure date with you. Reports are credited publicly in the security folder unless you ask otherwise.
Scope
In scope:
- The settlement contracts: Ethereum
0xFF73837F97f43BE5b05c20Ae71FDeB11487E2d1a, PulseChain0x5542F6BCe5261377Fe4cF66ABbB2d126744C9271(verified source). - The swap app at
app.bullbearswap.comand its API, including the quote, fee attestation and relayed-order (Permit2) flow.
Out of scope: third-party venues the contract routes through (Uniswap, Curve, Balancer, PulseX and the others), wallets, RPC providers, and issues that need a compromised user device or key. Denial of service against the quote server is out of scope unless it leads to a wrong settlement.
Rules
- Test on a fork. Do not exploit on mainnet with other users' funds, and do not extract more than the minimum needed to prove the issue with your own.
- No social engineering, no spam, no automated scanning of the live API beyond what a normal user produces.
- One report per issue; the first complete report of an issue is the one rewarded.
Rewards
The contracts are immutable, so a critical finding is fixed by pausing the app and redeploying, not by patching in place; the reward is for telling us first. Rewards are paid in USDC (or the chain's native token) and scale with impact:
| Severity | What it means | Reward |
|---|---|---|
| Critical | Loss or theft of user funds through the contract or the relayed-order flow | up to 2,500 USDC |
| High | Users receive materially less than the enforced minimum, fee charged where the contract forbids it, or a way to make the settlement pay a third party | up to 750 USDC |
| Medium | Wrong quotes or attestations that a user can be made to sign without loss beyond the signed floor; app-side issues that expose user data | up to 250 USDC |
| Low / Informational | Hardening, best-practice and gas findings | public credit |
Amounts are caps, paid from protocol fee revenue, and will rise as that revenue grows. The final figure depends on impact, quality of the report and whether it came with a working reproduction. Duplicates, findings already listed in the published security review, and theoretical issues without a path to impact are credited but not paid.
Working with researchers
The table is a baseline, not a ceiling. An exceptional report, or a researcher who keeps finding things, is paid above it; we would rather pay a good reporter twice than argue once. Everyone credited here gets a look at what ships next, before the public does: more products will run on the same contracts and infrastructure, and we want the people who understand them on our side for the long term. As protocol revenue grows, the caps grow with it.
What is already known
Everything in the published review is already known and is credited but not paid again. That is:
every automated-analysis finding (Slither and Aderyn, both builds) with its explanation; every
item in the line-by-line manual review — the fee-function revert on an absurd attestor-signed
quote, the fee being voluntary at the contract level, the V4 mask not covering dynamic LP fees,
the V2 adapter not checking edge.tokenOut, fee-on-transfer sell tokens reverting, the native
partial-fill behaviour on the Ekubo/V4 modes, and the attestation digest binding neither caller
nor a nonce; every stale comment listed there; and all eight hardening items scheduled for the
next deployment. The five-question board and the findings ledger on the security page summarise
these. Please read the review before reporting: it, and the page that summarises it, are where
"already known" is defined.