defirisk.co
rubric v1.7.0

Bug bounty scope gap on highest-TVL contracts

A code & audits factor in the v1.7.0 rubric. Measured per protocol on a s cadence.

Methodology how we score#

What this measures
This factor identifies whether the protocol's highest-TVL contracts -- particularly shared-primitive contracts such as LayerZero OFT adapters, ZK verifiers, or bridge inbox contracts -- are explicitly excluded from the scope of the protocol's bug bounty program, while other (lower-TVL) contracts remain in scope. The assessment cross-references the Immunefi scope definition and protocol bounty documentation against the contract addresses that collectively hold the majority of user funds.

Why it matters
A bug bounty program that excludes the contracts holding the most value provides economic incentive for researchers to disclose only the low-value vulnerabilities, while the highest-risk surfaces remain economically unprotected from exploit. Kelp DAO's April 2026 exploit ($292M) is the clearest documented case: the protocol ran an active Immunefi program for its core rsETH contracts, but the LayerZero OFT adapter -- the contract through which the exploiter minted unbacked tokens -- was explicitly excluded from bounty scope despite holding over $1B in bridged value. A whitehat who discovered the 1/1 DVN misconfiguration had no economic incentive to disclose it through the bounty channel because the scope exclusion made the report ineligible for payout.

Green / Yellow / Red
Green: the protocol's bug bounty scope explicitly includes all contracts that collectively hold more than 80% of TVL, including any bridge adapters, OFT contracts, or shared primitives. Yellow: the bounty scope includes primary lending or swap contracts but excludes some integration contracts (bridges, keepers) where the excluded contracts hold less than 20% of TVL. Red: any contract that individually holds more than $10M in TVL or more than 20% of protocol TVL is explicitly excluded from the bounty scope.

Common gray cases
This factor is gray when the protocol does not have a bounty program at all (captured separately by RD-F-007), or when the bounty scope documentation is ambiguous and curator review cannot determine inclusion or exclusion of specific contracts.

Notable historical examples
No hacks are currently linked in the database for this specific factor. The Kelp DAO case (April 2026, $292M) is the primary motivating incident; the factor was added in the v1.1 batch-24 pass precisely because the bounty scope gap was identified as a direct contributor to that exploit's severity.

Measurement what to look for#

Determine whether the highest-TVL contracts of this protocol (especially shared primitives: OFT adapters, ZK verifiers, bridge inbox) are explicitly excluded from the protocol's active bug bounty scope.

Data & output #

Data source
Immunefi API bounty scope field + protocol security docs + curator review of in-scope/out-of-scope contract list vs on-chain TVL by contract address
Output format
Green / Yellow / Red
Evidence artifact
Immunefi program URL + scope JSON (in/out-of-scope contract list) + curator note mapping highest-TVL contracts to scope status
Confidence signal
green = highest-TVL contracts are in scope; yellow = scope ambiguous or partially covers high-TVL contracts; red = highest-TVL contracts explicitly out of scope; gray = no bug bounty program exists (see RD-F-007)

Scored protocols 0 carry this factor#

No protocols have been scored for this factor yet.

Linked hacks no historical incidents linked#

No historical incidents are linked to this factor.
rubric_version v1.7.0factor RD-F-183category 1carried 0critical no