Victor.hl@victortopdefig·May 14
so superform just dropped a live bug bounty on cantina and it’s actually worth looking at
critical bugs = up to 100,000 usdc & $up tokens
high severity = up to 20,000 usdc & $up
for context, superform is a non-custodial protocol that allows anyone to build and distribute onchain financial products. basically they let curators build yield vaults (supervaults) on top of multiple strategies.
the security layer is wild tho, they use a validator-attested oracle + dual merkle hook validation to keep the price per share accounting clean.
that’s a lot of moving parts which is prolly why they need researchers on it.
been live since may 1, 2026 with 22 findings already submitted
what counts as critical?
things like “direct theft of principal from any supervault,”
“unauthorized minting or inflation of supervault shares,” or bypassing the pps oracle’s signature validation.
basically if you can drain funds or fake the accounting at scale, that’s the big bag tier.
the high tier covers stuff like stealing unclaimed fees or freezing user funds for 48+ hours. medium is paid in $up only, which is lowkey a signal they don’t take those too seriously.
a few catches tho:
- kyc required before payout (yep, dox yourself first lol)
- $20 deposit to join
- no testing on mainnet, local forks only
-you need a working poc (foundry or hardhat) or your submission gets binned
safe to say this is built for proper security researchers, not casual hunters. the dual merkle + oracle setup is complex enough that finding a real critical prolly takes deep evm knowledge and time.
@superformxyz's architecture is genuinely interesting, if you’re a smart contract dev or researcher, the risk-reward here is not bad at all. for the average degen, like myself this one’s not for us lol, but worth watching what comes out of it.
just created a cantina account. not like i'm going bounty or anything. anyways, @cantinasecurity why don't y'all have a dark them layout👀