Aave Labs Proposes Dedicated Bug Bounty Program for Aave V4 With Sherlock

CryptoNewsFlash
AAVE0,35%
USDC0,01%

  • Aave Labs has published a proposal for a dedicated bug bounty program for a 24/7 channel to report security issues.
  • High-priority submissions require participants to stake at least 250 USDC, which is forfeited if the report is invalid or deemed spam.

Aave Labs has published a proposal to launch a new dedicated bug bounty program for its v4 on Sherlock’s security platform for DeFi protocols. The proposal aims to establish a channel to report any security concerns on the DeFi platform as it transitions to the fourth version (v4) of its protocol. The Labs says that Sherlock has been working with the community to audit the current v3 protocol and was used for early v4 testing. This translates to shared reporting standards and escalation paths for all parties. Founder Stani Kulechov noted that bug bounties have been an important part of the network’s security strategy. He also praised the Sherlock team for its expertise in managing previous bug bounty programs and security contests.

We propose launching the Aave V4 bug bounty program with Sherlock. Bug bounties have long been an important part of Aave’s security strategy, and the Sherlock team has demonstrated strong expertise in managing both security contests and bug bounty programs. https://t.co/azjjaV7fIZ

— Stani.eth (@StaniKulechov) March 5, 2026

On its part, Sherlock expressed support for the proposed program, adding, “Always-on coverage, structured triage, and clear escalation for high-severity reports as V4 ships and scales. Aave’s commitment to security stays constant.” Aave’s 250 USDC Stake to Prevent Spam The bug bounty program will be limited to the Aave v4 repositories and deployed contracts. Any expansion or migration of other programs would need a separate governance poll. Participants can hand in medium- or low-priority submissions at will. However, they cannot upgrade these to upper-tier submissions even if they expand in scope to ensure they pay enough attention to the original classification. The high-priority and critical submissions, which receive heftier payouts, will be limited to users who stake 250 USDC. If the submission is valid, the stake is returned together with the payout. If invalid, the stake is forfeited to pay for triage costs. This is intended to prevent spam where participants classify all submissions as high-priority to take a shot at the higher payout. For high-priority submissions, Aave’s designated security team members are instantly notified via Telegram and Slack to respond immediately. The lower-priority submissions are assessed by an AI program working alongside human reviewers.  Only the reports deemed higher-quality will be submitted for review.

Image courtesy of Aave Labs.

Aave Labs conceded that while the 250 USDC staking will reduce spam, it could put off some genuine researchers from submitting high-priority security concerns. To mitigate, it intends to keep the medium-priority tier free and to prioritize experienced researchers using this tier. It also acknowledged that by barring the re-classification of medium submissions to high-priority, it would punish misclassified submissions. It intends to publish an extensive guide as part of the program launch materials. The proposal comes weeks after a dispute between Aave Labs and BGD Labs imploded, with the latter announcing its departure at the end of this month. BGD, which was contracted by the Aave DAO to cater to security and technical issues, says the Labs has frustrated its efforts to advance the protocol.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Gerelateerde artikelen

Charles Hoskinson Launches Midnight With $250M in Tokenized Deposits From Monument Bank

Gate News message, April 25 — Charles Hoskinson, founder of Cardano, has launched Midnight, a privacy-focused blockchain project, with approximately $250 million in tokenized deposits from Monument Bank. The partnership represents a significant institutional collaboration aimed at integrating blockc

GateNews2u geleden

摩根大通 ETF 趨勢報告:API 化、主動式佔 83%、代幣化分為合成與原生兩條路徑

摩根大通報告指出三大趨勢:一、AP的API自動化交易佔約50%一級市場流量;二、2025年主動式ETF佔新發行83%,預期2026–27年成主流;三、代幣化分為合成式(以衍生品鏡射價格)與原生式(區塊鏈發行)兩條路徑。報告強調以Athena等工具提升透明度與治理,並觀察後續跟進與正式商品化時程。

ChainNewsAbmedia3u geleden

Drift Product Lead Minh Don Plans Relaunch of Forked Exchange in May or June

Gate News message, April 25 — Drift Protocol's product lead Minh Don announced plans to relaunch the forked exchange in May or June, according to a statement made on the official Discord server. The team will spend several weeks optimizing the codebase, removing and adding features that, while

GateNews3u geleden

Fluent Ethereum Layer 2 Mainnet Launches with BLEND Token and $50M Day-One Liquidity

Gate News message, April 25 — Fluent, an Ethereum-based Layer 2 network, activated its mainnet and launched its native BLEND token on Friday, April 25, bringing online a "blended execution" environment that enables applications written for different virtual machines to operate within the same

GateNews4u geleden

SEALCOIN Launches Early Access Program 'Spacedrop' for Ecosystem Participants

Gate News message, April 25 — SEALCOIN has officially launched its early access program called "Spacedrop," designed to give users the opportunity to participate in the SEALCOIN ecosystem ahead of its full mainnet launch. Participants can engage with the platform by completing tasks, earning

GateNews5u geleden

JPMorgan: Tokenization Will Transform Funds Industry, but Quality Use Cases Still Years Away

Gate News message, April 25 — Ciarán Fitzpatrick, JPMorgan's global head of ETF product and securities services, said tokenization should drive significant change across the entire funds industry, not just for ETFs. In a post released Friday, Fitzpatrick noted that experimentation with tokenizing ET

GateNews6u geleden
Opmerking
0/400
Geen opmerkingen