Dear users, an important quick note on our Bug Bounty Program.
We’re receiving a high volume of reports, and we genuinely appreciate the attention Shift’s contracts are getting from the security community.
Every submission needs to be reviewed properly. Some identify issues worth investigating further. Others turn out to be duplicates, intended behavior, or findings that do not represent an actual vulnerability.
But we cannot know which is which until our team has done the work.
That means reading the report, reproducing the scenario, checking the PoC, reviewing the relevant contracts, and assessing the potential impact. With many submissions coming in at once, this takes time.
So if you haven’t received an immediate verdict, your report hasn’t been ignored. It’s in the review process, and we’re working through submissions as carefully as possible.
We’re also reaching out directly to researchers regarding bounty rewards, so please keep an eye on the email address you used for your submission. You may already have a message from us waiting there.
We built this program because we want our assumptions challenged. Keep looking. Keep testing. Keep sending us what you find.
We’ll keep reviewing.