Want to get paid for helping secure one of the top DEXs on TON?
STON.fi has a live bug bounty program where ethical hackers can earn up to $100,000 for critical vulnerabilities. 🧵
1. Why bug bounties matter
Even with audits, security is never truly “finished.”
Bug bounties bring independent researchers into the process, helping protocols discover issues that may have been missed during audits.
For STON.fi, the program works alongside audits and other security measures.
2. What does it cover?
The program focuses on STON.fi DEX Smart Contracts v2, including core contracts for:
• Swaps
• Liquidity
• Vaults
Frontend issues and disruptive testing can be out of scope, so always read the rules first.
3. What can you earn?
Rewards depend on severity.
A critical vulnerability can pay up to $100,000, with lower rewards for high, medium, and low-severity findings.
The vulnerability must be valid, in scope, reproducible, and backed by clear evidence.
4. What makes a strong report?
Explain:
• What the vulnerability is
• Where it exists
• How to reproduce it
• Potential impact
• A clear proof of concept
The easier it is to verify, the better.
5. How to participate
→ Visit the STON.fi program on HackenProof
→ Read the scope and rules
→ Research the eligible contracts
→ Reproduce and document your finding
→ Submit your report
Before submitting, review public audits and documentation to avoid reporting known issues.
6. Understand TON
TON isn't simply another EVM chain.
Researchers should pay attention to mechanics such as asynchronous messaging, contract state, and message handling.
Understanding these differences can reveal security considerations that may be easy to miss.
7. The bigger picture
Bug bounties create a win-win:
Researchers get rewarded for their skills.
Protocols get more eyes on their code.
Users benefit from stronger security.
STON.fi's $100K maximum reward gets attention, but the bigger story is the layered approach: audits, monitoring, and independent security research.
No DeFi protocol can guarantee zero vulnerabilities.
The goal is to make them harder to exploit, detect problems faster, and respond responsibly.
🔗 Official program: hackenproof.com/programs/ston-…
Would you participate in a TON bug bounty for a chance to earn up to $100K? 👇