Karmaverse, a AAA GameFi metaverse, aims to organically combine the Play-for-Fun and Play-to-Earn elements inside its ecosystem, to build a sustainable system in which the users can play and earn.
For more information about Karmaverse, please visit https://karmaverse.io/. This bug bounty program is focused on smart contracts, website and app, and is focused on preventing loss of user assets.
Rewards are distributed with references to the impact of the vulnerability based on the Immunefi Vulnerability Severity Classification System V2.1. This is a simplified 5-level scale, with separate scales for websites/apps, smart contracts, and blockchains/DLTs, focusing on the impact of the vulnerability reported. Karmaverse reserve the right to rectify these terms at any time without prior notice.
All web/app bug reports must come with a PoC with an end-effect impacting an asset-in-scope in order to be considered for a reward. All Smart Contract bug reports require a PoC and a suggestion for a fix to be eligible for a reward. Explanations and statements are not accepted as PoC and code is required.
All vulnerabilities marked in the Certik security review are not eligible for a reward.
The following vulnerabilities are excluded from the rewards for this bug bounty program:
The following activities are prohibited by this bug bounty program: