In scope
- All Auora smart contracts on Polygon (asset prediction, factory, tournaments, referral)
- Our public web application
- Our public APIs
- Any endpoint that handles signed messages, oracle data, or user authentication
Out of scope
- Third-party services we depend on (oracle networks, RPC providers, hosting providers — please report those to the upstream vendor)
- Social engineering of Auora employees
- Denial-of-service attacks against our public infrastructure (please don’t)
- Issues already reported by another researcher or already fixed
Reward tiers (indicative)
Final reward amounts are determined based on severity, exploitability, and quality of report.
How to report
Email dev@auora.gg with:- A clear description of the vulnerability
- Steps to reproduce
- Impact assessment
- Any proof-of-concept code (optional but appreciated)
