Security Vulnerability Report
I have identified a high-severity vulnerability in the Nado Protocol smart contracts that affects the liquidation mechanism.
Vulnerability class: Denial of Service (DoS) in the liquidation finalization path
Severity: High
Affected components: PerpEngine.sol and SpotEngine.sol
Impact: Permanent DoS of liquidation under specific but realistic market conditions. No privileged access required — conditions arise from normal protocol operation during market stress.
I am not disclosing technical details in this public issue per responsible disclosure best practices.
Request
I am requesting a private communication channel to share the full vulnerability report, which includes:
- Detailed technical description
- Proof-of-concept simulations (verified)
- Attack scenarios
- Remediation recommendations
Why direct contact?
I discovered this through your HackenProof bug bounty program, but the program requires 100 reputation points for submission. I currently have 80 reputation points and did not want to delay this time-sensitive finding.
Preferred contact channels
I can share the full report through any of the following:
- A private channel you designate (email, Signal, etc.)
- HackenProof private program invitation (if you can send one)
- GitHub Private Vulnerability Reporting (currently not enabled on this repo — I recommend enabling it)
I am committed to responsible disclosure and will not publish any details until resolution and mutual agreement on disclosure timeline.
Please acknowledge receipt and advise on the preferred private channel.
Security Vulnerability Report
I have identified a high-severity vulnerability in the Nado Protocol smart contracts that affects the liquidation mechanism.
Vulnerability class: Denial of Service (DoS) in the liquidation finalization path
Severity: High
Affected components: PerpEngine.sol and SpotEngine.sol
Impact: Permanent DoS of liquidation under specific but realistic market conditions. No privileged access required — conditions arise from normal protocol operation during market stress.
I am not disclosing technical details in this public issue per responsible disclosure best practices.
Request
I am requesting a private communication channel to share the full vulnerability report, which includes:
Why direct contact?
I discovered this through your HackenProof bug bounty program, but the program requires 100 reputation points for submission. I currently have 80 reputation points and did not want to delay this time-sensitive finding.
Preferred contact channels
I can share the full report through any of the following:
I am committed to responsible disclosure and will not publish any details until resolution and mutual agreement on disclosure timeline.
Please acknowledge receipt and advise on the preferred private channel.