Aave Labs Proposes Dedicated Bug Bounty Program for Aave V4 With Sherlock

CryptoNewsFlash
AAVE0,4%
USDC0,03%

  • Aave Labs has published a proposal for a dedicated bug bounty program for a 24/7 channel to report security issues.
  • High-priority submissions require participants to stake at least 250 USDC, which is forfeited if the report is invalid or deemed spam.

Aave Labs has published a proposal to launch a new dedicated bug bounty program for its v4 on Sherlock’s security platform for DeFi protocols. The proposal aims to establish a channel to report any security concerns on the DeFi platform as it transitions to the fourth version (v4) of its protocol. The Labs says that Sherlock has been working with the community to audit the current v3 protocol and was used for early v4 testing. This translates to shared reporting standards and escalation paths for all parties. Founder Stani Kulechov noted that bug bounties have been an important part of the network’s security strategy. He also praised the Sherlock team for its expertise in managing previous bug bounty programs and security contests.

We propose launching the Aave V4 bug bounty program with Sherlock. Bug bounties have long been an important part of Aave’s security strategy, and the Sherlock team has demonstrated strong expertise in managing both security contests and bug bounty programs. https://t.co/azjjaV7fIZ

— Stani.eth (@StaniKulechov) March 5, 2026

On its part, Sherlock expressed support for the proposed program, adding, “Always-on coverage, structured triage, and clear escalation for high-severity reports as V4 ships and scales. Aave’s commitment to security stays constant.” Aave’s 250 USDC Stake to Prevent Spam The bug bounty program will be limited to the Aave v4 repositories and deployed contracts. Any expansion or migration of other programs would need a separate governance poll. Participants can hand in medium- or low-priority submissions at will. However, they cannot upgrade these to upper-tier submissions even if they expand in scope to ensure they pay enough attention to the original classification. The high-priority and critical submissions, which receive heftier payouts, will be limited to users who stake 250 USDC. If the submission is valid, the stake is returned together with the payout. If invalid, the stake is forfeited to pay for triage costs. This is intended to prevent spam where participants classify all submissions as high-priority to take a shot at the higher payout. For high-priority submissions, Aave’s designated security team members are instantly notified via Telegram and Slack to respond immediately. The lower-priority submissions are assessed by an AI program working alongside human reviewers.  Only the reports deemed higher-quality will be submitted for review.

Image courtesy of Aave Labs.

Aave Labs conceded that while the 250 USDC staking will reduce spam, it could put off some genuine researchers from submitting high-priority security concerns. To mitigate, it intends to keep the medium-priority tier free and to prioritize experienced researchers using this tier. It also acknowledged that by barring the re-classification of medium submissions to high-priority, it would punish misclassified submissions. It intends to publish an extensive guide as part of the program launch materials. The proposal comes weeks after a dispute between Aave Labs and BGD Labs imploded, with the latter announcing its departure at the end of this month. BGD, which was contracted by the Aave DAO to cater to security and technical issues, says the Labs has frustrated its efforts to advance the protocol.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Sky Proposes Treasury Management Overhaul as Genesis Capitalization Phase Ends

Gate News message, April 27 — Sky, the decentralized finance (DeFi) lending protocol formerly known as MakerDAO, has proposed streamlining its Treasury Management Function (TMF) following the formal conclusion of its founding capital deployment phase. Founder Rune Christensen announced in a forum po

GateNews3h ago

Pavel Durov Says TON Fees Will Drop 6x Targeting Near-Zero Costs

TON reduces transaction fees sixfold to near-zero levels, shifting to fixed pricing independent of network congestion. Upgrade boosts speed and finality, enabling faster, cheaper transactions compared to Ethereum, Bitcoin, and Solana. Lower costs support microtransactions and apps,

CryptoFrontNews4h ago

CT3 Secure Storage Reports 5.29 PB Uploaded Data and 10 Enterprise Contracts in Second Month

Gate News message, April 27 — CT3 has released its second-month operating results for CT3 Secure Storage, showing accelerating adoption across private and enterprise segments. During March 2026, the network processed 5.29 PB of uploaded data, with 64,574 private uploads from 27,471 unique users and

GateNews4h ago

Solana Selects Falcon for Post-Quantum Cryptography, Migration Preparations Complete

Gate News message, April 27 — Solana's official team published a comprehensive quantum computing roadmap, reaffirming that quantum threats remain years away while the ecosystem has already completed extensive research and technical preparation. Two independent validator client development teams,

GateNews7h ago

Alphea Launches AI-Native Layer 1 Blockchain with Autonomous Agent Execution

Gate News message, April 27 — Alphea, a newly unveiled Layer 1 blockchain platform designed for AI infrastructure, officially presented its decentralized execution environment at Hong Kong Web3 Festival 2026. The platform integrates execution, persistent memory, and verifiable computation as

GateNews7h ago

Lise Completes World's First Tokenized IPO on Regulated Exchange

Gate News message, April 27 — Lise (Lightning Stock Exchange), a Paris-based regulated exchange, has closed what it describes as the world's first initial public offering (IPO) executed on a fully regulated, natively tokenized market infrastructure. ST GROUP, a French industrial SME supplying

GateNews7h ago
Comment
0/400
No comments