Challenge a draft report

Check a bug bounty report before you submit

Paste your draft and the code it cites. Your model reads it as the triager who has to pay for it, splits it into claims and marks each one against the lines you supplied. A correct report gets confirmed.

Opens the workbench with Challenge a draft report selected. 1 hosted review per UTC day on your own key. No card.

ExampleExample output · invented protocol

VerdictRewrite, then submit

The missing caller check is in the code. The theft is contradicted: line 76 pays the account that earned the reward.

  • 0Critical
  • 0High
  • 1Medium
  • 0Hardening
  • 2Checked safe
input-1/draft-report.md5 claims
Claims

Five claims in the draft, checked against RewardPool.sol

C1

claimFor has no access control.

ConfirmedThere is no caller check at lines 71-79. Anyone calls it for any account.

input-2/RewardPool.sol:71-79

C2

The attacker receives the victim’s rewards.

ContradictedLine 76 transfers to user, the account that earned the reward. The caller receives nothing.

input-2/RewardPool.sol:76

C3

This drains the reward pool.

OverstatedEach call pays one account what it has already earned. The pool pays nothing it does not owe.

input-2/RewardPool.sol:73-76

C4

It breaks the auto-compounder integration.

UnverifiableNo compounder code was supplied.

C5

Severity: Critical.

OverstatedThe code supports a forced claim with no loss of principal. The assumption that would move it: a forced claim costs the user something the compounder would have earned.

Next

Find the docs for claimFor. If they describe a keeper path, drop the report. If they do not, file the rewritten version.

What the challenge checks

The draft is split into the claims that decide it. Each is checked against the code.

  1. Root cause

    The missing or wrong check, located in the code. A root cause the code contradicts ends the report.

  2. Each attack step

    Every step of the path, checked in order against the lines it relies on.

  3. Preconditions

    What has to be true before the attack starts, and whether the draft says so.

  4. Impact and severity

    Who loses what, with the bound. The severity the evidence supports, and the one assumption that would move it.

  5. The fix

    Whether the proposed change closes the path.

  6. The proof

    Whether the test asserts the claimed end state, and whether that assertion fails once the fix is applied.

What to paste in

One file is the draft. The rest is the evidence it relies on.

  • Your draft report

    Markdown or plain text, as you intend to submit it.

  • The source files the report cites

    At the commit the report names.

  • The PoC and its outputOptional

    A supplied test lets the review confirm the impact instead of asking for it.

Up to 50 files, 120 KB per file, 240 KB and 20,000 lines in total. Paste, drop files, or import a repository, pull request or commit from GitHub at a pinned commit.

What comes back

A verdict on the draft and a row for every claim.

  • One verdict: submit, rewrite-then-submit, prove-first, hold-duplicate or drop.
  • A Claims table: each claim marked confirmed, overstated, contradicted or unverifiable, with the line that decides it.
  • The finding the code supports, at the severity it supports, as a finding card.
  • Only the gaps that change the decision. A gap the draft already discloses is skipped.
  • On rewrite-then-submit: a rewritten title, severity, summary and impact.
  • A packet with the SHA-256 manifest of every file reviewed.

The finding that survives

RewardPool is a contract invented for this page. The draft claimed a Critical theft. This is what the code supports.

ExampleExample output · invented protocol · RewardPool

F-1MediumProven in source

Anyone triggers a reward claim for any account

  • input-2/RewardPool.sol:71-79
Impact

A third party chooses when another account’s rewards are paid out. The rewards go to their owner. No principal moves.

Observed
  1. claimFor(address user) is external and has no caller check (line 71).
  2. It settles earned[user] and transfers that amount to user (lines 73-76).
Counterargument

Claiming for another account is the design. Keepers do it.

OpenNothing supplied documents claimFor as a keeper path. If the docs do, the behaviour is intended.

Evidence gap
  • The NatSpec or the docs page for claimFor.
  • The auto-compounder code, to show what a forced claim costs the user.
Fix

Require msg.sender == user, or restrict the call to an allowlisted keeper.

Next

Read the docs for claimFor before anything else.

Rewritten report

Title, severity, summary and impact only
Title
claimFor lets any caller trigger a reward claim for any account
Severity
Medium on the rules of this review. Grade it on the programme’s own table before filing.
Summary
claimFor(address user) has no caller check, so anyone settles and pays out another account’s rewards at a time of their choosing. The rewards are sent to their owner.
Impact
Loss of control over claim timing for every staker. No loss of principal and no loss of rewards is shown.

Questions

Does it rewrite my report?

Only when the verdict is rewrite-then-submit, and only the title, severity, summary and impact. You write the report. The review marks which claims the code does not support.

What if my report is correct?

Every decisive claim is marked confirmed and the verdict is submit. The profile is instructed to agree when the code and the proof support the draft, and to manufacture no objections.

Which model runs the review?

The one you choose, on your own key: OpenRouter, Anthropic, OpenAI, Google Gemini, xAI, DeepSeek, Mistral or Groq. With a chat subscription, export the prompt, paste it into your chat app and paste the answer back. From a coding agent, prepare_review hands the same request to the agent’s own model over MCP.

Where do my files go?

To the model provider you choose, through our server, for that one request. Bounty Operator does not store your files, prompts, keys or results. With an exported prompt they go from your browser to the chat app you paste into. The packet you download carries a SHA-256 manifest of every file reviewed.

Find the hole in your report before the triager does

Paste the draft and the code. Read the claims table. Then decide.

Opens the workbench with Challenge a draft report selected. Free: 1 hosted review per UTC day. Operator: unlimited, US$10 per week.