StaFiHub Public Testnet & Bug Bounty Program - DropsEarn
Home Active StaFiHub Public Testnet & Bug Bounty Program
StaFiHub Public Testnet & Bug Bounty Program

StaFiHub Public Testnet & Bug Bounty Program

Add to Watchlist

Added to Watchlist

Reward pool

Not set


Expected profit

$10 - 25,000


Max participants

No limit

DropsEarn score


Normal, Low Risks


It is developed by the StaFi team and based on the Cosmos SDK to serve the Liquid Staking Derivatives in the Cosmos ecosystem. Meanwhile, it’s the first crucial step taken by StaFi to expand into the increasingly prosperous Cosmos ecosystem. Once StaFiHub is launched on the mainnet, the projects based on Cosmos SDK can quickly deploy their own liquid staking solutions with StaFi rToken SDK.

StaFiHub has the following features:

  1. It‘s an application chain serving the Cosmos ecosystem Staking Derivatives.
  2. The IBC cross-chain protocol is supported. The token assets of the Cosmos ecosystem can be cross-chained to StaFiHub through the IBC protocol, and all the rToken assets on the StaFiHub can circulate in the Cosmos ecosystem through the IBC protocol.
  3. The tokens in the Cosmos ecosystem can directly mint out StaFiHub-based staking derivatives.
  4. StaFiHub has developed a Liquid Staking SDK for Cosmos Eco projects to easily and quickly get their own liquid staking derivatives with very limited development and time costs. .
  5. StaFiHub will provide decentralized trading services based on rDEX for all the liquid staking tokens issued by StaFiHub.

Now StaFi is excited to announce that StaFiHub public testnet is live:, the StaFi team welcomes all users and developers to participate in the testing. StaFi has also prepared incentives as bounty rewards for any user or developer who detects and reports bugs and vulnerabilities.

For a detailed introduction to the StaFiHub proposal solution, please check this link.

About StaFiHub Public Testnet

StaFiHub public testnet will be divided into the following 2 phases which will be released step by step:

Phase 1 of Functions Overview

  • Validator Testing: deploy the node of StaFiHub Chain and become a validator to test the transfer and staking functions etc.
  • Basic rToken function: stake tokens, mint rTokens, unbond tokens, the exchange rate update, transfer assets with IBC etc.
  • Staking Drop: the fixed number of FIS could be distributed when the original token is staked for the first time.
  • Fee station: supports the swapping of FIS in proportion with the original token
  • StaFiHub App UI/UX and operation testing.
  • Code review

Phase 2 of Functions Overview

  • rPool App: the incentive programs for rToken minting;
  • rDEX: support to trade rToken/Token trading pairs, add or unstake liquidity, and liquidity farming modules;
  • Code review

Phase 2 will be released around 3 weeks after the release of StaFiHub public testnet Phase 1. After the public testnet, c will release an incentivized testnet of StaFiHub for the community to participate soon. Please stay tuned for the details.

Bug Bounty

The contract of StaFiHub will be audited by a professional third-party agency and StaFiHub is approaching them. StaFiHub will synchronize it with the community as soon as there is some new progress. At the same time, StaFiHub is also launching the Bug Bounty for StaFiHub to the StaFi community. The aim of this program is to find functional vulnerabilities and code bugs with the help of the community. The bounty starts on 19/04/2022 and will always continue. Here are the details of this Bug Bounty.

Function Testing

Testing Guide



Testing Task

Seen in “About StaFiHub Public Testnet” part.

Welcoming community members with development expertise to join in the 2 different phases of StaFiHub testnet. You can submit any functional and code bugs that have not been found yet and provide suggestions related to StaFiHub after completing the testing and code review of StaFiHub testnet. Please explain the bugs and suggestions in detail, and send an email to [email protected] with the corresponding screenshots while submitting.

The StaFi team will evaluate and confirm the functional bugs. On successfully reporting bugs/issues, users will be awarded rewards worth 10 USDT to 1000 USDT.

Code Vulnerability Testing

Test Contents

StaFi Chain

rToken Relay

rToken App


Critical: Abnormal function, ineffective function, or security breach, etc.

Moderate: Defects that do not affect the function, non-security issues, including room for optimization, performance improvement, etc.

Low: Unimportant issues, some minor issues that can be modified during updates, such as modifying text or notes.

Outside the scope of the bounty program:

  • Repeated reports on security issues, including security issues that have been confirmed by the StaFi team.
  • Theoretical security issues without pragmatic application scenarios, or issues that require complex user-interactions.


  • It must be a newly discovered bug(s) that has/have not been reported before.
  • The bug(s) found must be related to security issues in StaFi GitHub page code, but not other third-party code.
  • Users who report bugs must not have written any codes of StaFi around the bug(s), and have not participated in any process that generated the bug(s) of StaFi in other ways.
  • Public disclosure will make you lose your bounty.
  • The StaFi team reserves the right to make the final decision on eligibility for the event and all rewards.

Bounty Rules

The bounty will be issued in the form of FIS, and the amount will depend on the severity of the bugs found.

In addition to severity, the bounty amount will be determined (but not limited to) by other factors including:

  • The accuracy and details of the bug description.
  • The quality of reproducibility, such as test code, scripts, and detailed instructions.

Submission Method

When you find a bug(s), please send a report to: [email protected].

Please include your name, email, company name (optional), description of the bug(s), your opinion on what is the potential impact of that bug on StaFiHub, and how you discovered that bug.

About StaFi

StaFi is the first DeFi protocol unlocking liquidity of staked assets. Users can stake PoS tokens through StaFi and receive rTokens in return, which are available for trading, while still earning staking rewards. rToken is a synthetic staking derivative issued by StaFi to users when users stake PoS tokens through StaFi rToken App . rTokens are anchored to the PoS tokens staked by users and the corresponding staking rewards. rTokens can be transferred and traded at any time.




After a thorough internal testing and continuous debugging, StaFiHub public testnet has been launched. Join StaFiHub testnet, find bugs, and win FIS rewards.

Activity Type


Bug bounty




19 Apr 2022 03:00(UTC+3) - 19 Jun 2023 03:00(UTC+3)



Event Status

You can participate (Event started, Registration open)