Report #12593

Report Date
October 20, 2022

Critical: Take funds by changing Fee Receiver Address

Report Info

BIC Response

This submission is related to an out of scope asset: the BEAN:3CRV Curve LP token. Curve pools are not part of Beanstalk and thus not included in the Immunefi bug bounty program. Curve pools are also non-upgradable.

The Beanstalk DAO acknowledges the risk of using Curve and has transparently communicated that here:


Due to these reasons, this report is not eligible for a reward.