# Welcome to Hats Finance


# Overview

General intro to key aspects of the protocol

Hats Finance is committed to safeguarding DeFi protocols, their users, and the broader blockchain community by aligning incentives between projects and security professionals through our decentralized security platform. Hats Finance is dedicated to making decentralized security (DeSec) accessible to everyone, transforming the landscape of Web3 security.

### What is Hats Finance?

Hats Finance offers Web3 native security solutions that align in all respects with the DeFi ethos. By leveraging the power of DeSec, blockchain technology, and community-driven security practices, we offer a suite of tools that include audit competitions and bug bounties. Our solutions are designed to enhance protocols’ security, foster community involvement, and streamline the development lifecycle of Web3 projects.

Hats Finance is the decentral protocol for hosting non-custodial Bug Bounties and Audit Competitions. With our non-custodial approach, projects gain complete control, reducing fees, and embracing a pay-for-results model. This unique feature enables running audit competitions even after multiple previous audits, eliminating payouts if no new audit findings emerge.

Moreover, our on-chain submission system serves as an efficient spam filter, guaranteeing that only top-tier reports are forwarded to the respective teams. This promotes a heightened focus on high-quality security assessments, ensuring the utmost protection for your project.

### Our Mission

Our mission is to create a more secure and trustworthy DeFi environment for everyone by providing tools that enable continuous and autonomous security. Hats Finance is built on the principle that security should be decentralized, transparent, and incentivized. We believe that by empowering the community of security researchers, we can collectively uplift the standards of security across the entire Web3 space.

### Features and Offerings

**Audit Competitions:**

We host time-sensitive crowd-sourced audits that allow high-quality security professionals to compete and identify vulnerabilities quickly and efficiently.

**Public Competition with First-come-first-served Mechanism:**&#x20;

Open to all auditors, this type of competition encourages broad participation, allowing any auditor to review and submit vulnerabilities they find while not wasting time on issues that have been submitted by others.

**Private Competition with First-come-first-served Mechanism:**&#x20;

Restricted to white-listed auditors for a more controlled and specialized audit process, ensuring targeted, high-quality submissions while enabling the project to stay in stealth mode.

**Bug Bounties:**

Our decentralized bug bounty platform is built on Web3 tenets, featuring on-chain submission processes and a peer-to-peer architecture that ensures the privacy of security researchers while removing the need for third-party support from the process.

**Decentralized Arbitration:**

We offer a decentralized arbitration mechanism that addresses disputes in audit competition and bug bounty submissions, providing a fair process and outcome for all parties involved.

**Solo Auditor Engagement:**&#x20;

Solo auditors are given a base fee to audit contracts and triage submissions to reduce the burden on the committee while competing with others publicly. They have the incentive to provide thorough audits by leveraging their reputation and can earn additional rewards by finding valid bugs during the competition. This creates a dynamic where solo auditors work diligently, while other competitors search for vulnerabilities in the open audit competition.

**Continuous Audit:**&#x20;

Tailored for projects needing to audit new code or modifications, especially useful for those who have previously participated in our competitions. Auditors familiar with the project can efficiently audit only the changes, streamlining the process and ensuring quick and affordable turnaround times while keeping security a top priority.

### Why Choose Hats?

Hats Finance is committed to driving innovation in the Web3 security industry and to rewarding its partners to the maximum degree. By comparing us with the competition you will see we offer better rewards to security researchers, more peace of mind and lower fees to protocols, and greater incentive alignment between all key stakeholders.

| **CATEGORY**                | **HATS FINANCE**                                                                                                                                                      | **COMPETITORS**                                                                                                           |
| --------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| **Audit Competition Model** | On-chain competitions with immediate, transparent reward distribution for the first unique successful submission.                                                     | Audit competitions have varying transparency and reward distribution methods.                                             |
| **Reward System**           | Payment only for valid vulnerabilities.                                                                                                                               | Fixed pricing regardless of vulnerabilities found.                                                                        |
| **Dispute Resolution**      | Soon - Decentralized arbitration with Kleros integration for fair and impartial outcomes.                                                                             | Varies; most lack a decentralized dispute resolution mechanism.                                                           |
| **Community Engagement**    | Strong community governance with liquidity mining incentives.                                                                                                         | Community-driven processes, but no community ownership.                                                                   |
| **Transparency & Trust**    | Fully on-chain solutions, fostering maximum trust.                                                                                                                    | Most don’t operate fully on-chain, potentially affecting transparency.                                                    |
| **Speed & Efficiency**      | Pay the first submission to incentivize quick vulnerability submissions. Fast payouts.                                                                                | Tend to split payouts between submissions, which may reduce the speed of submissions. Tend to have longer payout periods. |
| **Innovative Approach**     | Skin-in-the-game and other features align long-term interests of auditors with project success.                                                                       | Insurance or fixed fee models may not align auditor incentives with project outcomes as closely.                          |
| **Scalability & Coverage**  | Scalable platform with a vision for full lifecycle coverage of software development. Audit demand and supply can find an equilibrium in a genuinely free marketplace. | Centralized processes with access restrictions depend on scheduling with a central party.                                 |

### Documentation Overview

Our documentation is your comprehensive guide to understanding and utilizing the various services provided by Hats Finance. Whether you are a project looking to secure your contracts, a security researcher aiming to contribute to a safer DeFi space, or a community participant interested in the governance and future of Hats Finance, our docs will provide you with all the information you need to get started and become an active member of our community.

* For Projects: Discover how to launch an audit competition or bug bounty, contribute liquidity, and leverage our security services to protect your protocol.
* For Security Researchers: Learn how to participate in competitions, submit vulnerabilities, and understand the rewards and recognition system.
* For Community: Learn about our tokenomics and governance, and engage with the Hats Finance community

Miscellaneous: Learn more about the workings of Hats Finance.

We invite you to explore our docs and join us in our quest to secure the future of decentralized finance. For any questions or assistance, please feel free to contact our support team or join our community discussions.<br>


# FAQs

### **What is Hats Finance?**&#x20;

Hats Finance is a decentralized platform dedicated to enhancing Web3 security. We leverage audit competitions, bug bounties, and other security mechanisms to protect DeFi protocols and their users. Our model is based on aligning incentives between security researchers (white hat hackers) and DeFi projects.

### **How do Audit Competitions work at Hats Finance?**&#x20;

Audit competitions at Hats Finance are time-sensitive events where security experts compete to identify vulnerabilities in smart contracts. These competitions are designed to quickly mobilize a community of auditors, providing a comprehensive and thorough security assessment for DeFi projects.

### **What are Private Audit Competitions at Hats Finance?**&#x20;

Private Audit Competitions are a tailored version of our standard audit competitions, designed for protocols seeking a more controlled and exclusive security assessment. In these competitions, select auditors are invited to participate based on their expertise and track record. This allows protocols to benefit from a focused and specialized audit process, ensuring deeper scrutiny and confidentiality when needed.

### **How do Private Audit Competitions differ from Open Audit Competitions?**&#x20;

While Open Audit Competitions are open to a broad range of auditors, creating a competitive and diverse environment, Private Audit Competitions are limited to a pre-selected group of auditors. This selective approach is particularly beneficial for projects requiring audits on sensitive or high-stakes smart contracts, where discretion and specialized skills are paramount.

### **What are Hats Bug Bounties?**&#x20;

Hats Bug Bounties are decentralized bounty programs hosted on the Hats Finance platform, allowing protocols to offer rewards for identifying vulnerabilities in their smart contracts. These bounties are designed to continuously engage the white hat hacker community in monitoring and improving the security of DeFi projects

### **What makes Hats Finance different from other security platforms?**&#x20;

Hats Finance stands out due to its fully on-chain solutions, transparency in operations, and unique pricing model where projects pay only for actionable, validated vulnerabilities. This approach not only minimizes financial risks for projects but also incentivizes high-quality submissions from security researchers.

### **How does the 'Pay Only for Results' model work?**&#x20;

In our 'Pay Only for Results' model, projects pay only when a valid vulnerability is identified and verified. This pricing structure ensures that projects are investing in tangible results that enhance their protocol’s security, rather than paying flat fees regardless of outcomes.

### **What are the benefits of participating in Hats Finance as a security researcher?**&#x20;

Security researchers are incentivized by our policy of only paying the first person who submits a unique and valid issue which allows Hats to offer higher rewards. The transparent, on-chain submission process ensures fair evaluation and timely payouts. Additionally, our arbitration mechanism offers a fair dispute resolution process, ensuring that researchers' findings are evaluated impartially.

### **How do I submit a vulnerability finding in Hats Finance?**&#x20;

Findings can be submitted through our decentralized application (dApp). This on-chain submission process ensures transparency and traceability. Detailed guidelines on the submission process are available on our website.

### **How are the severity of findings determined in Hats Finance?**&#x20;

Findings are categorized into High, Medium, and Low severities based on their impact and risk to the protocol. This assessment considers factors like financial implications, data integrity, and user trust. Our comprehensive guide on evaluating finding severity is available on our documentation page.

### What happens if I disagree with the severity assessment of my finding?

If you disagree with the assessment by the project committee, you can initiate arbitration with a third-party arbitrator, such as Kleros. This process ensures that your submission receives an impartial judgment.

### Can I contribute liquidity to bug bounty vaults?

Yes, projects and users can contribute liquidity to bug bounty vaults. This not only supports the security ecosystem but also enables liquidity mining for contributors upon Token Generation Event (TGE).

### What is the role of the Kleros arbitration in Hats Finance?

Kleros arbitration is integrated into our platform to offer an unbiased dispute resolution mechanism. If there is a disagreement between the security researcher and the project committee regarding a submission, Kleros provides an impartial judgment, ensuring fairness in the payout process.


# Audit Competitions

What is a Hats Audit Competition?

### **Overview**

Hats Finance’s decentralized audit competitions focus on Web3 projects' code bases and provide a unique platform for security experts to participate in a collaborative effort to enhance the security and reliability of blockchain projects. Our audit competitions are time-sensitive events where a community of security experts, including auditors and white-hat hackers, engage in a collaborative yet competitive environment to identify and report vulnerabilities in smart contracts and DeFi protocols. This model leverages the collective expertise and insight of a diverse group of security professionals to enhance the security position of blockchain projects.

### **The goal**

The primary goal of an audit competition at Hats Finance is to ensure the robust security of DeFi protocols by uncovering potential vulnerabilities before they can be exploited maliciously. These competitions are designed to bring out the best in the auditing community, fostering a spirit of collaboration and innovation while ensuring a high standard of security for participating protocols.

### **Framing the problem**

Audit competitions, while not necessarily a replacement for traditional audits, can serve as an excellent complement to them or can be particularly effective when applied to code that has already been subject to a high level of internal review.

Web3 protocols commonly face several challenges when it comes to auditing their smart contracts:

1. Lengthy Wait Times: Traditional audit processes can take weeks or even months, delaying the launch of important updates or features.
2. High Cost with Minimal QA: Auditing services can be prohibitively expensive, often without a corresponding level of quality assurance to justify the expenditure.
3. Payment Based on Findings: Rewards in audit competitions are based on the severity and validity of the vulnerabilities found. This means that you pay only for vulnerabilities found, not for attempts of valid findings, ensuring that resources are spent effectively.
4. Limited Reviewers: With the traditional audit model, a limited number of individuals or a single team are typically involved in the code review process, which may limit the diversity of thought and potentially overlook vulnerabilities.

Audit competitions offer compelling solutions to these common issues:

1. Shorter Audit Cycle Time: By leveraging the power of a crowd of auditors, the audit process can be significantly expedited, reducing the time from discovery to patch.
2. Return of QA to Protocol Hands: In an audit competition, quality assurance is decentralized and falls into the hands of the protocol or developers themselves. They have the opportunity to assess submissions, thus allowing for a more hands-on approach to security.
3. Payment Based on Findings: Rewards in audit competitions are based on the severity and validity of the vulnerabilities found. This means that if no vulnerabilities are discovered, no payments are required, ensuring that resources are spent effectively.
4. The Advantage of Many Eyes: The power of the crowd is harnessed in audit competitions. With more individuals reviewing the code, the likelihood of discovering potential vulnerabilities is significantly increased. This "many eyes" approach fosters diversity of thought and comprehensive code review.

### **How Hats Finance audit competitions work**

**Initiation:** Protocols begin by meeting with our team to assess their needs and match them with the right product. From here the protocol submits its code and we collaboratively define the scope, rules, and potential rewards for participants. At this point, the protocol will use our vault creator to set up their competition vault creating reassurance for all potential participants that all potential rewards are on-chain and ready to be deployed. When this process is completed, we move into launch mode.

**Pre-Competition Launch:** In the time leading up to competitions beginning, we coordinate with protocols to ensure a community of security researchers are ready to get their eyes on code on day 1.

**Participation:** Security researchers and auditors from our community then scrutinize the submitted code, employing a variety of techniques to identify vulnerabilities. This could range from manual code reviews to automated testing.

**Submission of Findings:** Participants submit their findings directly on-chain, ensuring transparency and integrity in the reporting process. This unique approach allows for an immutable record of submissions.

**Review and Reward:** Submissions are carefully reviewed, with an emphasis on the quality and impact of the findings. Rewards are distributed based on the severity and uniqueness of the vulnerabilities uncovered. Hats Finance's model ensures that only the first unique submission for each issue is rewarded, reducing redundant work and enhancing the efficiency of the competition. If a dispute arises in relation to the validity or severity of a submission, participants can choose to enter impartial arbitration in order to resolve the issue.

**Continuous Improvement:** During and post-competition, the results are used by protocols to improve their security measures. This ensures protocols are ready to confidently deploy their reviewed and amended code in the shortest amount of time possible. Hats Finance also gathers insights from each competition to refine and enhance future events.

### **KEY BENEFITS OF PARTICIPATING**

**Competitive Rewards:** Hats' unique pay-for-results and low fee structure ensure successful participants can receive fair and substantial incentives for contributions. Our fully on-chain functionality ensures fast payouts for valid vulnerabilities.

**Transparency and Trust:** Fully on-chain submission and review process for maximum transparency.

**Collaborative Expertise and Learning:** Leverage the collective knowledge and skills of a diverse community of auditors in order to grow your own capabilities as a security researcher.<br>

### **GET INVOLVED**

Whether you are a seasoned auditor or an aspiring white-hat hacker, Hats Finance audit competitions offer a platform to showcase your skills, contribute to the security of the Web3 ecosystem, and earn rewards for your valuable insights. Join our community and participate in upcoming audit competitions to play a pivotal role in shaping the future of DeFi security.

<br>

<br>


# Skin-in-the-Game Audits

**Overview**

Traditional Web3 audits often suffer from several common issues that can hinder their effectiveness. Lengthy response times, lack of QA, and high costs for potentially subpar reports are some of the challenges faced by projects seeking audits. These limitations have prompted the need for alternative approaches that address these shortcomings.

Hats Finance understands the importance of creating incentive alignments through all parties having skin in the game. That's why we have developed a skin-in-the-game audit mechanism in which audit firms can share some of the long-term risks that projects face. This approach enhances QA and ultimately fosters increased trust and accountability between projects and auditing firms, thereby enhancing users' confidence in the security of smart contracts.

<br>

**Framing the problem**

Through our own experience and through countless conversations with representatives of other protocols, we have experienced the shortcomings of traditional audits. We also discovered that Hats.finance security primitive could be used to solve various problems in the following way:

1. Protocols’ security is dependent on the quality of their smart contracts.
2. Even the best solidity experts can make mistakes and find it difficult to review their own code.
3. To increase protocol and user security smart contracts need to be reviewed and audited by external smart contract security experts.
4. While audits conducted by audit firms come at a significant cost, they tend to lack mechanisms that encourage QA.
5. Audit firms can stake part of their fee using Hats.finance vault mechanism, thus demonstrating their commitment to sharing the risks associated with the projects they audit.&#x20;
6. Further, skin-in-the-game audits incentivize auditors to provide ongoing support and guidance beyond the initial assessment.
7. Thus, skin-in-the-game audits support protocols to get higher quality reports, gain greater trust from their users, and enlist ongoing engagement and support from their auditors.

**Key Benefits of Skin-in-the-Game audits:**

Here's how these innovative audits improve on the traditional approach:

1. Enhanced Trust and Accountability: Traditional audit firms examine a contract, identify vulnerabilities, provide a report, and then often disengage. 'Skin-in-the-game' audits, like those championed by Hats Finance, flip this model on its head. By using an on-chain bug bounty protocol, auditors, projects, and community members contribute liquidity to incentivize responsible vulnerability disclosure and reward ethical hackers. This means that audit firms have a vested interest in the ongoing security of the contract, thereby increasing accountability and trust.
2. Shared Risk: Rather than leaving a project to bear the risks of potential vulnerabilities alone, 'skin-in-the-game' audits introduce the concept of shared risk. Audit firms not only evaluate the contract but also share some of the long-term risk exposure. This results in a collaborative relationship where both parties are motivated to ensure robust security.
3. Community Involvement: These audits also increase community engagement. Community members and stakeholders can add liquidity to the bounty pool, actively participating in and influencing the security process.
4. User Trust: Given the improved trust between projects and audit firms, users can feel more secure about the smart contract's safety. This heightened trust can foster a stronger, more vibrant community around a project, enhancing its potential for success.<br>

**Current Audit Firm Partners**

Hats Finance has a growing partnership network of high quality audit firms who are willing to partner with protocols through skin-in-the-game audits. Our current network of skin-in-the-game audit partners includes:

* [Sayfer](https://sayfer.io/)
* [Team Omega](https://teamomega.eth.limo/)
* [Ginger Security](https://gingersec.xyz/)
* [Dcentralab](https://www.dcentralab.com/)


# Bug Bounties

What is a Hats Bug Bounty?

### **Overview**

Bug bounties offer the means to create a fair P2P market for the exchange of vulnerability information. They offer a form of perpetual protection, directly incentivizing security researchers to investigate project codes for vulnerabilities while ensuring projects only need to pay for meaningful security information that could compromise their protocol.

Hats has created the tooling and mechanisms to offer Web3’s first truly decentralized smart bug bounty marketplace. Our bug bounty vaults operate in accordance with the core aspects of the DeFi ecosystem. In short, they are permissionless, protect anonymity, are scalable, and allow anyone to provide liquidity to bug bounties.

### **Framing the problem**

In 2020, Web3 experienced what became known as the DeFi summer. Extraordinary rewards were experienced by protocols and users alike. However, simultaneously, this decentralized new world brought with it severe security risks and exploits began to abound.

We identified a crucial security issue in Web3 and devised a solution to address it. Here's an overview of our thinking process and the measures we implemented to tackle the problem:

* Web3 is built on smart contracts.
* Smart contracts are continuously at threat, offering a bounty in the form of their value or  form of their value or the value that is locked by them.
* Black hat hackers maliciously work to extract the value that is locked by them.&#x20;
* Extracting this value in a malicious manner causes more harm to protocols and the ecosystem as a whole than the size of the extracted value.
* Hacks or exploits have an effect on the adoption of all smart contract projects and the ecosystem itself. Ecosystem adoption could be boosted if we could reduce this risk.
* Protection can be created through incentivizing continuous audits of smart contracts
* Bug bounties enable protocols to incentivize hackers to become blockchain protectors rather than exploiters.
* Hats.finance incentivizes protocols, their users and hackers/security professionals to collaborate towards the success of the ecosystem.

### How Hats bug bounties work

Partners of Hats engage with the vault ecosystem in the following manner:

1. Representatives from the protocol and Hats collaborate to clarify the specific security needs of the protocol. They also determine if a bug bounty program can assist in securing the project.
2. If the protocol decides to establish a vault, it defines the composition of its vault committee. This committee ideally consists of security researchers, developers, and other essential project personnel.
3. In conjunction with Hats' governance, the protocol creates a bounty vault using its project tokens. The protocol can allocate up to 1% of its circulating token supply and earn Hats tokens through farming (subject to Hats' TGE - Token Generation Event).
4. Once the vault becomes operational, if a vulnerability is identified, the hacker must disclose the exploit to the protocol's committee via Hats' encrypted communication channel. The disclosure must include an on-chain hash proof.
5. The committee evaluates the vulnerability submission and either approves or rejects it. If approved, the committee releases funds to the hacker as per the token allocation specified in the vault.


# Audit Frame Game

### Introduction

The Audit Frame Game – a groundbreaking blend of audit competition excitement and community engagement within the Web3 and cybersecurity world. Here, we merge the competitive spirit of security research with widespread community participation.

### Participation Overview

* Security Researchers/Auditors: Exclusively eligible to opt-in for audit competitions, showcasing their skills and competing for top honors and the possibility to win Hats points. To opt-in you must open a White Hat Hacker profile on Hats dapp.
* General Participants: Open to everyone, regardless of experience or background. You can engage in the game by supporting your favorite auditors and participating in community activities.

### How Security Researchers Join the Competition

* Opt-In via Hats dApp: Security researchers interested in competing in audit competitions must opt-in through the Hats dApp where competitions are listed.
* Opt-In Window: Researchers can register their participation until 24 hours before the competition starts. Ensure your spot by opting in early!

### How to Play the Audit Frame Game

* Open to All: While only security researchers compete in the audits, anyone can play the Audit Frame Game by supporting their chosen auditors.
* Game Launch: The game goes live on Warpcast 24 hours before the start of audit competition.
* Earning and Using Game Points: Engage with the Frame Game by liking and recasting content to earn Hats Game Points. Use these points to vote for the auditor you believe will win the highest reward.
* Voting Period: Cast your vote up until half an hour before the audit competition begins. Remember, you have only one vote, so make it count.

### Rewards and Game Points Distribution

* Announcement of Winners: Winners of both the audit competition and the Audit Frame Game will be announced after the competition concludes.
* Rewards Distribution:
  * The winner/s of the competition will receive Hats Points&#x20;
  * 20% of the game's reward pool benefits the auditor who participated in the audit.
  * 80% is shared among players who accurately predicted the winning auditor, proportional to their point allocation.

### Definitions and Terms

* Game Points: Earn these provisional points through game engagement and campaign participation. Convertible to Hats points after completing certain activities.
* Hats Points: Essential, non-transferable points within the Hats.finance ecosystem, granted for activity completion or challenge participation.

### Voting Mechanics

Your support counts as votes, tallied through "Like" and "Recast" actions at the event's distribution time.

### Disclaimer

* Hats Game Points aim to amplify security awareness and community involvement, serving as engagement tools rather than financial assets.
* The kickoff of the Audit Frame game is scheduled to coincide with the beginning of the audit competition, subject to the final time approval of the competition's sponsor.


# Complete Audit Cycle

With Complete Audit Cycle, security researchers can earn additional rewards by delivering more comprehensive and ready-to-use solutions to sponsors through fixes and tests.&#x20;

Complete Audit Cycle leverages researchers' expertise in the projects they secure by:

* Enabling add-ons like fixes and tests for vulnerability submissions
* Allowing peer review of fixes by qualified researchers
* Delivering project-standard code that’s production-ready
* Creating consistent income paths for long-term contributors
* Reducing stress in the reward process for dependable contributors

Who Can Submit: Top 20% of researchers ($5,000+ in earnings)

Impact: We're building tools for decentralized secure development in which researchers not only find issues but also fix them.

This feature enriches the overall audit process, making it more valuable to sponsors while rewarding researchers who invest time and skill into making solutions that are thorough and actionable.

### How the Complete Audit Cycle Works

To be able to send fixes and tests, a researcher must be among the top 20% on the leaderboard with $5,000+ in earned rewards on Hats. Qualified researchers can:

1. Claim Fixes and Tests: Following any vulnerability submission marked for enhancement, top contributors can claim the opportunity to provide the fix and/or test.
2. Submit Complete Solutions: Researchers who claim a fix have 12 hours to submit the complete fix and accompanying test. Fixes must follow the project's code style for quality and consistency.
3. Earn Rewards: For each complete fix and test, points and rewards are provided. This allows researchers to elevate their earnings by completing solutions that enhance overall security.

#### &#x20;Core Fix Requirements:

* Fully addresses identified vulnerability
* Matches project's code style and patterns
* Includes targeted tests covering vulnerability
* Maintains existing interfaces and performance
* Changes focused only on vulnerability fix

#### Core Test Requirements:

* Demonstrates vulnerability existence pre-fix
* Verifies fix prevents vulnerability post-fix
* Covers core edge cases related to vulnerability
* Uses project's testing framework and patterns

#### Acceptance Criteria:

* Fix directly addresses reported vulnerability
* Tests prove vulnerability is fixed
* Code follows project standards
* Changes are minimal and focused
* Documentation clear and complete

#### Fix/Test Rejection Valid Only If:

* Does not fix vulnerability
* Introduces new security risks
* Breaks existing functionality
* Severely impacts performance
* Fails to follow project standards

#### Note: Focus is on proving vulnerability fix effectiveness. Additional edge cases may be suggested but cannot be the sole basis for rejection if core vulnerability is properly addressed and tested.

### The Point System

To incentivize comprehensive reports, the complete audit cycle will offer a tiered point structure:

* Extra Points for Fix  An additional 10% of the initial report points for an accepted fix (tagged as complete by the sponsor)
* Extra Points for Test (only if the issue requires a test): An additional 5% of the initial report points for an accepted fix (tagged as complete by the sponsor)

Let's explore an example of how the pointing system works:

In this reference, researchers receive 1 point per Low finding. That means 1 Low Fix will equal 0.1 extra points (10% of low issue points).&#x20;

<figure><img src="https://lh7-rt.googleusercontent.com/docsz/AD_4nXfpTTfcOagGNh6h_RzL0ah0bwQTPxRo32NRo1bPXykWnWk__sLlAN-iwh10r5TrlR8mJn3X2vI7755PoY6P-bCAAmFBeVqxcGnO0waJjM67D95ESptZXrcGh_hNa9wWI8I-PtevaA?key=ngx8r1PQCqAg_hPYQkTcidbb" alt=""><figcaption><p><em>Important: Percentages for fixes and tests remain consistent across all competitions, but the number of points and maximum rewards vary depending on the specific vault and competition details.</em></p></figcaption></figure>

In cases where a Test isn’t applicable, submitters can check the “Test not applicable” option. Points for completed Tests and fixes are pooled into the total reward for the competition, allowing participants to benefit without additional funding from project sponsors.

<br>


# FOR PROJECTS


# Requesting an Audit

### **Requesting an Audit at Hats Finance**

Welcome to the guide for protocol teams looking to request an audit through Hats Finance. Our platform provides a structured and competitive environment for auditing your smart contracts, ensuring the highest standards of security for your protocol.

### **Why Choose Hats Finance for Your Audit**

Hats Finance stands out in the DeFi security landscape with its unique approach to audits:

1. **Competitive Audit Environment:** Leverage the power of crowdsourcing through our audit competitions, where multiple security experts simultaneously scrutinize your code for vulnerabilities.
2. **Transparent and Decentralized:** Our process is fully on-chain, offering unparalleled transparency and aligning with the ethos of decentralization.
3. **Fair and Equitable Incentives:** We align incentives between protocols and auditors, ensuring auditors are rewarded fairly for their discoveries.
4. **Rapid Turnaround:** Quick setup and execution of audit competitions mean faster results for your project.

### **How to Request an Audit with Hats Finance**

1. Assess Your Needs: Evaluate what you need from the audit. Consider factors like the complexity of your project, criticality of the smart contracts, and desired timeline.
2. Contact Hats Finance: Reach out to us via our [contact form](http://app.hats.finance/contact) or directly through our [Calendly](https://calendly.com/d/d6y-8dr-wd3/hats-security-building-block). Provide a brief overview of your project and your auditing needs.
3. Discuss Audit Scope and Timeline: Once we receive your request, our team will work with you to define the scope of the audit and agree on timelines. We'll ensure the audit competition aligns with your project’s milestones and deadlines.
4. Prepare for the Audit: Ready your codebase for the audit. Ensure your code is well-documented and accessible for the auditors. Provide any necessary background information or documentation that will aid the auditors.
5. Launch the Audit Competition: Once everything is set, Hats Finance will launch the audit competition on our platform. This will invite auditors from our extensive network to participate and scrutinize your code.
6. Review and Implement Findings: After the competition, you’ll receive a comprehensive report of findings. Review these findings with your team and implement the recommended fixes or enhancements.

### **What to Expect After Submitting Your Request**

**Initial Response:** Our team will respond to your inquiry, typically within 48 hours, to gather more details and begin the audit preparation process.

**Customized Approach:** Each project is unique, and we tailor our audit process to fit your specific needs and context.

**Collaboration and Support:** Our team will be in continuous communication with you throughout the audit process, offering support and ensuring a smooth and efficient experience.

### **Ready to Secure Your Protocol?**

At Hats Finance, we are committed to enhancing the security and reliability of the DeFi ecosystem. Requesting an audit with us means not just securing your protocol but also contributing to the broader mission of fortifying the future of decentralized finance.

[Request an audit](http://app.hats.finance/request-audit) today and take a significant step towards ensuring the robustness of your project.


# The Auditing Process

Welcome to Hats Finance's guide to the audit competition process. Our platform ensures a comprehensive, transparent, and efficient audit of your smart contracts, aligning with the evolving dynamics of the Web3 ecosystem.

### **Overview of the Onboarding Process at Hats Finance**

Hats Finance redefines the auditing process by integrating competition, transparency, and decentralization. Here's an overview of our unique approach:

1. **Initiation Submission:** Protocols interested in our offerings seeking an audit submit their request through Hats Finance’s platform, outlining their specific needs and objectives.
2. **Defining Scope and Timeline:** Our team collaborates with the protocol to define the audit’s scope and establish a timeline, ensuring it aligns with the project’s goals and schedule.
3. **Creation of Vault and Committee Multisig:** Each vault is managed by a Multisig address, set up by the project's core team. This setup enables Multisig members to deploy and modify the vault, oversee the check-in (take control), and manage the payout process.
4. **Preparing for the Audit/Bug Bounty/Etc.:** Protocols prepare their codebase for review, ensuring it is well-documented and accessible. Clear documentation helps auditors in understanding the architecture and functionalities.
5. **Launching the Audit Competition/Bug Bounty/Etc.:** Hats Finance announces your protocol’s participation on our platform, inviting a diverse pool of skilled auditors and security researchers to participate. This is an ongoing process that ensures white hats are ready to vet your code from day 1.
6. **Active Auditing Period:** Auditors scrutinize the code, identifying vulnerabilities and suggesting improvements. This period is dynamic, with continuous interaction between auditors and the protocol team.
7. **Compilation and Evaluation of Findings:** Upon completion of the audit competition, all findings are compiled and verified, ensuring no duplicates and that each submission meets our standards of quality and relevance.
8. **Arbitration Option:** In cases of disputes or disagreements over findings, our arbitration mechanism, developed in partnership with Kleros, ensures fair and impartial resolution. This step ensures that auditors and protocols have a balanced platform for resolving any conflicts.
9. **Final Report and Review:** The protocol receives a comprehensive report detailing the findings. This report serves as a guide for implementing necessary security measures and enhancements.
10. **Post-Audit Support:** For protocols using any of our suite of Audit offerings, Hats Finance provides ongoing support and guidance for implementing the audit findings and maintaining the security integrity of the smart contracts.

### **Key Features of Our Auditing**

1. Decentralized and Competitive Approach: Our audit competitions harness the collective expertise of the community, fostering a thorough and diverse examination of the code.
2. Transparent and On-Chain: Every step of the process, from submission to reward distribution, is recorded on-chain, enhancing transparency and trust.
3. Flexibility and Customization: We tailor each audit to the specific needs of the protocol, considering factors like complexity, criticality, and urgency.
4. Community Engagement: The audit process at Hats Finance actively involves the community, encouraging participation from a wide range of auditors and security experts.
5. Fair and Equitable Rewards: Auditors are fairly compensated based on the severity and impact of their findings, aligning incentives and ensuring high-quality submissions.

### **Start Your Security Journey with Hats Finance**

Begin the process of securing your protocol]\(<http://app.hats.finance/start-audit>) with Hats Finance and join the movement towards a safer, more resilient Web3 world.


# Preparing for an Audit Competition

Embarking on an audit competition with Hats Finance is a significant step towards ensuring the security and integrity of your smart contract. Proper preparation is key to a smooth and effective audit process. This guide provides an overview to help protocols prepare for a Hats Audit Competition. However, should you be at the point of wanting to get things rolling in real time, here is a link to the more detailed [Hats Audit Competition onboarding template](https://docs.google.com/document/d/1G30J28NJ5Vfon47blAt7-bxijQGRYYgH9_4C39o2l0U/edit#heading=h.3uycra2ngzdq) that walks you through preparatory activities step-by-step.

### **Define the Audit’s Scope and Objectives**

Clearly outline what you hope to achieve with the audit. Are you looking for a general security check, specific vulnerability assessments, or both? Pinpoint critical components of your smart contract that require special attention. High-value pools, governance mechanisms, or any novel implementations are examples of such areas. Specify severity levels with clear definitions ensuring your criteria will incentivize security researchers to focus on what is of greatest value to you.

Be very specific about which code is in scope for the review, so that reviewers know where to look. Also, be very specific about which kind of vulnerabilities you will reward, and which vulnerabilities are not in scope - are you interested only in attacks in which money is lost or a protocol is halted, or will you reward deviations from the specifications, or suggestions for code improvements and gas optimizations as well?

### **Create Your Point System**

Incorporate a customizable pointing system to evaluate vulnerabilities, assigning points to severity levels that match your project's priorities. For instance:&#x20;

* Low Severity: 1 point&#x20;
* Medium Severity: 12 points&#x20;
* High Severity: 25 points

Note: You should adjust these point values based on your audit's specific needs. Our team is ready to support you to define your point system should you so desire.

Each point represents a portion of the bounty pool, with payouts adjusted based on total points awarded. This ensures rewards are aligned with your audit objectives, encouraging researchers to prioritize findings that offer the greatest value to your project.&#x20;

### **Document and Organize Your Codebase**

1. **Code Documentation:** Ensure your code is well-documented: documentation will help auditors to quickly become familiar with the purpose of your code, and gives auditors a tangible way of seeing when a contract is not doing what it is supposed to do This includes clear comments within the code and a comprehensive readme file explaining the overall architecture and functionality.
2. **Testing:** Your code should come with a complete and thorough set of tests. This will not only help you to catch bugs and mistakes yourself, but it will also help auditors understand how you intend your code to be used. Use continuous integration - like github actions - to make sure your tests are reproducible and all pass.
3. **Provide Deployment Scripts:** Provide documented deployment procedures. Some on-chain vulnerabilities can be the result of a botched or misconfigured deployment - and having your deployment procedures audited will mitigate these risks as well .

### **Disclose Known Vulnerabilities**&#x20;

It is important for researchers to not waste time describing vulnerabilities that your team is already aware of, so you should be as clear and complete as possible in this regard. If you have (for example) github issues describing such vulnerabilities, mention these in the description of your scope. If your code was audited before, provide such earlier audit reports. And if your protocol has experienced security incidents in the past, provide details about them.

Understanding past vulnerabilities can help auditors focus on potential recurring issues or overlooked aspects of your code.

### **Establish Communication Channels**

1. **Dedicated Communication:** Set up a dedicated channel for communication with auditors. This could be a Discord server, Telegram group, or an email hotline.
2. **Availability for Queries:** Allocate team members who can respond to queries from auditors. Prompt responses can significantly expedite the auditing process.

### **Prepare for Post-Audit Activit**ies

1. **Plan for Implementing Fixes:** Have a strategy for addressing and implementing fixes or recommendations that emerge from the audit.
2. **Reserve time for arbitrage:** Some audit competitions receive a large number of submissions, and it may require a significant amount of time to read and judge each of them
3. **Consider Arbitration Mechanisms:** Understand the arbitration process offered by Hats Finance, especially if disputes arise regarding the findings.

### **Bonus Tips**

1. **Engage with the Community:** Consider reaching out to the Hats community for preliminary feedback or suggestions before the official audit competition begins.
2. **Stay Informed:** Keep up with the latest developments in smart contract security to anticipate potential areas of vulnerability in your protocol.

By following these steps, you can set the stage for a thorough and effective audit competition with Hats Finance. Your proactive efforts in preparation not only facilitate a smoother audit process but also demonstrate your commitment to the security and reliability of your protocol. Begin your journey towards a secure future with Hats Finance today.


# Setting Up a Bug Bounty

Welcome to Hats Finance's Bug Bounty Program. This guide is designed to assist protocols in setting up and managing a bug bounty with us, ensuring a structured and effective approach to securing smart contracts. For real-time step-by-step assistance, please refer to our detailed Hats Bug Bounty onboarding template.

### **Defining the Bug Bounty's Scope and Objectives**&#x20;

The first step in setting up a bug bounty is defining its scope and objectives. Determine what you hope to achieve: Is it a general security check, specific vulnerability assessments, or both? Pinpoint critical components of your smart contract that require special attention, such as high-value pools or unique governance mechanisms.

#### **Documentation and Organization of Your Codebase**

**Code Documentation:** Ensure your code is thoroughly documented. This includes clear comments and a comprehensive readme file explaining the overall architecture and functionalities.

**Version Control:** Maintain an organized version control system using platforms like GitHub.

**Testing and Deployment Scripts:** Provide testing scripts and deployment procedures to help researchers understand how your system operates. Configure continous integration - such as github actions - to that you are sure your tests all pass and are easily reproducible.

**Accessibility and Understanding Access to Codebase:** Ensure the codebase is accessible to researchers. Make private repositories available to the Hats team and bug bounty participants.

**Clarify Dependencies:** List and explain any external dependencies your contract has.

**Disclose Known Vulnerabilities:** It is important for researchers to not waste time describing vulnerabilities that your team is already aware of, so you should be as clear and complete as possible in this regard. If you have (for example) github issues describing such vulnerabilities, mention these in the description of your scope. If your code was audited before, provide such earlier audit reports

#### **Disclosure of Past Incidents**&#x20;

If your protocol has experienced security incidents in the past, provide details. Understanding past vulnerabilities can guide researchers to focus on potential recurring issues.

#### **Establishing Communication Channels**&#x20;

Dedicated Communication: Set up a channel for communication with researchers, like a Discord server or Telegram group.

**Availability for Queries:** Assign team members to respond to queries from researchers promptly.

#### **Preparation for Post-Bounty Activities**&#x20;

**Implementing Fixes:** Have a strategy for addressing and implementing recommendations or fixes from the bounty.

**Understanding Arbitration:** Familiarize yourself with Hats Finance’s arbitration process for dispute resolution.

### **Launching Your Bug Bounty**

**Vault Setup:** Define your vault committee, which should consist of security researchers, developers, and essential project personnel. Create a bounty vault using your project tokens. Earn Hats tokens through farming post-TGE (Token Generation Event).

**Vault Rules & Guidelines:** Define the in-scope code, severity types, total rewards, and competition duration. Customize severity descriptions and submission guidelines as needed. Share these decisions with the Hats team and use our Vault Editor to set up your vault.

**Responsibilities of the Committee:** The committee is responsible for monitoring and triaging audit reports, and communication with the submitter. These reports are encrypted, and can only be read by the committee (and not by HATs), so make sure you save the PGP keys that you need to read the messages.

**Known Issues Document:** Add this to your repository with a link in the vault description. Optional Documentation: Create documentation of the protocol and architecture, including diagrams.

### **Example of Severity Descriptions**

**Critical Severity:** Includes economic attacks, cryptographic flaws. Prize capped based on the potential risk.&#x20;

**High Severity:** Covers temporary inability to transfer tokens, transient consensus failures.&#x20;

**Medium Severity: I**ncludes gas griefing, denial of service.&#x20;

**Low Severity:** Non-critical functional issues with no fund risk.&#x20;

**Limitations:** Reporters will not receive a bounty for known issues, vulnerabilities made public, “centralization risks”, or attacks requiring leaked private keys.

By preparing meticulously for your bug bounty with Hats Finance, you facilitate a smoother process and demonstrate your commitment to security. Start securing your protocol's future with Hats Finance today.


# Pricing Structures

Welcome to Hats Finance’s pricing structure, where we prioritize value, transparency, and efficiency. Our innovative approach to pricing sets us apart from competitors, offering unparalleled benefits for both projects and security researchers.

### **Key Features**

1. **Result-Oriented Pricing:** At Hats Finance, our fundamental principle is 'Pay Only for Results'. Unlike traditional models which often require significant upfront costs, our clients pay exclusively for actionable, validated vulnerabilities. This ensures that you invest only in results that enhance your protocol's security.
2. **Fee Structure:** Hats Finance fee consists of a management fee and a success fee. Depending on the bounty the percentages change to maximize participation and incentivization for auditors.
3. **Minimizing Financial Risk:** Our unique risk reversal model significantly reduces the financial risk for projects. By only charging for small fees and successful vulnerability submissions, we alleviate the financial burden typically associated with security audits.
4. **Enhanced Reward Incentive:** This pricing structure allows us to offer higher rewards to participating security researchers, creating a strong incentive for the best of the best to engage with our audit competitions and bug bounties. High rewards draw top talent, ensuring thorough and effective security assessments.
5. **Better Deal Than Competitors:** Our pricing model is designed to be more cost-effective and value-driven compared to our competitors. We understand the importance of security in the Web3 space and strive to make it accessible and affordable for projects of all sizes.
6. **Transparent and Fair:** With Hats Finance, there are no hidden fees or charges. Our transparent pricing ensures that projects understand and agree to the cost implications from the outset, fostering trust and long-term partnerships.

### **Conclusion**

At Hats Finance, we believe in fair pricing, aligned incentives, and the power of community-driven security. Our pricing model reflects these values, offering a cost-efficient, transparent, and effective solution for securing your Web3 projects.

Interested in learning more about our pricing or starting an audit competition? Contact us through our [Calendly ](https://calendly.com/d/d6y-8dr-wd3/hats-security-building-block)or visit [Hats Finance dApp](http://app.hats.finance).


# FOR SECURITY RESEARCHERS


# Participating in Audit Competitions

Welcome White Hats!

Welcome to Hats Finance, a platform where White Hat auditors and security experts like you play a critical role in enhancing the resilience of the Web3 ecosystem. Our Audit Competitions are designed to challenge, reward, and recognize your expertise in uncovering vulnerabilities and strengthening decentralized applications.

### **A Quick Start Guide for Security Researchers**&#x20;

As a security researcher at Hats Finance, you have the unique opportunity to engage in audit competitions that not only test your skills but also contribute to the overarching goal of fortifying DeFi protocols against potential threats.

### **Why Participate?**&#x20;

**Competitive Rewards:** Hats Finance offers substantial incentives for your contributions, with fast payouts for the first unique submissions.&#x20;

**Transparent Processes:** Our fully on-chain system ensures that your submissions and the subsequent evaluations are completely transparent.&#x20;

**Reputation Building:** Successful submissions qualify participants to gain XP and be included in our leaderboard enhancing your reputation which can also contribute to receiving new opportunities. Community Collaboration: Join a network of fellow auditors in a decentralized environment, where community governance and shared knowledge are at the forefront.&#x20;

**Continuous Learning:** Each competition is a chance to sharpen your skills, learn new techniques, and stay updated with the latest in smart contract security.

### **Getting Started**&#x20;

To jump into Hats Finance audit competitions, follow these steps:&#x20;

* **Explore Active Competitions:** Review the list of ongoing audit competitions on our dApp, where you'll find details on scope, rules, and rewards.&#x20;
* **Open a Hats Finance Profile:** To participate you will need to create a profile on our dApp.&#x20;
* **Prepare Your Tools:** Ensure you have the necessary tools for static and dynamic analysis, manual code review, and any other resources that aid in your auditing process.&#x20;
* **Understand the Rules:** Each audit competition comes with a set of rules and scope. Familiarize yourself with these to maximize your efficiency and align your efforts with the competition's objectives.&#x20;
* **Submit Findings:** Once you've identified vulnerabilities, submit your findings through our on-chain process. Your submissions will create an immutable record on the blockchain, ensuring transparency and traceability.&#x20;
* **Collaborate and Discuss:** Engage with the protocol representatives if questions or disputes arise.

### **The Audit Competition Lifecycle**&#x20;

If you are investigating our upcoming competitions you can think about the phases in the following way:

**Preparation Phase:** Review documentation and prepare your testing environment.&#x20;

**Discovery Phase:** Use your expertise to uncover potential vulnerabilities within the given scope.&#x20;

**Submission Phase:** Document and submit your findings according to the competition guidelines.&#x20;

**Evaluation Phase:** The project committee reviews submissions, with the option for disputes to be resolved through our decentralized arbitration mechanism.&#x20;

**Reward Phase:** Successful submissions receive rewards, distributed directly to your wallet.

### **Your Role as an Auditor**&#x20;

As a white hat auditor, you're not just a bounty hunter; you're a guardian of the DeFi space. Your analytical skills, attention to detail, and innovative thinking are crucial in the collective effort to secure decentralized technologies.

At Hats Finance, we're committed to supporting you every step of the way. From comprehensive resources to responsive community support, we ensure that you have everything you need to succeed in our audit competitions.

Ready to make your mark? Start your journey with Hats Finance today.


# Submission Guide

### **Writing a Finding**

**Understand the Scope and Rules:** Before beginning your audit, make sure you fully understand the scope and specific rules of the competition. Focus your efforts on areas that are within the defined scope to ensure your findings are eligible for rewards.&#x20;

**Identify Vulnerabilities:** Use a combination of manual code review and automated tools to identify vulnerabilities. Prioritize vulnerabilities based on their severity and impact on the protocol.&#x20;

**Document Your Findings:** Clearly and concisely document each vulnerability you find. Include the following in your report:&#x20;

* **Title:** A concise title that summarizes the vulnerability.&#x20;
* **Severity:** Estimate the severity of the vulnerability (High, Medium, Low).&#x20;
* **Description:** Detailed explanation of the vulnerability, how it works, and why it is a threat, including code references.&#x20;
* **Proof of Concept:** Step-by-step instructions or a script demonstrating the vulnerability.&#x20;
* **Suggested Fix:** If possible, suggest a way to mitigate or fix the vulnerability.

### **Submitting Your Findings**&#x20;

* **Prepare Your Submission:** Ensure your report is clear, concise, and contains all necessary information. Double-check the competition rules for any specific submission requirements.&#x20;
* **On-Chain Submission Process:** Hats Finance uses an on-chain submission process for increased transparency and traceability. Submit your findings through our dApp, which will record your submission on the blockchain.&#x20;
* **Await Review:** Once submitted, your finding will be reviewed by the project’s committee. The committee may reach out to you for further discussion or clarification on your submission.&#x20;
* **Reward Process:** If your finding is accepted, you will be rewarded based on the severity of the vulnerability and in accordance with the competition's reward structure. Hats Finance ensures timely and fair compensation for your valuable contributions.

### **Tips for a Successful Submission**&#x20;

**Detail is Key:** The more detailed your report, especially in the proof of concept, the better your chances of it being accepted.

**Stay Updated:** Keep abreast of the latest vulnerabilities and hacking techniques to ensure your skills remain sharp.&#x20;

**Communication:** Be ready to engage in discussions regarding your findings. Clear communication can often be as important as the finding itself.

Thank you for participating in Hats Finance audit competitions. Your efforts help secure the future of DeFi and contribute to a safer Web3 environment.&#x20;


# Evaluating the Severity of Submissions

This page provides a structured approach to classify the severity of your findings accurately, ensuring they are in line with our criteria for low, medium, and high-severity issues.

### **Understanding Severity in Vulnerability Assessment**&#x20;

The severity of a vulnerability is a measure of its potential impact on the system, considering factors like exploitability, impact on users, and the complexity of mitigation. Accurate severity assessment helps in prioritizing fixes and understanding the risk associated with the vulnerability.

### **Example Severity Levels Defined**

The following are some generic examples of severity levels. However, protocols have complete control over defining these for their own unique needs.

**Low Severity:** These are typically minor issues that pose a limited impact on the system. They might include: Inefficiencies in gas usage. Minor deviations from best practices that don't lead to security risks. Small bugs that do not affect the protocol's functionality or security.

**Medium Severity:** These issues represent a greater threat and may include: Vulnerabilities that can cause temporary disruption but do not lead to direct loss of funds or long-term damage. Flaws that require specific conditions or privileges to exploit. Vulnerabilities that impact the user experience but do not compromise the overall security of the protocol.

**High Severity:** These are critical issues that demand immediate attention, such as: Direct theft or loss of user funds. Long-term freezing of user funds. Vulnerabilities leading to protocol insolvency. Exploits that allow unauthorized control or manipulation of the protocol.

### **Evaluating the Severity of Your Findings**

**Analyze Exploitability:** Assess how easy it is to exploit the vulnerability. High-severity issues are often easily exploitable, while lower-severity ones require more specific conditions.

**Consider Impact:** Evaluate the potential damage the vulnerability can cause. High-severity vulnerabilities usually have widespread implications, like loss of funds or user trust.

**Review Attack Complexity:** Consider how complex it is to execute the attack. The simpler it is, the higher the severity.

**Check for Mitigation and Workarounds:** Determine if there are easy fixes or workarounds. Issues without straightforward solutions are often of higher severity.

**Contextualize Within the Protocol:** Understand how the vulnerability fits within the broader context of the protocol. Issues affecting core functionalities are generally of higher severity.

Another helpful principle to take into account is the combined impact and probability of an exploit. The combination of these two factors can help inform your evaluation of a finding severity level.


# Becoming a Lead Auditor

The Lead Auditor's role at Hats Finance is pivotal in maintaining the integrity and security of our sponsor’s codebase. The Lead Auditor is tasked with thoroughly reviewing and assessing all submitted code, ensuring the sponsor’s codebase is robust, secure, and efficient.

### Key Responsibilities

1. **Comprehensive Code Review:**
   * Conduct meticulous reviews of all submitted code.
   * Draft detailed and comprehensive audit reports outlining findings.
2. **Structured Evaluation:**
   * Label and organize other submissions with a Lead auditor label to ensure a fair and structured evaluation process. The lead auditor can’t label his submissions.
   * Provide clear and unbiased assessments.
3. **System Architecture Assessment:**
   * Evaluate the overall architecture of the system.
   * Identify systematic or centralization risks.
4. **Documentation Scoring:**
   * Assess the quality of the provided documentation.
   * Offer clear and constructive feedback to improve future submissions.
5. **Recommendations for Deployment and Monitoring:**
   * Provide strategic recommendations for the deployment and monitoring of contracts.
   * Ensure best practices are followed to maintain system integrity.
6. **Reviewing Fixes:**
   * Reassess code after implemented fixes to ensure vulnerabilities are properly addressed.

### Selection and Compensation

* The Lead Auditor is selected by the Sponsor.
* Compensation includes a base fee, which varies depending on the competition
* The lead auditor will compete like any other auditor to gain more rewards.
* To ensure fairness, the Lead Auditor will have access to the codebase simultaneously with other participants.

### Tips to Become a Lead Auditor

1. High Ranking on Hats Leaderboard:A high ranking on the Hats Leaderboard significantly increases your chances of being selected as a Lead Auditor.
2. Maintaining an Updated GitHub Account: Keep your GitHub account tidy and up-to-date, and connect it to the Hats Leaderboard to showcase your skills and contributions.

### Future Opportunities

Achieving a high rank on the Hats Leaderboard opens doors to becoming a Lead Auditor and unlocks many other opportunities within Hats Finance. Stay tuned for more opportunities in the future!

By fulfilling these responsibilities, the Lead Auditor plays a crucial role in safeguarding our sponsor’s codebase, ensuring the quality and security of their code, and contributing to Hats Finance's overall success.

<br>


# FOR COMMUNITY


# Governance

Hats.Finance is committed to building a decentralized and community-driven ecosystem. To achieve this, we are implementing a DAO governance model that empowers the community to actively participate in shaping the platform's future.

The initial members of the DAO will be the current members of the core team.

### Legal Entity and Liability Framework

Hats DAO, operating as a decentralized autonomous organization, is affiliated with the Incentive Alignment Foundation in the Cayman Islands. This foundation acts as a legal entity and liability shield, protecting DAO members from potential legal exposure and legitimizing the DAO's governance protocols. The foundation's role includes compliance oversight, particularly concerning Anti-Money Laundering measures for the DAO Treasury. Despite this affiliation, Hats DAO retains its autonomous operational ethos. The involvement of the Incentive Alignment Foundation does not imply any direct control over DAO activities, nor does it assume liability for the outcomes of these activities.

### Governance Structure

Instead of a single, monolithic governance body, Hats.finance will utilize specialized Guilds focusing on key areas of the platform's growth and development:

* Product Guild: Responsible for ideation, development, and iteration of new features and products.
* Marketing Guild: Focused on promoting Hats.finance, building brand awareness, and expanding community reach.
* Growth Guild: Dedicated to driving user acquisition, partnerships, and overall ecosystem expansion.
* Management Guild: Oversees operational efficiency, treasury management, and platform sustainability.

### Quarterly Funding and Proposal Evaluation

At the start of each quarter, each Guild will be allocated a predetermined amount of $HAT tokens from the DAO treasury. These funds will be managed within a dedicated Guild Vault. Community members can submit proposals to the relevant Guilds outlining their ideas or plans for executing initiatives within the Guild's scope.

### Proposal Submission and Reward Mechanism

Each proposal should clearly outline:

* Problem or Opportunity: A concise description of the problem being addressed or the opportunity being explored.
* Proposed Solution: A detailed explanation of the proposed solution or initiative.
* Implementation Plan: A clear roadmap with defined milestones and timelines.
* Budget Request: A breakdown of the requested funding and how it will be utilized.

### Proposal evaluation

Guilds will evaluate proposals based on the following criteria:

* Potential Impact: The potential impact of the proposal on achieving the Guild's objectives.
* Feasibility and Viability: The practicality and likelihood of successful implementation.
* Budget Efficiency: The responsible and effective use of requested funds.
* Alignment with Hats.finance Vision: The proposal's alignment with the overall vision and values of Hats.finance.

### Reward Distribution

Guilds have the authority to approve and reward proposals in two ways:

* Immediate Reward: Full funding is provided upfront for smaller initiatives or proposals with a clear and immediate impact.
* Milestone-Based Linear Release: Funding is released incrementally as the proposer achieves predefined milestones. This approach ensures accountability and minimizes risk for the DAO. Guilds retain the right to revoke funding if milestones are not met.

### Voting Power and Quarterly Votes

At the end of each quarter, the community will participate in votes to determine the allocation of the next quarter's funding for each Guild. Voting power will be determined by $HAT holdings, with varying weights to encourage long-term commitment and platform utilization:

* Regular $HAT Tokens: 1x voting power (delegated or undelegated)
* Locked $HAT Tokens: 2x voting power
* $HAT Tokens in Hats Vaults: 3x voting power (tokens actively contributing to bug bounties or other platform services)

This tiered voting system encourages active participation, long-term commitment, and utilization of the Hats.finance platform, ensuring that those most invested in the ecosystem have a greater influence on its direction. However in the future, Hats Finance will move towards ve tokenomics, so $HAT will have to be locked and converted to veHAT to accrue voting power. We will notify the community when this happens.&#x20;

### Becoming a Guild Member:

Hats.finance encourages active community members to participate in Guild activities. Individuals who consistently demonstrate their commitment and expertise to a specific Guild can apply for membership.

The application process will involve:

* Submission of Contributions: Providing evidence of meaningful contributions to the Guild's area of focus, such as code contributions, marketing initiatives, growth strategies, or operational improvements.
* Community Endorsement: Receiving endorsements from existing Guild members and the wider community based on the applicant's demonstrated expertise and commitment.
* Guild Approval: The Guild members will vote on the applicant's acceptance based on their qualifications and the potential value they bring to the Guild.

### Multisig Governance

Hats DAO employs Multisig wallets for decision execution and treasury management. Comprising elected delegates, these Multisigs ensure responsible governance and effective management of DAO operations.

### Treasury Management

The DAO's treasury income is allocated towards ensuring the long-term sustainability and growth of the Hats ecosystem. Governance decisions on fund allocation are made with ethical considerations and alignment with DAO principles.

### Legal Considerations

Membership in Hats DAO is structured to avoid legal liability for DAO activities. All legal matters are managed through the Incentive Alignment Foundation, delineating a clear boundary between the decentralized operations of the DAO and its legal responsibilities. This setup ensures that DAO activities remain within the ambit of legal compliance while upholding the principles of decentralization.<br>

The abovementioned operational processes will be managed by the management guild, and the initial team comprising the management guild will be from the Hats Finance team.&#x20;

\ <br>


# Tokenomics

HAT Tokens are utility tokens that hold no association or connection with securities.&#x20;

They are specifically designed for utilization within the Hats Governance framework and hold no ownership, equity, or financial rights in the form of securities.

Please note that the information provided herein is for informational purposes only and does not constitute an offer, solicitation, or recommendation to purchase HAT Tokens or engage in any investment activities. The acquisition, possession, and utilization of HAT Tokens carry inherent risks, and potential token holders are advised to conduct their own research, seek professional advice, and understand the associated risks before engaging in any transactions or activities involving HAT Tokens.

HAT Tokens may be subject to legal and regulatory requirements in different jurisdictions, and it is the responsibility of individuals or entities to comply with applicable laws and regulations governing their acquisition, possession, transfer, and use.

The project team, developers, and affiliates associated with HAT Tokens disclaim any warranties or representations, express or implied, regarding the functionality, security, or performance of HAT Tokens or the Hats Governance framework. The team shall not be held liable for any losses, damages, or liabilities arising from the use, possession, or reliance on HAT Tokens or any related activities.

By acquiring, possessing, or utilizing HAT Tokens, you acknowledge and agree to release the project team, developers, and affiliates from any claims, liabilities, or disputes arising from the acquisition, possession, or use of HAT Tokens, to the fullest extent permitted by applicable laws.

This disclaimer is subject to change and may be updated without prior notice. Individuals or entities engaging with HAT Tokens are advised to regularly review this disclaimer for any amendments or updates.

**TL;DR**

* $HAT token contract address on [ethereum](https://etherscan.io/token/0x76c4ec0068923Da13Ee11527d6cF9b7521000049) and [arbitrum](https://arbiscan.io/token/0x4D22e37Eb4d71D1acc5f4889a65936D2a44A2f15)&#x20;
* $HAT is the native governance token of Hats Finance
* 50% of the $HAT genesis supply is allocated to Hats community members.
* $HAT tokens will be rewarded to users who join any Hats protocol bounty vaults.

### Token allocation

<figure><img src="https://lh7-us.googleusercontent.com/docsz/AD_4nXeo9vbjCzMN7vs9sxjH_lOFI4RdD_8lfZMqIGe6XRzzPj9zjxZGHLUMxi3Qj_obrtostDK0--PjyaTRVHBTPuuKVyYBWkSwh6lrcqHydZI1gRLVmpfx9n9-6hKXa5SMiSxNZvHdzQdiZAJJk3j_lMwfNKYO?key=B9qXjTH6uYU2naaJNdPvdg" alt=""><figcaption></figcaption></figure>

The total supply of $HAT tokens is capped at 100 million. Here are some of the key allocations:

* Core Team Tokens: 20% (20,000,000 HAT), vesting over 27 months from the TGE.
* Seed Round: 11.50% (11,500,000 HAT), vesting over 24 months from the TGE.
* Private Round: 6.61% (6,611,111 HAT), vesting over 21 months from the TGE.
* Public Round: 0.3% (255,000 HAT), vesting over 6 months from the TGE.
* Airdrop: 5.23% (5,228,611 HAT), vesting over 3 months from the TGE.
* Marketing: 0.40% (400,000 HAT), vesting over 12 months from the TGE.
* Incentives: 28% (28,000,000 HAT), vesting over 48 months from the TGE.
* LBP: 4% (4,000,000 HAT) immediately unlocked from TGE

### Liquidity mining

The total HATs Tokens for the 1st liquidity mining program will be 8,500,000, comprising 8.5% of the total token supply. The initial PPM(Protocol Protection Mining) program is not subject to vesting.

At its discretion, Hats governance can decide to replace the current liquidity mining program with another one to best align with the implementation of new protocol features.

### $HAT token uses

$HAT tokens offer numerous use cases, making them a valuable component in the Hats Finance ecosystem. The key utilities are listed below.

### Governance:

By holding $HAT tokens, you gain voting power in Hats Finance’s governance system, allowing you to participate in decision-making and shape the future of Web3 security. Locking or delegating your $HAT tokens lets you benefit from the platform’s economic activities and helps optimize incentives. Token holders also govern platform fees, decide on revenue utilization, and influence decisions on all aspects of Hats Finance, from code changes to competition rules.

This balanced system appeals to both auditors and audit buyers. Community members can also get involved by locking or delegating their tokens and have a say in the future of Hats Finance and security!

### Bug Bounty Farming

You can deposit the $HAT tokens into the Hats Finance Bug Bounty Vault and earn APY on your $HAT token deposits. A full guide on Bug Bounty liquidity farming is available on our [Medium page](https://hatsfinance.medium.com/how-to-deposit-liquidity-on-bug-bounties-with-hats-finance-9db137293fba).

Please note: APY is subject to fluctuation without prior notice.

### Enhancing Security and Community

Community users who hold the $HAT token may stand to enjoy personal security services by security researchers, access previously granted to protocols only. Hats Finance is currently developing these tools and services, which we will share with the community soon.

### For Security Researchers

$HAT tokens incentivize security researchers to engage in audit competitions and bug bounties, fostering more secure projects. Security Researchers will be rewarded with Hat Points and $HAT tokens for submitting valid bugs. This collaborative effort bolsters security and secures the future success of Hats Finance and the security of the web3 space.

Security researchers pay a small fee in the network’s native token (e.g., ETH on Arbitrum) to submit a vulnerability, minimizing spam and ensuring constructive engagement, which is converted into $HAT. Initially set at $0.30, the fee can be adjusted by stakers based on activity levels and subsequent DAO governance proposals.

Alternatively, researchers can stake some $HAT to submit reports without paying a transaction fee. Abusing this privilege may result in penalties. Researchers can become Lead Auditors by staking more $HAT and achieving a top 50 leaderboard position. Lead Auditors can be booked for competitions and are responsible for triaging submissions and creating audit reports.

### For Protocols and Customers

A minimum amount of $HAT will need to be staked to deploy a vault on the Hats Finance’s Platform. Staking more $HAT increases the vault’s visibility and competitiveness, especially during high-demand periods. Hats Finance is also planning some additional incentives and discounts for loyal customers should they stake additional $HAT tokens, which we will announce in the future.

Please note that the exact amount figures outlined in these utilities are still to be finalized even after the docs are published and may continue to evolve with DAO governance in the future.

### HATs token uses in the protocol:

Each exploit that will be fixed and rewarded through the protocol will trigger a split function that will incentivize hackers, committees, and protocol participants to further use the protocol. The split function parameters can be set by the governance and their default is:

* 60%: 30 days vested Vault tokens for (Hacker reward)
* 20% Vault tokens (Hacker reward). Fungible tokens for immediate hacker use
* 5% Committee. To incentivize committee resolution and triage of vulnerabilities reports.
* 5% Converted through Uni v3 to Hats and vested for 90 days (Hacker reward). To make the hacker invested in the protocol they have just added value to and to incentivise them to further disclose vulnerabilities through Hats protocol
* 10% Converted through Uni v3 to Hats and sent to Governance. To incentivize the long-term sustainability of the protocol and its community needs.

### Goals of the Tokenomics

The $HAT token is designed with clear objectives to serve crucial roles within our ecosystem:

* **Access to Expertise and Services**: The token facilitates access to our global network of security experts and additional features like triage competitions, bot races, and decentralized arbitration services.
* **Competitive Advantage in Talent Acquisition:** Holding $HAT provides a competitive edge in attracting top security talent by offering additional visibility and exclusive opportunities within the Hats Finance ecosystem.
* **Monetary Benefits and Ecosystem Growth:** Stakeholders benefit financially by aligning with the protocol's growth trajectory. This alignment is instrumental in building a sustainable and fortified ecosystem, creating a competitive moat around Hats Finance.

The $HAT token is more than just a means of transaction; it's a cornerstone in our strategy to build a secure, efficient, and community-driven security service ecosystem.

### Value Accrual in Two Phases

#### Phase 1: Network Effects

* Objective: Focus on accelerating growth and achieving network effects.
* Incentives: Core actions are incentivized through liquidity mining and airdrops, encouraging the creation of vaults and delivery of security services.
* Staking Benefits: Staking $HAT tokens offers increased access, visibility, and monetary benefits, signaling long-term commitment. Staking is optional but provides competitive advantages.
* Community Ownership and Governance: Stakeholders begin to shape the protocol’s rules and processes, contributing to a strong community-driven ecosystem.
* Arbitration Service: Activation requires a token stake, with a slashing mechanism for the losing party in arbitration, doubling as spam protection.
* Token Buyback: Fees generated by the protocol are used for token buybacks, enhancing treasury value.

#### Phase 2: Value-Accrual

* Transition: Initiated once the community agrees that network effects are sufficiently established.
* Mandatory Stakes: Participation in the marketplace requires a minimum stake from both security experts and customers.
* Stake Utilization: Ensures efficient marketplace operation, with potential slashing for malicious actions.
* Stake Influence: Determines participant visibility, module access, and fee structures.
* Token Buyback and Revenue Sharing: Continuation of the buyback policy; additional incentives for building on the protocol and revenue sharing.

In both phases, the $HAT token plays a crucial role in fostering a thriving ecosystem, aligning stakeholder interests with the protocol’s growth, and ensuring a fair, efficient, and rewarding marketplace.


# $HAT Airdrop

Starting on July 25th, 2024, at 7 pm UTC, our long-awaited $HAT treasure vault will be live and available for claiming. 5% of our total $HAT token supply will be airdropped to our dedicated community members. This claim period will run until October 25th, 2024, when unclaimed tokens will be returned to the DAO.

### Who’s Eligible?

Here’s a breakdown of the groups eligible for the airdrop and what actions make you qualify:

* Crow NFT Holders: Recipients of the Hats “Crow” NFT (1st airdrop only).
* Committee Members: Members of bug bounty committees (1st airdrop only).
* Depositors: Individuals who have deposited into Hats vaults (1st airdrop only).
* “Super Coder” NFT Holders: Recipients of the Hats “Super Coder” NFT (1st airdrop only).
* Hats Early Supporters: Recognized early supporters of Hats (1st airdrop only).
* Security Payout Participants: Depositors into audit competitions or bug bounty vaults with payouts issued before July 2nd.
* Security Researchers: Recipients of payouts from audits or bug bounty programs before July 2nd.
* Security Content Creators: Creators of approved content for Hats before July 2nd.
* Hat Hunters Treasure Hunt Participants: Users of TaskOn, Galxe, and Warpcast who participated before the snapshot.
* Monad Community: Top whitelisted contributors for the Monad airdrop.

Please note that team members are unable to advise whether you are specifically eligible for an airdrop over community channels, as we need to understand your full history of transactions with Hats Finance. Please wait for the airdrop checker to be released.

### Airdrop Allocation

The $HAT token allocation will differ across these groups, with each airdrop vested over three months. The eligible members will get 33% unlocked right on the Token Generation Event day.

### Disclaimer:

If you miss the deadline to claim your airdrop, your unclaimed $HAT tokens will be returned to the DAO (Decentralized Autonomous Organization). This means you will lose the opportunity to benefit from your allotted tokens. Be sure to act promptly to secure your share and take advantage of all the rewards and opportunities within the Hats Finance ecosystem.

### How to Claim Your $HAT Tokens

1. Visit Hats Finance Dapp: Go to the official [Hats Finance Dapp](https://app.hats.finance/) on July 25th, 2024.
2. Connect Your Wallet: Make sure your wallet is securely connected to the platform using the same wallet you used before to interact with the Hats Finance app.&#x20;
3. Check Eligibility: Press “Use connected wallet” or paste your wallet address in the “Check Your Eligibility” box and press the “Check Eligibility” button to see if you qualify for the airdrop. If you have used multiple wallets with the Hats Finance app, you can check those addresses, too. Click “Check Eligibility” to go to the next page.
4. Claim Tokens: If you are eligible, your designated airdrops will be displayed on the page. You may qualify for one or both of the following airdrops:
   * Immediate Airdrop: Tokens available for instant claim.
   * Linearly Released Airdrop: Tokens released over a specified period.

To begin the claim process, press the Redeem button. Please note that your tokens will gradually become available for linearly released airdrops according to the specified schedule.

5. Answer Quiz: Complete a simple quiz to show your dedication to Hats Finance and its commitment to Decentralized Security in Web 3.0.
6. Choose Your Delegate: A delegate is an elected member of the Hats community who will vote on your behalf in governance votes. This means they represent your interests in decision-making and security for the Hats Finance ecosystem. You can either choose a listed delegate or list yourself as one.
7. Claim Now Or Deposit $HAT: You can now release your allocated $HAT tokens or deposit them in the $HAT vault to earn an attractive APY. Read more about your bug bounty farming mechanism [here](https://hatsfinance.medium.com/how-to-deposit-liquidity-on-bug-bounties-with-hats-finance-9db137293fba).

The bug bounty comes with attractive rewards for yield farming however, please note:

Depositing into a Hats Finance $HAT bug bounty vault involves a potential risk of fund lockup during claim processing, a 5% maximum risk of being part of the payout, and a 7-day withdrawal delay.

<br>


# MISCELLANEOUS


# Risk factors & Disclaimers

Interacting with Hats.finance platforms requires a certain level of understanding and risk tolerance. Users should perform their due diligence and fully comprehend the inherent risks before participating. ​&#x20;

**Smart Contract and Software Risks:** Despite meticulous examination and auditing of all Hats.finance smart contracts, including those for onboarded and upcoming vaults, the risk cannot be entirely mitigated. Security audits substantially reduce, but do not wholly eliminate, potential vulnerabilities. As a user, it's essential to commit only those funds that you can afford and are willing to risk. ​&#x20;

**Governance and $HAT Token Risks:** Hats governance does not control user funds directly. However, it does manage certain protocol parameters that can impact user rewards and fund availability. These parameters include the withdrawal request period, withdrawal period, and allocation points per vault.

For instance, governance could set an extended withdrawal request period, potentially delaying withdrawals for an indefinite time. It's crucial to understand these possibilities and their implications.

**Data Accuracy and Distribution Changes:** The data regarding Hats distribution presented on our website may not perfectly align with actual user distribution due to two primary reasons: a. Potential calculation errors in the website's front-end. b. The Hats governance DAO retains the power to adjust any token distribution.

**Transaction Disclaimers**&#x20;

The Protocol facilitates the deposit of specific blockchain-based cryptocurrencies, interaction with various Vaults, and implements a smart contract dictating the process for security professionals' rewards. The decision to join a Vault rests entirely with you. It's important to understand that neither Incentive Alignment Foundation nor Hats DAO commit to confirming the identity of any committee members, nor do they assume responsibility or liability for the actions or inactions of any other Protocol users. Note that transactions, such as deposits or withdrawals to or from Vaults, are irreversible and can't be 'canceled' or 'undone.' Therefore, Incentive Alignment Foundation and Hats DAO hold no responsibility for any transactions made in error. By using the Protocol or any Vault, or depositing cryptocurrencies or other digital assets, you acknowledge the associated risks and agree to abide by the rules embedded in the Protocol, as well as those set by the Hats DAO and Vault committee members. All such actions are undertaken at your own risk.&#x20;

The Protocol, Vaults, and blockchain networks are open-source, decentralized systems that may still be under active development. They might contain bugs, errors, and defects; experience periods of downtime or malfunction; lead to total or partial loss or corruption of cryptocurrencies deposited or data; and can be modified at any time, including through updates or newer versions, potentially without prior notice. Incentive Alignment Foundation and the Hats DAO disclaim any liability for any losses or damages you may incur due to these risks.&#x20;

When initiating a transaction, please be aware that there might be a delay before its execution, or potential malfunctions may arise. These issues could be due to inherent delays within the blockchain's underlying structure. Incentive Alignment Foundation and Hats DAO bear no responsibility or liability for such delays or malfunctions. Your interaction with the Protocol is solely at your discretion and risk.

**Security Professional Submission Risks:** Submissions made by security professionals in the context of skin-in-the-game audits, audit competitions, and bug bounties involve specific uncertainties. While we endeavor to provide fair and transparent processes for these submissions, several risk factors are worth noting:&#x20;

* **Evaluation of Submissions:** The determination of the validity and value of a submission is subjective and relies on the discretion of the evaluating panel. Although we strive for impartial and consistent evaluations, discrepancies in judgments could occur.&#x20;
* **Reward Payment:** Reward distribution is contingent on the availability of funds and the discretion of Hats.finance governance. There might be delays or changes in the payment method and structure.&#x20;
* **Ranking and Competition:** In competitive audit environments, there's the inherent risk that a security professional's submission may not be the first of its kind, rendering it ineligible for a reward despite its validity. Risk of Exposure: There's always a risk that a discovered vulnerability could be exploited if not promptly or adequately addressed. Hats.finance cannot be held responsible for any potential exploitation of these disclosed vulnerabilities.

As a security professional, it's essential to consider these risks before participation. Hats.finance cannot be held liable for any issues that may arise from a security professional's involvement in these activities.

**General Disclaimer:** At this stage, the crypto market is inherently volatile and subject to fluctuations which can impact the value of $HAT and or other associated tokens. Hats.finance does not guarantee profits and is not liable for any financial losses incurred while using the platform. Users should have a thorough understanding of cryptocurrency investment risks and seek independent financial advice if necessary.


# Glossary

**Arbitration Fee:** A refundable fee paid to initiate the arbitration process when there's a disagreement with the Committee's assessment.

**Arbitration Mechanism:** A system allowing security researchers to challenge the Committee's decisions on submissions, with a third-party arbitrator providing an impartial judgment.

**Audit Commencement:** The phase where security researchers submit their findings directly on-chain during an audit.

**Audit Competition Process:** Hats Finance's approach combining traditional audits with decentralized solutions.

**Audit Competition Promotion:** Campaigns launched in partnership with protocols to engage security researchers.

**Audit Competitions:** Events where security professionals compete to uncover vulnerabilities in smart contracts.

**Audit Request Initiation:** The starting point for protocols to engage Hats Finance's audit services.

**Audit Slot Reservation:** Protocols reserve their audit slot by depositing into a dedicated vault.

**Bug Bounties:** Programs that reward individuals for identifying and reporting system vulnerabilities.

**Challenge Period:** A designated timeframe for disputing and reviewing submitted claims.

**Code Update Audit:** A focused audit on new code or modifications, particularly useful for projects with previous audit participation.

**Committee's Preliminary Assessment:** The initial evaluation of a claim by the project's committee.

**Continued Engagement:** Post-audit phase where protocols may opt to keep their vault active for ongoing bug bounties.

**Decentralized Arbitration:** A system for resolving disputes in audit competitions and bug bounty submissions fairly.

**Dynamic Analysis:** Testing smart contracts through unit and integration tests to identify untested areas and potential vulnerabilities.

**Escalation Period for Additional Issues:** A period provided for submitting overlooked issues post-audit.

**Expert Committee:** A group appointed to review disputes and suggest new payouts for challenged claims.

**Hacker:** An individual identifying and reporting potential security vulnerabilities.

**Initial Claim Submission:** The first step in the arbitration process, involving the on-chain submission of findings.

**Kleros Court:** A decentralized service offering final judgment on escalated disputes.

**Liquidity Mining:** A process where users provide liquidity to a project's token pool and receive rewards, often in the project's native tokens.

**Manual Code Review:** A thorough examination of smart contract code by auditors.

**Post-Fix Review and Mainnet Launch Sign-Off:** The final review stage post-fixes, leading to mainnet deployment approval.

**Preliminary Assessment and Proposal:** An initial review by Hats Finance based on provided details, shaping the audit process.

**Public Competition with FCFS Mechanism:** An open audit competition where any auditor can participate and submit vulnerabilities.

**Review of Findings:** The process of evaluating findings during and at the end of an audit competition.

**Safety Period:** A timeframe before public disclosure of a vulnerability for committee review and resolution.

**Scope and Timeline Discussion:** Detailed discussions with the protocol team to define the audit's scope and timeline.

**Solo Auditor Engagement:** A model where individual auditors are given a base fee for auditing contracts and triaging submissions.

**Static Analysis:** Using automated tools to scan code for common errors and known vulnerabilities.

**Triage Competition:** A proposed feature to incentivize community assistance in submission quality control.

**Vault Committee:** A group responsible for governance and claims management within Hats Finance.

**Web3 Security Researchers:** Specialists in identifying and addressing vulnerabilities within blockchain and smart contract ecosystems.

**Whitehats:** Ethical hackers focused on securing systems and reporting vulnerabilities.


# Terms of use

These "Terms of Use" govern your interaction with the Hats Protocol, a decentralized protocol on the Ethereum blockchain. The Protocol aims to incentivize security professionals/auditors with funds sourced from various projects and their token holders. These Terms serve as a multiparty agreement between you and all other parties involved with the Protocol. This includes (i) code contributors, (ii) users (depositors of cryptocurrencies), (iii) vault committee members, and (iv) security professionals/auditors.

Be sure to read these terms thoroughly, especially all disclaimers and risk factors, before engaging with the Protocol. Your use of the Protocol signifies your irreversible consent to abide by these terms. If you disagree with any part of these terms, refrain from using the Protocol. Your ability to use the Protocol depends on your acceptance of all these terms, which will be evidenced by your use of the Protocol.

**Minors Prohibited**

If you are under the age of eighteen or under the legal age in your jurisdiction, you are not permitted to access or use the Protocol. Your use of the Protocol is an affirmation that you are of the required age.

**Arbitration**

Be aware that these terms, including an Agreement to Arbitrate, govern how any claims you might have in connection with the Protocol, its use, or these terms are resolved. This agreement will necessitate both parties to submit any claims to binding and final arbitration. As per the Agreement to Arbitrate, both parties can only (1) pursue claims individually, not as a plaintiff or class member in any collective action or proceeding, and (2) seek relief (like monetary, injunctive, or declaratory) on an individual basis.

**The Protocol**

1. The Protocol is a self-governing decentralized system on the Ethereum blockchain, designed to reward security professionals through funds gathered from projects and their token holders. As a decentralized blockchain protocol, the Protocol operates autonomously without any central authority or entity in control. The open-source code that forms the foundation of the Protocol is freely accessible at <https://github.com/hats-finance/hats-contracts>. Modifications to the software code and the Protocol's regulations can only be executed by the holders of a specific percentage of the Protocol's governance tokens, a threshold set within the Protocol's code. However, in case of a fork, alterations can be implemented by those instigating the fork.
2. While Incentive Alignment Ltd., a Cayman Islands Foundation ("IA"), was the creator of the original code for the Protocol, it no longer holds control over its operation once deployed on the Ethereum blockchain. Instead, the Protocol's governance is under the purview of the decentralized Hats DAO token. The Protocol's code may have been altered by other parties and might not reflect the original code released by IA. As an open-source, decentralized protocol subject to modifications by others at any time, IA disclaims all responsibility or liability, under any legal theory, for your use of the Protocol, which is done solely at your risk. It is your responsibility to verify the proper operation, performance, functionality, and security of the Protocol prior to use. You assume full risk and responsibility for your engagement with the Protocol and/or any Vault.
3. Vaults within the Protocol are overseen by independent committee members, who have no affiliation with IA and who operate independently from Hats DAO. Neither IA nor the Hats DAO bear any responsibility or liability for these committee members' actions or inactions. Your engagement with the Protocol and any Vault is undertaken solely at your own risk. It's recommended that you thoroughly examine the operation, functionality, and performance of each Vault, as well as its committee members, before depositing any crypto assets.

**License; No Warranties; Limitation of Liability**

1. The software that underpins the Protocol is provided under the terms of the MIT License, accessible here: <https://github.com/hats-finance/hats-contracts>.
2. The Protocol is given "AS IS," "WITH ALL FAULTS," and "AS AVAILABLE," without any express or implied assurances, including warranties of merchantability or fitness for a particular use, which are hereby disclaimed.
3. Neither the copyright holders nor contributors will be responsible for any direct, indirect, incidental, special, exemplary, or consequential damages. This includes, but is not limited to, replacement of goods or services; loss of use, data, or profits; or interruption of business activities, regardless of how they occur or the theory of liability, be it in contract, strict liability, or tort (including negligence or otherwise). This applies even if the possibility of such damage was previously advised, and results from the use of this software.

<br>

**Risk Disclaimers**\
\
By using the Protocol, you acknowledge the risks tied to cryptographic systems and affirm your understanding of cryptographic tokens, digital assets, blockchains, decentralized systems, and smart contracts. To ensure you understand all risks as well as the protocol’s disclaimers, thoroughly read and review the Risks and Disclaimers page of Hats Finance’s documents available at: <https://docs.hats.finance/miscellaneous/risk-factors-and-disclaimers>. &#x20;

Governing Law; Jurisdiction; Agreement to Arbitrate; No Class Action; Waiver of Right to Jury Trial

All claims or disputes relating to the Protocol or its use, or these Terms, will be interpreted and governed by the laws of the Cayman Islands. This applies without reference to its conflict-of-laws principles, and the United Nations Convention Relating to a Uniform Law on the International Sale of Goods may not be applied.

Every claim or dispute emerging from these terms, the Protocol, or its use, shall be conclusively settled under the Rules of Arbitration of the International Chamber of Commerce by one or more arbitrators designated following the said Rules. The arbitration will be conducted in English and held via teleconference or, if teleconference isn't feasible, in the Cayman Islands (the “Agreement to Arbitrate”).

You are required to bring all such claims or disputes individually, not as a plaintiff or member of any alleged class action, collective action, private attorney general action, or other representative proceeding. This provision is applicable to class arbitration.

By using the Protocol, you waive your right to a trial by jury.

Severability&#x20;

If a court of competent jurisdiction determines that any provision of these Terms is unenforceable, that provision will be reduced or removed to the minimal extent necessary. This ensures that these Terms remain fully effective, while staying as close as possible to the original intent.

<br>


# Cookies Policy

**We use in our site <https://hats.finance>  ("Site")** cookies and similar files or technologies to automatically collect and store information about your computer, device, and Site usage, in order to improve their performance and enhance your user experience. We use the general term "cookies" in this policy to refer to these technologies and all such similar technologies that collect information automatically when you are using our Site where this policy is posted.  You can find out more about cookies and how to control them in the information below. <br>

If you do not accept the use of these cookies, please disable them using the instructions in this cookie policy or by changing your browser settings so that cookies from this Site cannot be placed on your computer or mobile device. Important: disabling cookies on this Site may impair certain Site features.

In this Cookies Policy, we use the term Incentive (and "we", "us" and "our") to refer to Incentive Alignment Ltd. Our Privacy Policy is available at <https://docs.hats.finance/privacy-policy>.<br>

## **What is a cookie?** <br>

Cookies are computer files containing small amounts of information which are downloaded to your computer or mobile device when you visit a website.  Cookies can then be sent back to the originating website on each subsequent visit, or to another website that recognizes that cookie. Cookies are widely used in order to make websites work, or to work more efficiently, as well as to provide information to the owners of the website.&#x20;

Cookies do lots of different jobs, like letting you navigate between pages efficiently, remembering your preferences, and generally improving the user experience. Cookies may tell us, for example, whether you have visited our Site before or whether you are a new visitor.<br>

There are two broad categories of cookies:

* First party cookies, served directly by us to your computer or mobile device.
* Third party cookies, which are served by a third party on our behalf.  We use third party cookies for performance / analytics purposes. The third-party cookies are outside of our control. The third parties may, at any time, change their terms of service, purpose and use of cookies, etc. See below additional information on how to manage such cookies.

Cookies can remain on your computer or mobile device for different periods of time. Some cookies are 'session cookies', meaning that they exist only while your browser is open. These are deleted automatically once you close your browser. Other cookies are 'permanent cookies', meaning that they survive after your browser is closed. They can be used by websites to recognize your computer when you open your browser and browse the Internet again.

### **Web beacons:**<br>

Cookies are not the only way to recognize or track visitors to a website. We may use other, similar technologies from time to time, like web beacons (sometimes called "tracking pixels" or "clear gifs"). These are small graphics files that contain a unique identifier that enable us to recognize when someone has visited our website. This allows us, for example, to monitor the traffic patterns of users from one page within our website to another, to deliver or communicate with cookies, to understand whether you have come to our website from an online advertisement displayed on a third party website, to improve website performance and to measure the success of email marketing campaigns. In most instances, these technologies are reliant on cookies to function, and therefore declining cookies prevents them from functioning.<br>

You may have the right to decide whether to accept or reject cookies.  When you access our Site, you are presented with a cookie consent mechanism that allows you to accept or reject cookies that are not essential cookies.  You may also control cookies by setting your browser to turn off cookies as described further below. If you turn off cookies, web beacon and other technologies will still detect your visits to our Site; however, they will not be associated with information otherwise stored in cookies.<br>

### **Targeted advertising**

Third parties may drop cookies on your computer or mobile device to serve advertising through our website. These companies may use information about your visits to this and other websites in order to provide relevant advertisements about goods and services that you may be interested in. They may also employ technology that is used to measure the effectiveness of advertisements. The information collected through this process does not enable us or them to identify your name, contact details or other personally identifying details unless you choose to provide these to us.<br>

## **How do we use cookies?**

### **We use cookies to:**

* track traffic flow and patterns of travel in connection with our Site; &#x20;
* understand the total number of visitors to our Sites on an ongoing basis and the types of internet browsers (e.g. Chrome, Firefox, Safari, or Internet Explorer) and operating systems (e.g. Windows or Mac) used by our visitors;&#x20;
* monitor the performance of our Site and to continually improve it; and
* customize and enhance your online experience.

### **What types of cookies do we use?**

The types of cookies used by us in connection with the Site can be considered 'analytics and performance cookies'. We've set out some further information below, and the purposes of the cookies we set in the following table. <br>

### **Performance / Analytics Cookies**

We use performance/analytics cookies to analyze how the website is accessed, used, or is performing. We do this in order to provide you with a better user experience and to maintain, operate and continually improve the website. For example, these cookies allow us to:

* Better understand our website visitors so that we can improve how we present our content;
* Test different design ideas for particular pages, such as our homepage;
* Collect information about Site visitors such as where they are located and what browsers they are using;
* Determine the number of unique users of the website;
* Improve the website by measuring any errors that occur; and
* Conduct research and diagnostics to improve product offerings.&#x20;

| **Cookie name**             | **Source**                                                                                                       | **Expiry**     | **Purpose**                                                                                             |
| --------------------------- | ---------------------------------------------------------------------------------------------------------------- | -------------- | ------------------------------------------------------------------------------------------------------- |
| **\_ga**                    | **Google Analytics**                                                                                             | **2 years**    | **Registers a unique ID that is used to generate statistical data on how the visitor use the website**  |
| **\_gat**                   | **Google Analytics**                                                                                             | **1 Day**      | **Used by Google Analytics to throttle request rate**                                                   |
| **\_git**                   | **Google Analytics**                                                                                             | **1 Day**      | **Registers a unique ID that is used to generate statistical data on how the visitor uses the website** |
| **submitVulnerabilityDATA** | [**https://hats.fiance/static/js/2.b55b228.chunk.js**](https://rinkeby.hats.fiance/static/js/2.b55b228.chunk.js) | **Persistent** | **Persist disclosure state in local storage for better user experience.**                               |

## **How to control or delete cookies**

You may have the right to decide whether to accept or reject cookies. When you access our Site, you are presented with a cookie consent mechanism that allows you to accept or reject cookies that are not essential cookies. &#x20;

As another way of controlling cookies, most browsers allow you to change your cookie settings. These settings will typically be found in the “options” or “preferences” menu of your browser. In order to understand these settings and learn how to use them, please consult the “Help” function of your browser, or the documentation published online for your particular browser type and version.

However, please note that if you choose to refuse cookies you may not be able to use the full functionality of our Site.

The following pages have information on how to change your cookies settings for the different browsers:

* [Cookie settings in Chrome](https://support.google.com/chrome/answer/95647?hl=en\&ref_topic=14666) and [Chrome mobile](https://support.google.com/chrome/answer/95647?hl=en)&#x20;
* [Cookie settings in Firefox](https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer?redirectlocale=en-US\&redirectslug=Cookies) and [Firefox mobile](https://support.mozilla.org/en-US/kb/clearing-cookies-private-data-history-and-settings)&#x20;
* [Cookie settings in Internet Explorer](http://windows.microsoft.com/en-GB/internet-explorer/delete-manage-cookies#ie=ie-10) and [Microsoft Edge](https://support.microsoft.com/en-gb/help/4027947/microsoft-edge-delete-cookies)
* [Cookie settings in Safari](https://support.apple.com/kb/PH5042?locale=en_US) and [Safari mobile](https://support.apple.com/en-gb/HT201265)
* [Cookie settings in iOS](https://support.apple.com/en-gb/HT201265)
* [Cookie settings in Opera](https://www.opera.com/help/tutorials/security/privacy/)
* [Cookie settings in Apple Safari](https://support.apple.com/en-gb/safari)

If you use another browser, you can check if the procedure for your browser is mentioned in [this explanatory website](http://www.allaboutcookies.org/manage-cookies).

To opt out of being tracked by Google Analytics across all websites, visit [**here**](http://tools.google.com/dlpage/gaoptout)**.**<br>

### **Third Party Websites' Cookies**&#x20;

When using our website, you may be directed to other websites for such activities as surveys, to make payment in currency other than U.S. dollars, or for job applications. These websites may use their own cookies. We do not have control over the placement of cookies by other websites you visit, even if you are directed to them from our website.

If you use the buttons that allow you to share products and content with your friends via social networks like Google, Twitter and Facebook, these companies may set a cookie on your computer memory. Find out more about these here:

[**https://www.facebook.com/about/privacy**<br>](https://www.facebook.com/about/privacy/)[**http://twitter.com/privacy**<br>](http://twitter.com/privacy)[**http://www.google.com/intl/en-GB/policies/privacy**](http://www.google.com/intl/en-GB/policies/privacy/)

### **Need More Information?**

If you would like to find out more about cookies and their use on the Internet, you may find the following link useful:

* [**All About Cookies**](http://www.allaboutcookies.org/)

### **Cookies that have been set in the past**

If you have disabled one or more Cookies, we may still use information collected from cookies prior to your disabled preference being set, however, we will stop using the disabled cookie to collect any further information.&#x20;

### **Contact us**

If you have any questions or comments about this cookies policy, or privacy matters generally, please contact us via email at **<privacy@hats.finance>**\ <br>


# Privacy Policy

**HATS.FINANCE PRIVACY POLICY**

*Last Updated: August 30, 2021*

This privacy policy (“**Privacy Policy**”) governs how we, Incentive Alignment Ltd. (together, “**Hats Finance**” “**we**”, “**our**” or “**us**”) use, collect and store Personal Data we collect or receive from or about you (“**you**”) such as in the use cases mentioned in section 1.

Please read this Privacy Policy carefully, so you can understand our practices and your rights in relation to personal data. “**Personal Data**” or “**Personal Information**” means any information that can be used, alone or together with other data, to uniquely identify any living human being and any information deemed as Personally Identifiable Information by privacy laws. **Important note**: Nothing in this Privacy Policy is intended to limit in any way your statutory right, including your rights to a remedy or means of enforcement. **SOME OF YOUR DATA WILL BE STORED ON A BLOCKCHAIN-BASED NETWORK (ETHEREUM BLOCKCHAIN)** **AND, THEREFORE, WILL BE ACCESSIBLE TO ANYONE. IF YOU DISAGREE WITH THIS, PLEASE DO NOT USE OUR PRODUCTS AND SERVICES.**

**Table of contents**:

1. What information we collect, why we collect it, and how it is used
2. How we protect and retain your Personal Data
3. How we share your Personal Data
4. Your privacy rights
5. Use by children
6. Interaction with third party products
7. Log files
8. Analytic tools
9. Specific provisions applicable under California privacy law
10. Contact us

This Privacy Policy can be updated from time to time and, therefore, we ask you to check back periodically for the latest version of this Privacy Policy.  If we implement significant changes to the use of your Personal Data in a manner different from that stated at the time of collection, we will notify you by posting a notice on our Website or by other means.

1. **WHAT INFORMATION WE COLLECT, WHY WE COLLECT IT, AND HOW IT IS USED**
2. **We Process the following Personal Information:**
3. **Information You Provide Directly to Us.** We collect Personal Data you provide directly to us, including Personal Data when you browse and make use of our website <https://hats.finance/> (“**Website**”) and/or our application [Https://app.hats.finance](https://app.hats.finance/) (“**Application**”), including, full name, email address, and other information that you decide to share with us. When you communicate with Hats Finance (via email, website or telephone), we collect the contents of those communications, as well as feedback, and/or answers to surveys or questionnaires that you may submit.
4. **Information provided in the context of Hats Finance** **Application:** Hats Finance may receive information in the context of providing its services to you.&#x20;
   1. When you are a member of a committee in our Application (“**Committee**”), we collect your full name,, twitter user, public key, telegram user, picture and other information that you make available to us.
   2. When you are a governance member, depositors and/or investors, we collect your full name, email address, phone number, log-in details picture and other information that you make available to us
   3. When you are a white hacker, we collect your wallet information, transaction information, Telegram user details and any other information that you decide to send us.

For the avoidance of doubt, the Telegram user details and any messages (vulnerabilities found) that you decide to provide the committee is encrypted and only the relevant Telegram committee can access and decrypt such messages.

1. **Information from Other Sources.**  Hats Finance may also obtain information (that in general will not contain Personal Data) about you from other sources, including private and publicly - or commercially - available information, and through third-party partners and service providers.&#x20;
2. **Automatic Data Collection.** We may automatically collect certain information through your use of the Hats Finance Website and Application, such as cookie identifiers and other device identifiers, analytic tools and log files that are automatically assigned to your device, browser type and language, geo-location information, hardware type, operating system, internet service provider and other information about actions taken through the use of the Hats Finance services.
3. **We Process Personal Information for the following purposes:**
4. **To provide you with the Hats Finance** **Application**. Hats Finance will use your information to provide the Hats Finance Application, including: (i) to process your vulnerability submission; (ii) to share your message and vulnerability submission with the relevant Committee; (iii) to communicate with you about the vulnerability request in case that the Committee has any question; (iv) track the vulnerability request sent by you; (vi) to allow you to connect your wallet; (v) to create and publish the relevant information of the Committee members; (vii) to create and publish the relevant information of the governance members; (viii) to provide you with a user friendly interface to Hats smart contracts; (ix) to provide you with information about our Application and its capabilities; and (x) to personalize your experience with the Hats Finance Application.
5. **For** **Administrative Purposes**. Hats Finance may use your information (i) to respond to your questions, comments, and other requests for support, or information; (ii) to provide you with the Hats Finance Application and services; (iii) for internal quality control purposes; (iv) to establish a business relationship; (v) for testing, research, analysis, and product development, including to develop and improve our Website and Application, and in connection with providing and maintaining our products, and services; and (vi) to generally administer the Hats Finance Website and Application.
6. **To Market the Hats Finance Application.** Hats Finance may use information to market the Hats Finance Website and Application. Such use includes (i) notifying you about offers and services that may be of interest to you that we offer and/or that we offer jointly with or on behalf of other organizations; (ii) tailoring content, advertisements, and offers for you, including, targeting and re-targeting practices; (iii) conducting market research; (iv) developing and marketing new products and services, and to measure interest in Hats Finance’s services; (v) other purposes disclosed at the time you provide Personal Information; and (vi) as you otherwise consent.&#x20;
7. **Security purposes**. Some of the abovementioned information will be used for detecting, taking steps to prevent, and prosecution of fraud or other illegal activity, to identify and repair errors, to conduct audits, and for security purposes. Personal Data may also be used to comply with applicable laws, with investigations performed by the relevant authorities, law enforcement purposes, and/or to exercise or defend legal claims.
8. **De-identified and Aggregated Information Use**. In certain cases, we may or will anonymize or de-identify your Personal Data and further use it for internal and external purposes, including, without limitation, to improve the services and for research purposes. “**Anonymous Information**” means information which does not enable identification of an individual user, such as aggregated information about the use of our services. We may use Anonymous Information and/or disclose it to third parties without restrictions (for example, in order to improve our services and enhance your experience with them).
9. **Cookies and Similar Technologies**. We, as well as third parties that provide content, advertising, or other functionality on the Hats Finance Website, may use cookies, pixel tags, local storage, and other technologies (“**Technologies**”) to automatically collect information through the Hats Finance Website. We use Technologies that are essentially small data files placed on your device that allow us to record certain pieces of information whenever you visit or interact with the Hats Finance Website. If you would like to opt out of the Technologies we employ on the Hats Finance Application, you may do so by blocking, deleting, or disabling them as your browser or device permits.

Finally, please note that some of the abovementioned Personal Data will be used for detecting, taking steps to prevent, and prosecution of fraud or other illegal activity, to identify and repair errors, to conduct audits, and for security purposes. Personal Data may also be used to comply with applicable laws, with investigations performed by the relevant authorities, law enforcement purposes, and/or to exercise or defend legal claims. In certain cases, we may or will anonymize or de-identify your Personal Data and further use it for internal and external purposes, including, without limitation, to improve the services and for research purposes. “Anonymous Information” means information which does not enable identification of an individual user, such as aggregated information about the use of our services. We may use Anonymous Information and/or disclose it to third parties without restrictions (for example, in order to improve our services and enhance your experience with them).

1. **HOW WE PROTECT AND RETAIN YOUR INFORMATION**
   1. **Data stored by** Hats Financ&#x65;**:** The data stored by Hats Finance will, in order to ensure the functioning of the services and Website.
   2. Security. We have implemented appropriate technical, organizational and security measures designed to protect your Personal Data. However, please note that we cannot guarantee that the information will not be compromised as a result of unauthorized penetration to our servers. As the security of information depends in part on the security of the computer, device or network you use to communicate with us and the security you use to protect your user IDs and passwords, please make sure to take appropriate measures to protect this information.
   3. Retention of your Personal Data. Your information will be stored until we delete the record and we proactively delete it or you send a valid deletion request. Please note that in some circumstances we may store your Personal Data for longer periods of time, for example (i) where we are required to do so in accordance with legal, regulatory, tax or accounting requirements, or (ii) for us to have an accurate record of your dealings with us in the event of any complaints or challenges, or (iii) if we reasonably believe there is a prospect of litigation relating to your Personal Data or dealings. Regarding retention of cookies, you can read more in our cookie policy.
   4. **Data stored on the blockchain:** The data stored on the Ethereum Blockchain will be stored perpetually, without any way for deletion, Ethereum network which is a decentralized and open-source network. Please note that, given the nature of the blockchain, the effectiveness of the security measures depends on the efforts of a decentralized network of miners, validator nodes and proof-of-stake participants, among other participants in the Ethereum Network. In any event, as an additional precaution, we have followed a data minimization approach to ensure that little personal data is processed (as further described in Section 1 above). Therefore, in the event of a data breach or security incident, such incident is unlikely to result in a risk to your rights and freedoms because the amount and nature of the personal data potentially compromised is not sensitive and is unlikely to reveal any private aspect or cause you any damage.
   5. IF YOU DISAGREE WITH THIS SECTION 2, PLEASE DO NOT USE OUR SERVICES AND WEBSITE.
2. &#x20;**HOW WE SHARE YOUR PERSONAL DATA**

In addition to the recipients described above, we may share your Personal Data as follows:

* 1. **Data stored by Hats Finance:**
  2. With our business partners with whom we jointly offer products or services. We may also share Personal Data with our affiliated companies.
  3. We may use third party service providers to process your Personal Data for the purposes outlined above, including, without limitation:
     1. With cloud service providers for hosting purposes;
     2. With word press service providers in order to help us manage our Website and Application;
     3. With email providers, marketing, CRM and other similar tool providers; and
     4. With analytic companies, in order to help us understand and analyze data we collect in accordance with this policy.
     5. \[*Shay – please add more categories that may be missing*]
  4. To the extent necessary, with regulators, courts or competent authorities, to comply with applicable laws, regulations and rules (including, without limitation, federal, state or local laws), and requests of law enforcement, regulatory and other governmental agencies or if required to do so by court order;
  5. If, in the future, we sell or transfer, or we consider selling or transferring, some or all of our business, shares or assets to a third party, we will disclose your Personal Data to such third party (whether actual or potential) in connection with the foregoing events;
  6. In the event that we are acquired by, or merged with, a third party entity, or in the event of bankruptcy or a comparable event, we reserve the right to transfer, disclose or assign your Personal Data in connection with the foregoing events, including, in connection with, or during negotiations of, any merger, sale of company assets, consolidation or restructuring, financing, or acquisition of all or a portion of our business by or to another company; and/or
  7. Where you have provided your consent to us sharing or transferring your Personal Data (e.g., where you provide us with marketing consents or opt-in to optional additional services or functionality).
  8. **Data stored on the blockchain:** The information stored on the Ethereum Blockchain Network will be shared with anyone accessing the Ethereum Blockchain Network, since the Ethereum Blockchain Network is a decentralized and public protocol, which could include parties that are located outside from your country or jurisdiction. Please note these parties may be located in countries and jurisdictions that do not approach or protect your privacy rights as in your jurisdiction. In any event, please note that sharing data with such parties is necessary for providing the services at hand. Moreover, please note that given the implementation of our data minimization approach, the only information that will be shared is described in Section 1.
  9. IF YOU DISAGREE WITH THIS SECTION 3, PLEASE DO NOT USE OUR APP.

1. **YOUR PRIVACY RIGHTS. HOW TO DELETE YOUR ACCOUNT**
   1. **Data stored by Hats Finance**: Rights: The following rights (which may be subject to certain exemptions or derogations) shall apply to certain individuals (some of which only apply to individuals protected by specific laws):

* You have a right to access Personal Data held about you. Your right of access may normally be exercised free of charge, however we reserve the right to charge an appropriate administrative fee where permitted by applicable law;
* You have the right to request that we rectify any Personal Data we hold that is inaccurate or misleading;
* You have the right to request the erasure/deletion of your Personal Data (e.g. from our records). Please note that there may be circumstances in which we are required to retain your Personal Data, for example for the establishment, exercise or defense of legal claims;
* You have the right to object, to or to request restriction, of the processing;
* You have the right to data portability. This means that you may have the right to receive your Personal Data in a structured, commonly used and machine-readable format, and that you have the right to transmit that data to another controller;
* You have the right to object to profiling;
* You have the right to withdraw your consent at any time. Please note that there may be circumstances in which we are entitled to continue processing your data, in particular if the processing is required to meet our legal and regulatory obligations. Also, please note that the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal;
* You also have a right to request certain details of the basis on which your Personal Data is transferred, but data transfer agreements and/or other details may need to be partially redacted for reasons of commercial confidentiality;
* You have a right to lodge a complaint with your local data protection supervisory authority (i.e., your place of habitual residence, place or work or place of alleged infringement) at any time or before the relevant institutions in your place of residence. We ask that you please attempt to resolve any issues with us before you contact your local supervisory authority and/or relevant institution.
  1. You can exercise your rights by contacting us at <privacy@hats.finance>. You may use an authorized agent to submit a request on your behalf if you provide the authorized agent written permission signed by you. To protect your privacy, we may take steps to verify your identity before fulfilling your request. Subject to legal and other permissible considerations, we will make every reasonable effort to honor your request promptly in accordance with applicable law or inform you if we require further information in order to fulfil your request. When processing your request, we may ask you for additional information to confirm or verify your identity and for security purposes, before processing and/or honoring your request. We reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive. In the event that your request would adversely affect the rights and freedoms of others (for example, would impact the duty of confidentiality we owe to others) or if we are legally entitled to deal with your request in a different way than initial requested, we will address your request to the maximum extent possible, all in accordance with applicable law.
  2. **Data stored on the blockchain: IMPORTANT NOTE**: SOME OF THE ABOVEMENTIONED RIGHTS CANNOT BE HONORED IN CONNECTION WITH THE DATA STORED ON THE BLOCKCHAIN. GIVEN THE NATURE OF THE BLOCKCHAIN, THE DATA IDENTIFIED IN THE TABLE IN SECTION 1 AS “STORED ON THE BLOCKCHAIN” WILL REMAIN STORED ON THE ETHEREUMBLOCKCHAIN NETWORK AND WILL REMAIN ACCESSIBLE TO ANYONE.
  3. IF YOU DISAGREE WITH THIS SECTION 4, PLEASE DO NOT USE OUR APP. We and our services do not perform any processing activity for the purposes of making automated decisions or profile you in any manner.

1. **USE BY CHILDREN.** We do not offer our products or services for use by children and, therefore, we do not knowingly collect Personal Data from, and/or about children under the age of eighteen (18). If you are under the age of eighteen (18), do not provide any Personal Data to us without involvement of a parent or a guardian. We do not intend to *offer information society* services *directly to children*. In the event that we become aware that you provide Personal Data in violation of applicable privacy laws, we reserve the right to delete it. If you believe that we might have any such information, please contact us at <privacy@hats.finance>.
2. **INTERACTION WITH THIRD PARTY PRODUCTS.** We enable you to interact with third party websites, mobile software applications and products or services that are not owned or controlled by us (each a “**Third Party Service**”). We are not responsible for the privacy practices or the content of such Third Party Services. Please be aware that Third Party Services can collect Personal Data from you. Accordingly, we encourage you to read the terms and conditions and privacy policies of each Third Party Service.
3. **LOG FILES.** We use log files. We use such information to analyze trends, administer the Website, track users’ movement around the Website, and gather demographic information.
4. **ANALYTIC TOOLS**

* **Google Analytics**. The Website uses a tool called “**Google Analytics**” to collect information about use of the Website. Google Analytics collects information such as how often users visit this Website, what pages they visit when they do so, and what other websites they used prior to coming to this Website. We use the information we get from Google Analytics to maintain and improve the Website and our products. We do not combine the information collected through the use of Google Analytics with Personal Information we collect. Google’s ability to use and share information collected by Google Analytics about your visits to this Website is restricted by the Google Analytics Terms of Service, available at <https://marketingplatform.google.com/about/analytics/terms/us/>, and the Google Privacy Policy, available at <http://www.google.com/policies/privacy/>. You may learn more about how Google collects and processes data specifically in connection with Google Analytics at <http://www.google.com/policies/privacy/partners/>. You may prevent your data from being used by Google Analytics by downloading and installing the Google Analytics Opt-out Browser Add-on, available at <https://tools.google.com/dlpage/gaoptout/>.

We reserve the right to remove or add new analytic tools.

1. **CONTACT US.** If you have any questions, concerns or complaints regarding our compliance with this notice and the data protection laws, or if you wish to exercise your rights, we encourage you to first contact us at <privacy@hats.finance>.


# Curator Terms & Conditions

### 1. Introduction <a href="#id-1.-introduction" id="id-1.-introduction"></a>

This T\&C governs the role and responsibilities of curators within the Hats Finance ecosystem, a decentralized autonomous organization (DAO) governed by the community. Hats Finance DAO is supported by the Incentive Alignment Foundation, a Cayman Islands Foundation, which manages all legal matters on behalf of the DAO. By becoming a curator, you agree to these conditions and to uphold the integrity of the platform. Failure to comply may result in the termination of your role as a curator and potential legal consequences.

### 2. Curator Tiers and Responsibilities <a href="#id-2.-curator-tiers-and-responsibilities" id="id-2.-curator-tiers-and-responsibilities"></a>

Hats Finance curators are divided into three tiers, each with increasing levels of responsibility and rewards:

#### Tier 1: Growth Seeker 🕵️ <a href="#tier-1-growth-seeker" id="tier-1-growth-seeker"></a>

Focus: Identifying and engaging potential clients for audit competitions.

**Responsibilities:**

* Create and manage groups with leads on platforms like Telegram or Discord.
* Personally organize the first meeting between the Hats Finance team and potential clients. Meetings with potential clients are valid to earn rewards if no meeting has occurred between them and Hats Finance in the last six months.
* Participation in client meetings is optional but encouraged.

**Rewards:**

* Earn 10% of the Hats Finance fee from competitions you initiate, contingent upon successful competition completion.

**Requirements:**

* Open to proactive individuals with basic Business Development skills and a talent for networking.
* Integrity and good communication skills are also essential in terms of representing Hats Finance.

***

#### Tier 2: Growth Genius 🧞 <a href="#tier-2-growth-genius" id="tier-2-growth-genius"></a>

Focus: Begin by covering Tier 1 and ensuring smooth progression of competitions from conception to deployment.

**Responsibilities:**

* Open vaults with clients and ensure the secure deposit of funds.
* Guide projects through all pre-competition phases, coordinating with the Hats security team.
* Maintain high-quality standards for vaults, audit scopes, and reward structures.

**Rewards:**

* Earn 15% (10% from tier 1 + 5% on tier 2) of the Hats Finance fee from competitions you manage, based on the successful deployment of the competition.

**Requirements:**

* Strong understanding of Business Development and Technology, with the ability to manage complex projects and client relationships.
* Integrity and good communication skills are also essential in terms of representing Hats Finance.

***

#### Tier 3: Growth Wizard 🧙 <a href="#tier-3-growth-wizard" id="tier-3-growth-wizard"></a>

Focus: Begin by covering Tier 1 and 2 along with end-to-end management of competitions, including promotion and dispute resolution.

**Responsibilities:**

* Promote the competition to attract participants.
* Oversee operations and timelines, ensuring smooth execution.
* Resolve any disputes that arise during the competition.

**Rewards:**

* Earn up to 50% (15% on Tier 1 & 2 + up to 35% for Tier 3) of the Hats Finance fee from the competition’s payout, contingent upon successful completion. The reward starts at 15% and increases based on additional responsibilities.

**Requirements:**

* Experience in audit firms or as a solo auditor, with extensive knowledge of the Hats competition model and strong leadership skills.
* Integrity and good communication skills are also essential in terms of representing Hats Finance.

***

### 3. Eligibility Requirements <a href="#id-3.-eligibility-requirements" id="id-3.-eligibility-requirements"></a>

To become a curator, you must:

* Have proven experience in blockchain or cybersecurity.
* Be actively engaged with the Hats Finance platform.
* Agree to Hats Finance’s ethical guidelines.

### 4. Confidentiality <a href="#id-4.-confidentiality" id="id-4.-confidentiality"></a>

Curators must maintain strict confidentiality regarding all projects under audit. Breaches may result in legal action and immediate removal from the program.

### 5. Conflict of Interest <a href="#id-5.-conflict-of-interest" id="id-5.-conflict-of-interest"></a>

Curators must act in the best interest of the Hats Finance ecosystem and disclose any potential conflicts of interest. Any misuse of information for personal or financial gain is strictly prohibited.

### 6. Disciplinary Actions <a href="#id-6.-disciplinary-actions" id="id-6.-disciplinary-actions"></a>

Non-compliance with these T\&C may lead to:

* Suspension or revocation of curator status.
* Loss of compensation or rewards.
* Legal action, where applicable.

### 7. Compensation and Fees <a href="#id-7.-compensation-and-fees" id="id-7.-compensation-and-fees"></a>

Curators will be compensated based on the Hats Finance fee structure and up to 50% according to the tier and responsibilities. Compensation is tied to the successful completion and payout of the competitions they oversee.

### 8. Amendments to the T\&C <a href="#id-8.-amendments-to-the-t-and-c" id="id-8.-amendments-to-the-t-and-c"></a>

Hats Finance reserves the right to amend these T\&C. Curators will be notified of significant changes, and continued involvement will imply acceptance of the updated terms. Curators have the right to terminate their role if they do not agree with substantial changes.

### 9. Legal Compliance <a href="#id-9.-legal-compliance" id="id-9.-legal-compliance"></a>

Curators must comply with all relevant laws, including data protection, financial regulations, and cybersecurity laws. Hats Finance operates as a decentralized autonomous organization (DAO) supported by the Incentive Alignment Foundation (Cayman Islands Foundation) to handle legal and jurisdictional matters. All disputes or legal claims relating to Hats Finance are subject to the laws of the Cayman Islands, and the Foundation shall represent Hats Finance in all such matters.

Hats Finance reserves the right to amend these T\&C at any time. Curators will be notified of changes, and continued involvement will imply acceptance of the updated terms. Curators have the right to terminate their role if they do not agree with substantial changes.

### 10. Legal Compliance and Jurisdiction <a href="#id-10.-legal-compliance-and-jurisdiction" id="id-10.-legal-compliance-and-jurisdiction"></a>

Curators must comply with all relevant laws, including data protection, financial regulations, and cybersecurity laws. These T\&C shall be governed by and construed in accordance with the laws of the Cayman Islands.

### 11. Termination of Curator Role <a href="#id-11.-termination-of-curator-role" id="id-11.-termination-of-curator-role"></a>

Hats Finance reserves the right to terminate your role as a curator with or without cause, effective immediately. Curators may also voluntarily terminate their role by providing 30 days written notice to the Hats Finance governance committee. Upon termination, all confidentiality and non-disclosure obligations remain in effect.

### 12. Dispute Resolution <a href="#id-12.-dispute-resolution" id="id-12.-dispute-resolution"></a>

Disputes arising under these T\&C will be resolved according to the Hats Finance governance processes. You can open one on Hats Discord under the Curator program channel.

### 13. Independent Contractor Status <a href="#id-13.-independent-contractor-status" id="id-13.-independent-contractor-status"></a>

Curators are considered independent contractors and not employees of Hats Finance. They are responsible for their own taxes, insurance, and any other legal obligations related to their curator activities.

### 14. Representation and Warranties <a href="#id-14.-representation-and-warranties" id="id-14.-representation-and-warranties"></a>

Curators represent and warrant that they have the necessary skills, experience, and qualifications to perform their role effectively and that all information provided to Hats Finance is accurate and complete.

### 15. Severability <a href="#id-15.-severability" id="id-15.-severability"></a>

If any provision of these T\&C is found to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

### 16. Foundation Representation Disclaimer <a href="#id-16.-foundation-representation-disclaimer" id="id-16.-foundation-representation-disclaimer"></a>

Hats Finance DAO is supported by the Incentive Alignment Foundation, which acts as the legal representative for all official matters. While the DAO governs the platform through decentralized mechanisms, the Foundation manages all legal, regulatory, and compliance matters on behalf of the DAO. This ensures that all curators, users, and participants adhere to applicable laws while engaging with Hats Finance.

**By accepting the role of curator, you acknowledge that you have read, understood, and agree to be bound by these Terms and Conditions.**


# Hats contracts

| Contract name | Link                                                                                   | Modification |
| ------------- | -------------------------------------------------------------------------------------- | ------------ |
| **HATVaults** | <p>\<a href="<https://etherscan.io/address/0x571f39d351513146248AcafA9D0509319A327C4D> |              |

"><https://etherscan.io/address/0x571f39d351513146248AcafA9D0509319A327C4D> <br> <br></a></p> | Immutable                                                                         |
\| **HATToken**              | <https://etherscan.io/address/0x685D939C8FE6CCe02f3C7Cbc37d024E99570812c>                                 | Immutable                                                                         |
\| **TokenLockFactory**      | <p>\<a href="<https://etherscan.io/address/0x2c7dAec5B1C6157C2b37B2505d5D57d6D075E39E>

"><https://etherscan.io/address/0x2c7dAec5B1C6157C2b37B2505d5D57d6D075E39E> <br> </a></p>     | Upgradable by Hats governance                                                     |
\| **HATTimelockController** | <p><a href="https://etherscan.io/address/0xFd4255F16378306CA83E37015Df01a1700DAc296"><https://etherscan.io/address/0xFd4255F16378306CA83E37015Df01a1700DAc296></a><br></p>           | <p>Immutable<br><br>Owners can be changed with the default timelock (3 weeks)</p> |

**Oracles**\
Hats protocol does not rely on oracles. Vault token value are displayed for better UX only.

**Front run attacks mitigation**\
Hats deposits have a withdrawal request period (currently set to 7 days) which prevent the depositors from front running the bounty payout function call. In addition to that the pendingApprovalClaim function that pauses the withdrawals in order to pay a bounty can be called only in a safety period(1 hour twice a day) a period where withdrawals are disabled. So even a depositor that have an active withdrawal request cant frontrun the bounty payout.&#x20;

**Timelock**\
Timelocks are handled by HATTimelockController contract that is based on openzeppelin-solidity/contracts/governance/TimelockController.sol default timeout is set to 3 weeks.\
\
**Flashloans**\
Hats functions are not susceptible to flashloans. Hats vaults swapBurnSend function can only be called by governance therefore it is not susceptible to price manipulation attack.

**Pause controls**\
Hats contracts don't have pause controls. Hats vaults withdrawals cannot be stoped only deposits can be paused by Hats governance.


# FAQ

### **Where can I find the contract?**

You can find it underneath the reward breakdown "view contracts covered."

### **Where is the readme file?**

Please check this link: GitHub

### **How should I submit my report?**

Please watch this video to learn all about the submission process.

### **How can I recheck my submission?**

The report is encrypted with the committee PGP key. You will be asked to download and save the encryption version to your local machine during submission.


# TERMS OF SALE OF NFTs

Last updated on February 7, 2022

THESE TERMS AND CONDITIONS CONSTITUTE A LEGALLY BINDING AGREEMENT (“**AGREEMENT**”) BETWEEN YOU (“**YOU**”, “**YOUR**” OR “**USER**”) AND INCENTIVE ALIGNMENT FOUNDATION (“**WE**”, “**US**” OR THE "**FOUNDATION**"), GOVERNING YOUR PURCHASE OF NFTS (AS DEFINED BELOW) FROM OUR WEBSITE (THE “**OFFERING**”). BY REDEEMING, PURCHASING NFT'S FROM THE FOUNDATION'S WEBSITE, DAPP, SMART CONTRACT, ANY OTHER PLATFORM OR OTHERWISE PARTICIPATING IN THE OFFERING, YOU AGREE TO BE BOUND BY THIS AGREEMENT AND ALL OTHER TERMS INCORPORATED HEREIN BY REFERENCE. IF YOU DO NOT AGREE TO THIS AGREEMENT, YOU MAY NOT PURCHASE ANY NFT FROM OUR WEBSITE.

### 1.DEFINITIONS

“**Art**” means any art, graphics, images, designs, logos, taglines, and drawings that may be associated with an NFT in which you acquire Licensed Rights.

“**Name and Likeness**” means name, nicknames, images, likenesses, marks, copyrights, trade dress colors, trade dress designs, and/or all other intellectual property of the Foundation.

“**NFT**” means any blockchain-based, non-fungible token.

“**Licensed Rights**” with respect to an NFT means your rights to use the Art associated with an NFT of which you are the current rightful holder, where proof of such purchase is recorded on the relevant blockchain.

“**Third Party IP**” means any third-party patent rights (including, without limitation, patent applications and disclosures), copyrights, trade secrets, trademarks, know-how or any other intellectual property rights recognized in any country or jurisdiction in the world.

### 2.OWNERSHIP

1. You acknowledge and agree that the foundation (or, as applicable, its licensors) owns all legal right, title and interest in and to the Art and Name and Likeness, and all intellectual property rights therein. The rights that You have in and to the NFT and Art are limited to those expressly stated in Section 3 of this Agreement. The Foundation and its licensors reserve all rights and ownership in and to the NFT, Name and Likeness, and Art not expressly granted to You in Section 3 of this Agreement.
2. All purchases of NFTs, as well as associated charges, are non-refundable. This no-refund policy shall apply at all times regardless of Your decision to terminate usage of the NFT, any disruption to the operations of any components of the NFT, or any other reason whatsoever.

### 3.GRANT OF LICENSE

1. **License.** You acknowledge and agree that the Art associated with an NFT of which you are holder is made available solely for your own personal use. Without limiting the foregoing and subject to your continued compliance with this Agreement, the Foundation grants you a worldwide, non-exclusive, non-transferable (except as specifically provided below in Section 3.2), license to display the Art associated with your NFTs, solely for your own personal, non-commercial use.
2. **Transfers of Your NFT.** The Licensed Rights will apply to the person or entity who at the applicable time is the rightful holder of the applicable NFT, with respect to the Art associated with such NFT.

### 4.RESTRICTIONS

1. You agree that you may not, nor permit any third party to do or attempt to do any of the following without express prior written consent from the Foundation in each case: (i) modify the NFT, and/or Art for your NFT in any way, including, without limitation, the shapes, designs, drawings, attributes, or color schemes, the specific characters or other assets, clothing, accessories and expressions in the Art; (ii) use the NFT, and/or Art for your NFTs to advertise, market, or sell any product or service; (iii) use the NFT, and/or Art from your NFTs in connection with images, videos, or other forms of media that depict hatred, intolerance, violence, cruelty, or anything else that could reasonably be found to constitute hate speech or otherwise infringe upon the rights of others, drugs (including, without limitation, both prescription and non-prescription) or other supplements, death, pornography or other “adult only” or sexually explicit activities, massage parlors, prostitution or any dating or escort activities, weapons or ammunition, denigration or discrimination against individuals based on race, national origin, gender, religion, disability, ethnicity, sexual orientation, gender identity or age, medical conditions and/or political campaigns or causes; (iv) use the NFT and/or Art from Your NFTs in movies, videos, or any other forms of media, except solely for Your own personal, non-commercial use; (v) sell, distribute for commercial gain (including, without limitation, giving away in the hopes of eventual commercial gain), or otherwise commercialize merchandise that includes, contains, or consists of the NFT, and/or Art from Your NFTs; (vi) attempt to trademark, copyright, or otherwise acquire additional intellectual property rights in or to the NFT and/or Art from Your NFTs; or (vii) otherwise utilize the Art from your NFTs for Your or any third party’s commercial benefit.
2. To the extent that the NFT, Name and Likeness and/or Art associated with Your NFTs contains Third Party IP, You understand and agree as follows: (i) that You will not have the right to use such Third Party IP in any way except as incorporated in the Art, and subject to the license and restrictions contained herein; (ii) that, depending on the nature of the license granted from the owner of the Third Party IP, the Foundation may need to pass through additional terms and/or restrictions on Your ability to use the Art; and (iv) to the extent that the Foundation informs You of such additional restrictions in writing (email is permissible), You will be responsible for complying with all such restrictions from the date that You receive the notice, and that failure to do so will be deemed a breach of this Agreement.
3. The restrictions in this Section 4 will survive the expiration or termination of this Agreement.

### 5.TERMINATION

1. The Licensed Rights granted to You hereunder shall automatically terminate and all rights shall return to the Foundation if: (i) at any time You sell, trade, donate, give away, transfer, or otherwise dispose of Your NFT for any reason; (ii) You breach any of the Agreement and conditions; (iii) You have a trustee, receiver or similar party appointed for Your property, become insolvent, acknowledge Your insolvency in any manner, make an assignment for the benefit of your creditors, or file a petition of bankruptcy; (iv) You engage in any unlawful business practice related to the NFT; (iv) You initiate any legal actions against any of the Foundation and/or its officers, directors, affiliates, agents, attorneys and employees.

### 6.DISCLAIMER OF WARRANTIES & LIMITATION OF LIABILITY

ALL NFTs ARE PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND EITHER EXPRESS OR IMPLIED. TO THE FULLEST EXTENT PERMISSIBLE PURSUANT TO APPLICABLE LAW, THE FOUNDATION DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF NON-INFRINGEMENT, MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. TO THE FULLEST EXTENT PERMISSIBLE BY APPLICABLE LAW, IN NO EVENT SHALL THE FOUNDATION BE LIABLE TO YOU FOR ANY PERSONAL INJURY, PROPERTY DAMAGE, LOST PROFITS, COST OF SUBSTITUTE GOODS OR SERVICES, LOSS OF DATA, LOSS OF GOODWILL, WORK STOPPAGE, COMPUTER AND/OR DEVICE OR TECHNOLOGY FAILURE OR MALFUNCTION, OR FOR ANY FORM OF DIRECT OR INDIRECT DAMAGES, AND/OR ANY SPECIAL, INCIDENTAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES BASED ON ANY CAUSES OF ACTION WHATSOEVER RELATED TO ANY NFT, INCLUDING BUT NOT LIMITED TO THE NFT, THE OFFERING, ANY TECHNOLOGY AND/OR PARTIES RELATED TO THE OFFERING, INCLUDING BUT NOT LIMITED TO BLOCKCHAIN AND CRYPTO WALLET. YOU AGREE THAT THIS LIMITATION OF LIABILITY APPLIES WHETHER SUCH ALLEGATIONS ARE FOR BREACH OF CONTRACT, TORTIOUS BEHAVIOR, NEGLIGENCE, OR FALL UNDER ANY OTHER CAUSE OF ACTION, REGARDLESS OF THE BASIS UPON WHICH LIABILITY IS CLAIMED AND EVEN IF A DISCLAIMING PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSS OR DAMAGE, AND IN ANY EVENT, TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE FOUNDATION'S TOTAL AGGREGATE LIABILITY SHALL NOT EXCEED TEN PERCENT (10%) OF THE TOTAL SUM PAID DIRECTLY BY YOU TO THE FOUNDATION FOR THE APPLICABLE NFT. YOU ACCEPT THE INHERENT SECURITY RISKS OF PROVIDING INFORMATION AND DEALING ONLINE OVER THE INTERNET AND AGREE THAT WE HAVE NO LIABILITY OR RESPONSIBILITY FOR ANY BREACH OF SECURITY UNLESS IT IS DUE TO OUR GROSS NEGLIGENCE. IF APPLICABLE LAW DOES NOT ALLOW ALL OR ANY PART OF THE ABOVE LIMITATION OF LIABILITY TO APPLY TO YOU, THE LIMITATIONS WILL APPLY TO YOU ONLY TO THE EXTENT PERMITTED BY APPLICABLE LAW.

### 7.ASSUMPTION OF RISK

1. The NFTs are made available solely for entertainment purposes. You agree that You assume the following risks: (A) To the extent there is a price or market for a blockchain asset such as an NFT, such markets and prices are extremely volatile, and variations in the price of other digital assets could materially and adversely affect the value of any digital asset(s) You own, including Your NFT, and there is no guarantee that Your NFTs will have or retain any value; (B) the commercial or market value on an NFT that You purchase may materially diminish in value as a result of a variety of things such as negative publicity; (C) there are risks associated with using Internet-native assets (e.g., non-fungible tokens, cryptocurrencies, etc.) including, but not limited to, the risk of hardware, software and Internet connections and/or failures, the risk of malicious software introduction, and the risk that third parties may obtain unauthorized access to information stored within your digital “wallet” or elsewhere, and the Foundation will not be responsible for any of these, however caused; (D) the Foundation does not make any promises or guarantees about the availability of the NFT or the Art on the Internet or that they will host the NFT or the Art at any specific location and/or for any specific period of time; (E) upgrades to the relevant blockchain platform, a hard fork or other change in the blockchain platform, a failure or cessation of blockchain, or a change in how transactions are confirmed on the blockchain platform may have unintended, adverse effects on all blockchains using such technologies, including without limitation NFTs; (F) the Foundation does not make any promises or guarantees related to cryptocurrency wallet, blockchain or any other third parties related to this auction and each of their applications and/or services, including but not limited to the continued availability of either and/or the protection and/or storage of any data you provide to those parties; (G) the risk of losing access to NFT due to loss of private key(s), custodial error or purchaser error; (H) the risk of mining attacks; (I) the risk of hacking, security weaknesses, fraud, counterfeiting, cyberattacks and other technological difficulties (J) the risk of changes to the regulatory regime governing blockchain technologies, cryptocurrencies, and tokens and new regulations, unfavorable regulatory intervention in one or more jurisdictions or policies any of which may materially adversely affect the use and value of the NFT; (K) the risks related to taxation; (L) that NFTs are not legal tender and are not back by any government; (M) the Foundation is not responsible for any transaction between you and a third party (e.g., Your transfer of a NFT from a third party on the so-called “secondary market”), and the Foundation shall have no liability in connection with any such transaction; and (N) the NFTs, Art or any other part of the Offering, do not and may never have or acquire any functionality or value. The Foundation makes no commitment, representation or warranty in this respect. The Foundation makes no commitment to develop, create or implement any associated game that incorporates the NFTs and/or Art or any other part of the Offering.
2. In addition to assuming all of the above risks, you acknowledge that You have obtained sufficient information to make an informed decision to license the NFT and that You understand and agree that you are solely responsible for determining the nature, potential value, suitability and appropriateness of these risks for yourself. The Foundation cannot and does not represent or warrant that any NFT, or its supporting systems or technology, is reliable, current or error-free, meets Your requirements, or that defects in the NFT, or its supporting systems or technology, will be corrected. The Foundation cannot and does not represent or warrant that the NFT or the delivery mechanism for it are free of viruses or other harmful components. You accept and acknowledge that the Foundation will not be responsible for any communication failures, disruptions, errors, distortions or delays You may experience related to the Offering.

### 8.GOVERNING LAW AND VENUE

This Agreement and all matters related to it and/or any NFT shall be governed by, construed, and enforced in accordance with the laws of the Cayman Islands, as they are applied to agreements entered into and to be performed entirely within the Cayman Islands and without regard to conflict of law principles, except to the extent that law is inconsistent with or preempted by federal law. Any dispute between the parties arising out of or in relation to this Agreement shall be resolved in the courts of Cayman Islands.

### 9.MODIFICATIONS TO THIS AGREEMENT

The Foundation may make changes to this Agreement from time to time. When the Foundation makes such changes, we will make the updated Agreement available on this website and update the “Last Updated” date at the beginning of the Agreement accordingly. Please check this page periodically for changes. To the maximum extent permitted by law, any changes to this Agreement will apply on the date that they are made and, by way of example, Your continued access to or use of the NFT and the Art after the Agreement has been updated will constitute your binding acceptance of the updates.

### 10.ELIGIBILITY

1. Participation in the Offering is open only to individuals who have the right and authority to enter into this Agreement, are fully able and competent to satisfy the terms, conditions, and obligations herein and who are using currency that such party is the lawful holder thereof. It is not available to Users who have had their User privileges temporarily or permanently deactivated. You may not allow other persons to use your User credentials, and You agree that You are the sole authorized user.
2. By becoming a User, You represent and warrant that You are at least 18 years old and that You are not a resident of or located in a country or jurisdiction where purchasing NFTs or the Art or otherwise accessing the Offering is prohibited or restricted. You will not log in or try to log in to access the Offering through unauthorized third party applications or clients.

### 11.INDEMNITY

You will defend, indemnify, and hold the Foundation, including each of their respective affiliates, subsidiaries, parents, successors and assigns, and each of our respective officers, directors, employees, agents, or shareholders, harmless from any claims, actions, suits, losses, costs, liabilities and expenses (including reasonable attorneys’ fees) relating to or arising out of your license, sale or possession of the NFT and/or Your participation in the Offering, including: (1) Your breach of this Agreement or the documents it incorporates by reference; (2) Your violation of any law or the rights of a third party as a result of your own interaction with such third party; (3) any allegation that any materials that You submit to us or transmit in the course of the auction, communications seeking the Foundation's consent to activities or otherwise, infringe or otherwise violate the copyright, trademark, trade secret or other intellectual property or other rights of any third party; and/or (4) any other activities in connection with the Offering or the NFT. This indemnity shall be applicable without regard to the negligence of any party, including any indemnified person.

### 12.SEVERABILITY

If any term or provision of this Agreement is invalid, illegal, or unenforceable in any jurisdiction, such invalidity, illegality, or unenforceability shall not affect any other term or provision of this Agreement or invalidate or render unenforceable such term or provision in any other jurisdiction.

### 13.CONTACT US

If you have any questions or concerns, including if you need to access this Agreement in an alternative format, we encourage you to contact us via e-mail at [contact@hats.finance](mailto:nfts@levana.%EF%AC%81nance)


