Arbitrum expanded its Immunefi bug bounty program scope, adding 6 new impact categories and removing 2, for a net increase of 4 eligible vulnerabilities.
Tech & Launches ·
Arbitrum has expanded the scope of its Immunefi bug bounty program, adding six new impact categories while removing two, resulting in a net increase of four eligible vulnerability types. The adjustment widens the range of security issues that researchers can report for potential rewards on the platform.
The program covers vulnerabilities in Arbitrum One and Arbitrum Nova, the protocol's mainnet chains built on Optimistic Rollup and AnyTrust technology respectively. Rewards are calculated at 10% of directly affected funds up to a maximum of $2,000,000 for mainnet assets, with critical vulnerabilities capped at a minimum of $50,000 and high-severity issues at $10,000. All submissions must include a proof of concept and meet KYC requirements, with payouts handled by the Arbitrum Foundation team in USDC.
The specific details of which impact categories were added or removed are not enumerated in available materials, leaving unclear exactly which vulnerability types are now in or out of scope. The full scope changes are documented separately.