Chainlink expanded its bug bounty program scope on Immunefi, adding 4 new impact categories and removing 1.
Tech & Launches ·
Chainlink has expanded its bug bounty program on Immunefi, adding four new impact categories to its vulnerability reporting scope. The adjustment results in a net addition of three eligible vulnerability types after one category was removed, broadening the range of issues that security researchers can report for potential rewards.
The program requires proof of concept submissions for smart contract reports, along with fix suggestions, to qualify for bounties. Critical smart contract vulnerabilities carry a maximum reward of USD $3,000,000, with specific amounts determined by factors including impact, exploitability, and likelihood of exploit conditions. All reporters must complete Know-Your-Customer or Know-Your-Business verification and pass screening checks before payouts, which are distributed in USD Coin.
The exact nature of the four newly added categories and the single removed category is not detailed in available materials, nor is it specified whether the expanded scope applies to smart contracts, websites, applications, or other asset classes within the Chainlink ecosystem.