Chainlink expanded its bug bounty program scope on Immunefi, adding 8 new impact categories and removing 4 (net +4 eligible vulnerabilities).
Tech & Launches ·
Chainlink has expanded its bug bounty program scope on Immunefi, adding eight new vulnerability impact categories while removing four, resulting in a net increase of four eligible vulnerability types. The adjustment widens the range of security issues that researchers can report for potential rewards on the platform. Details of the scope changes remain available on the Immunefi bounty page, where the program specifies that all smart contract bug reports must include a proof of concept and remediation suggestion to qualify for compensation. Critical smart contract vulnerabilities carry maximum rewards of USD $3,000,000 at the discretion of Chainlink Labs, with final amounts determined by factors including exploit impact and likelihood. Reporters must complete Know-Your-Customer or Know-Your-Business verification and pass OFAC screening before bounty payouts, which are sent in USD Coin. The precise vulnerabilities added and removed in this update, and which threat levels or asset categories they affect, are not detailed in publicly available materials.