Puffer launches a bug bounty program on Sherlock offering up to $100K for critical vulnerabilities in its Ethereum infrastructure.
Tech & Launches ·
Puffer has launched a bug bounty program on Sherlock with rewards up to $100K for identifying critical vulnerabilities in its Ethereum infrastructure. Sherlock is hosting the program, which invites external security researchers to probe the protocol's code in exchange for compensation.
Bug bounty programs represent a formalized approach to protocol security, where conditional rewards are paid to anyone who completes a defined task—in this case, discovering and reporting smart-contract vulnerabilities. The distinction between informal bounties (announced via social channels) and on-chain implementations matters significantly: informal bounties depend on the issuer's willingness to pay, while on-chain versions remove counterparty risk by locking funds in smart contracts that release automatically upon verified completion.
It remains unclear whether Puffer's Sherlock bounty is structured on-chain or informally, what the scope of eligible infrastructure extends to beyond smart contracts, how the submission and verification process will operate, or whether a single researcher or multiple hunters may claim rewards for separate valid findings.