ZKsync Era expanded its bug bounty program scope to include 92 new assets while removing 47, increasing vulnerability eligibility on Immunefi.
Tech & Launches ·
ZKsync Era has expanded the scope of its bug bounty program on Immunefi, adding 92 new assets while removing 47, for a net increase of 45 eligible assets. The expansion broadens the surface area for vulnerability disclosures and potential bounty rewards across the protocol.
The program operates under a threat-level-based reward structure, with critical vulnerabilities on mainnet assets eligible for up to $300,000, capped at 10% of directly affected funds. High-severity smart contract vulnerabilities carry a minimum reward of $20,000. All payouts are processed by the ZKsync team in USDC and require KYC verification using government identification.
The specifics of which asset categories were added and which were removed remain unclear from the publicly available summary. Additionally, the rationale behind the scope adjustment—whether driven by new contract deployments, simplified coverage, or security considerations—has not been disclosed.