ZKsync OS expanded its bug bounty program scope to cover 230 additional assets on Immunefi.
Tech & Launches ·
ZKsync OS has expanded the scope of its bug bounty program on Immunefi to encompass 230 additional assets. The expansion broadens the range of vulnerabilities eligible for researcher compensation across the protocol's ecosystem.
The program covers ZKsync OS, described as an execution layer supporting multiple virtual machines, along with its associated smart contracts for settlement and communication, the Airbender proving system, and related cryptographic components. Payouts for critical issues are structured as 10% of directly affected funds, with a floor of $30,000 to $50,000 depending on asset type and a ceiling of $100,000. Rewards for high and medium severity findings scale within published ranges based on exploitability and impact. Compensation is distributed in USDC on ZKsync Era, with USD pricing determined by averaging rates from CoinMarketCap and CoinGecko at submission time.
The specific composition of the 230 newly in-scope assets and the precise mechanics of how the expansion affects researcher eligibility remain unclear from available detail. Whether this represents a change to existing coverage or addition of entirely new asset categories has not been specified.