• About
  • Landing Page
  • Buy JNews
Newsletter
Impact Crypto News
Advertisement
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0
No Result
View All Result
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0
No Result
View All Result
Impact Crypto News
No Result
View All Result
Home Crypto News Ethereum

Secured #4: Bug Bounty Rewards now up to $250,000 USD

IMPACTCRYPTO by IMPACTCRYPTO
May 16, 2022
in Ethereum
58 0
0
Secured #4: Bug Bounty Rewards now up to 0,000 USD
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


The Ethereum Foundation Bug Bounty Program is one of the earliest and longest running programs of its kind. It was launched in 2015 and targeted the Ethereum PoW mainnet and related software. In 2020, a second Bug Bounty Program for the new Proof-of-Stake Consensus Layer was launched, running alongside the original Bug Bounty Program.

The split of these programs is historic due to the way the Proof-of-Stake Consensus Layer was architected separately and in parallel to the existing Execution Layer (inside the PoW chain). Since the launch of the Beacon Chain in December of 2020, the technical architecture between the Execution Layer and the Consensus Layer has been distinct, except for the deposit contract, so the two bug bounty programs have remained separated.

In light of the coming Merge, today we are happy to announce that these two programs have been successfully merged by the awesome ethereum.org team, and that the max bounty reward has been substantially increased!

Merge (of the Bug Bounty Programs) ✨

With The Merge approaching, the two previously disparate bug bounty programs have been merged into one.

As the Execution Layer and Consensus Layer become more and more interconnected, it is increasingly valuable to combine the security efforts of these layers. There are already multiple efforts being organized by client teams and the community to further increase knowledge and expertise across the two layers. Unifying the Bounty Program will further increase visibility and coordination efforts on identifying and mitigating vulnerabilities.

Increased Rewards ????

The max reward of the Bounty Program is now $250,000 (paid out in ETH or DAI) for vulnerabilities in scope. Upgrades live on public testnets and targeted for a Mainnet release are also scope, and rewards are doubled during this time, which means that the max reward is $500,000 during these periods!

In total, this marks a 10x increase from the previous maximum payout on Consensus Layer bounties and a 20x increase from the previous max payout on Execution Layer bounties.

Impact Measurement ????

The Bug Bounty Program is primarily focused on securing the base layer of the Ethereum Network. With this in mind, the impact of a vulnerability is in direct correlation to the impact on the network as a whole.

While, for example, a Denial of Service vulnerability found in a client being used by <1% of the network would certainly cause issues for the users of this client, it would have a higher impact on the Ethereum Network if the same vulnerability existed in a client used by >30% of the network.

Visibility ????

In addition to the merge of the bounty programs and increase of the max reward, multiple steps have been taken to clarify how to report vulnerabilities.

Github Security

Repositories such as ethereum/consensus-specs and ethereum/go-ethereum now contain information on how to report vulnerabilities in SECURITY.md files.

security.txt

security.txt is implemented and contains information about how to report vulnerabilities. The file itself can be found here.

DNS Security TXT

DNS Security TXT is implemented and contains information about how to report vulnerabilities. This entry can be viewed by running dig _security.ethereum.org TXT.

How can you get started? ????

With nine different clients written in various languages, Solidity, the Specifications, and the deposit smart contract all within the scope of the bounty program, there is a plenty for bounty hunters to dig into.

If you’re looking for some ideas of where to start your bug hunting journey, take a look at the previously reported vulnerabilities. This was last updated in March and contains all the reported vulnerabilities we have on record, up until the Altair network upgrade.

We’re looking forward to your reports! ????



Source link

Related articles

Rug the Privacy, Not the Money

Rug the Privacy, Not the Money

December 17, 2025
take the zk pill, you stay in the provable reality, and EF’s institutional privacy lead oskar thorén will show you how deep the rabbit hole goes…

take the zk pill, you stay in the provable reality, and EF’s institutional privacy lead oskar thorén will show you how deep the rabbit hole goes…

December 10, 2025
Tags: bitcoin newsBountybugcrypto analysiscrypto newsLatest bitcoin newslatest crypto newsRewardsSecuredUSD
Share76Tweet47

Related Posts

Rug the Privacy, Not the Money

Rug the Privacy, Not the Money

by IMPACTCRYPTO
December 17, 2025
0

When a Cypherpunk Says 'Permissioned' This is an EVMavericks production. All links are added as footnotes in a comment. (Ameen...

take the zk pill, you stay in the provable reality, and EF’s institutional privacy lead oskar thorén will show you how deep the rabbit hole goes…

take the zk pill, you stay in the provable reality, and EF’s institutional privacy lead oskar thorén will show you how deep the rabbit hole goes…

by IMPACTCRYPTO
December 10, 2025
0

oskar thorén is one of the leads in ethereum foundation's newest IPTF, or institutional privacy task force. he's a freedom...

BC.GAME’s “Stay Untamed” Breakpoint Eve party tops 1,200 sign-ups, with DubVision and Mari Ferrari headlining

BC.GAME’s “Stay Untamed” Breakpoint Eve party tops 1,200 sign-ups, with DubVision and Mari Ferrari headlining

by IMPACTCRYPTO
December 8, 2025
0

Belize City, Belize, December 8th, 2025, Chainwire As Bitcoin MENA 2025, Solana Breakpoint 2025 and the Global Blockchain Show bring...

Hotstuff Labs launches Hotstuff, a DeFi native Layer 1 connecting On-Chain Trading with Global Fiat Rails

Hotstuff Labs launches Hotstuff, a DeFi native Layer 1 connecting On-Chain Trading with Global Fiat Rails

by IMPACTCRYPTO
December 5, 2025
0

Singapore, Singapore, December 5th, 2025, Chainwire Hotstuff Labs today announced the public testnet for Hotstuff L1, a DeFi Layer 1...

Devconnect Argentina Recap | Ethereum Foundation Blog

Devconnect Argentina Recap | Ethereum Foundation Blog

by IMPACTCRYPTO
December 4, 2025
0

Devconnect Buenos Aires wrapped up as the largest Ethereum Foundation event yet, bringing together a global mix of developers, founders,...

Load More

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.
No Result
View All Result
  • Home
  • DeFi News
  • EVM News
    • Avalanche Network
    • Ethereum
    • Fantom Opera Chain
    • Harmony Chain
    • Huobi Eco Chain
    • Polkadot Chain
    • Polygon Chain
  • NFT News
  • Altcoin News
  • Crypto News
    • Crypto Regulation News
    • Bitcoin
    • Blockchain
    • Crypto Exchanges
    • Crypto Mining
    • Metaverse
    • Scam News
    • Web 3.0

© 2018 JNews by Jegtheme.