LayerZero, Immunefi Offer Bug Bounty With $15M Max Payout

KYC is required for participation, and there are range of rewards available for bug hunters

article-image

Kelvin Degree/Shutterstock modified by Blockworks

share

LayerZero, a cross-chain messaging protocol, has established a bug bounty with a maximum reward of $15 million alongside partner Immunefi.

That number surpasses MakerDAO’s bug bounty, which offered a maximum of $10 million after launching in February 2022.

LayerZero will reserve the maximum bounty reward for those who find vulnerabilities at the “highest severity level,” and it will be paid out for each new bug found by participants.

LayerZero’s decision to partner with Immunefi mirrors the thinking of other prominent projects who have adopted the Web3 platform for their own bug bounties, including MakerDAO, Compound and Chainlink. Immunefi raised $24 million in its Series A round back in September 2022 and now claims to have paid out over $75 million in bounties. 

Immunefi’s terms for LayerZero’s bounty are public and outline the rewards by “threat level” and by “groups.” Group 1 includes the chains Ethereum, BNB Chain, Avalanche, Polygon, Arbitrum, Optimism, and Fantom, while Group 2 is for every other chain out there. 

The highest threat level for bugs is “critical,” as defined by Immunefi. For smart contracts, a critical threat entails voting manipulation in governance proposals, direct theft of user funds and NFTs, among a host of other things.

According to Immunefi’s terms, “Critical smart contract vulnerability payouts for Group 1 are a minimum of USD $250,000, or 10% of the value at risk at the time of report submission, with a hard cap of USD $15,000,000, whichever is larger. Value at risk should be calculated primarily (though not exclusively) based on concrete and demonstrable funds at risk.”

For Group 2, the minimum payout is $25,000 or, again, 10% of the value that’s at risk. The cap is $1.5 million. 

Importantly, smaller payouts are up for grabs for lower threat bugs that participants are able to find. The lowest minimum prize is $1,000.

Supplementary rewards beyond minimum payouts or the 10% metric is “at the discretion of the team.”

Additionally, know-your-customer is needed to participate in this bounty. That means to get paid, you’ll have to send an invoice with your name, address and payment instructions. A government identification and an Office of Foreign Assets Control (OFAC) screening are also required. 

Blockworks reported in April that LayerZero secured $120 million in funding to expand into the Asia-Pacific region’s gaming sector, boosting the company’s valuation to $3 billion.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the Forward Guidance newsletter.

Get alpha directly in your inbox with the 0xResearch newsletter — market highlights, charts, degen trade ideas, governance updates, and more.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates (1).jpg

Research

With $13B in tokenized assets, strong institutional partnerships, and a clear first-mover advantage in the RWA space. The platform's methodical approach to regulatory compliance, coupled with its hybrid public-private architecture, positions it uniquely to capture significant market share in the emerging tokenization landscape. While current fee generation primarily stems from metadata transactions, the planned launch of Figure Markets, major exchange listings, and comprehensive market-making initiatives in 2025 could serve as powerful catalysts for growth.

article-image

Perena is built on the premise that as stablecoins proliferate, liquidity could fragment, and stablecoins aren’t useful if they aren’t liquid

article-image

From hackathons to trading tools and DAO governance, AI agents are redefining how we build and innovate

article-image

CME’s large bitcoin contracts are so big that investors are turning to micro bitcoin contracts

article-image

The third-largest stablecoin is going multichain for the first time in its seven-year history

article-image

Nano Labs’ news release notes confidence in bitcoin being “a reliable store of value amidst its rising global adoption”

article-image

Several big companies report third quarter earnings this week, likely moving markets