Glamsterdam Bug Bounty
The Glamsterdam upgrade will be in scope once its release candidates are announced on the Ethereum Foundation blog (يفتح في علامة تبويب جديدة). Glamsterdam specifications and EIPs are already in scope with a 0.5× multiplier.
The special rules and multipliers below only apply to bugs specific to the Glamsterdam upgrade. Researchers should target the latest unstable client branches and check for existing issues and pull requests. Bugs already covered by an open issue or pull request are not eligible.
Released clients, EIPs and specifications are now in scope, as per the blog post (يفتح في علامة تبويب جديدة).
Reward multipliers
- 0.5×: From publication of the release candidate blog post until the scheduled Sepolia testnet upgrade. Medium, High and Critical findings are in scope. Glamsterdam specifications and EIPs are already eligible for this multiplier.
- 2.0×: From 24 hours after the Sepolia upgrade epoch finalizes until the Hoodi upgrade. Low, Medium, High and Critical findings are in scope.
- 1.5×: From the Hoodi upgrade until one week before the scheduled mainnet upgrade. Low, Medium, High and Critical findings are in scope.
The multiplier will be determined by when a report is submitted, not when the bug was discovered. The reward amounts shown elsewhere on this page are the standard caps; Glamsterdam multipliers adjust those caps and do not guarantee an award.
Low-severity Glamsterdam findings do not receive rewards during the 0.5× window. Eligibility is based on validated severity.
Upgrade dates are subject to change.
The existing bug bounty rules continue to apply to Glamsterdam reports. All reports unrelated to Glamsterdam follow the normal bug bounty submission rules.
العملاء المشمولون في المكافآت











ضمن النطاق
يمتد برنامج مكافآت الأخطاء الخاص بنا من البداية إلى النهاية: من سلامة البروتوكولات (مثل نموذج إجماع سلسلة الكتل، وبروتوكولات الاتصال ونظير إلى نظير، و إثبات الحصة (PoS)، وما إلى ذلك) وامتثال بروتوكول/التنفيذ إلى أمان شبكة وسلامة إجماع. يعد أمان العميل الكلاسيكي بالإضافة إلى أمان الأساسيات التشفيرية جزءًا من البرنامج أيضًا. يجب إجراء جميع عمليات الكشف عن الأخطاء وتقديم الثغرات من خلال نموذج إرسال الأخطاء (يفتح في علامة تبويب جديدة) الخاص بنا.
Fast Confirmation Rule (يفتح في علامة تبويب جديدة) is now in scope of the Bug Bounty Program.
مؤهلات خطورة الثغرات الأمنية
يتم تقييم الخطورة بناءً على القدرة الفريدة لكل ثغرة أمنية مكتشفة على القيام بما يلي:
إرسال خطأ
لوحة صدارة مكافآت أخطاء طبقة التنفيذ
ابحث عن أخطاء طبقة التنفيذ لتتم إضافتك إلى لوحة الصدارة هذه
لوحة صدارة مكافآت أخطاء طبقة الإجماع
ابحث عن أخطاء طبقة الإجماع لتتم إضافتك إلى لوحة الصدارة هذه
الأسئلة الشائعة
التقديم بشكل مجهول أو باستخدام اسم مستعار أمر مقبول، ولكنه سيجعلك غير مؤهل للحصول على مكافآت ETH/DAI. لتكون مؤهلاً للحصول على مكافآت ETH/DAI، نطلب إرسال اسمك الحقيقي وإثبات هويتك، مشفرًا باستخدام PGP على موقعنا الآمن، إلى فريقنا القانوني في مؤسسة إيثيريوم وهم المراجعون الوحيدون للوثائق. التبرع بمكافأتك لجمعية خيرية لا يتطلب الكشف عن هويتك.
يُرجى إعلامنا إذا كنت لا ترغب في عرض اسمك/لقبك في لوحة المتصدرين.












































































































