Glamsterdam Bug Bounty
The Glamsterdam upgrade will be in scope once its release candidates are announced on the Ethereum Foundation blog (opens in a new tab). Glamsterdam specifications and EIPs are already in scope with a 0.5× multiplier.
The special rules and multipliers below only apply to bugs specific to the Glamsterdam upgrade. Researchers should target the latest unstable client branches and check for existing issues and pull requests. Bugs already covered by an open issue or pull request are not eligible.
Reward multipliers
- 0.5×: From publication of the release candidate blog post until the scheduled Sepolia testnet upgrade. Medium, High and Critical findings are in scope. Glamsterdam specifications and EIPs are already eligible for this multiplier.
- 2.0×: From 24 hours after the Sepolia upgrade epoch finalizes until the Hoodi upgrade. Low, Medium, High and Critical findings are in scope.
- 1.5×: From the Hoodi upgrade until one week before the scheduled mainnet upgrade. Low, Medium, High and Critical findings are in scope.
The multiplier will be determined by when a report is submitted, not when the bug was discovered. The reward amounts shown elsewhere on this page are the standard caps; Glamsterdam multipliers adjust those caps and do not guarantee an award.
Low-severity Glamsterdam findings do not receive rewards during the 0.5× window. Eligibility is based on validated severity.
Upgrade dates are subject to change.
The existing bug bounty rules continue to apply to Glamsterdam reports. All reports unrelated to Glamsterdam follow the normal bug bounty submission rules.
Clients featured in the bounties











In Scope
Our bug bounty program spans end-to-end: from soundness of protocols (such as the blockchain consensus model, the wire and p2p protocols, proof of stake, etc.) and protocol/implementation compliance to network security and consensus integrity. Classical client security as well as security of cryptographic primitives are also part of the program. All bug disclosures and vulnerability submissions must be made through our bug submission form (opens in a new tab).
Vulnerability severity qualifications
Severity is assessed based on each discovered vulnerability's unique ability to do the following:
Submit a bug
Execution Layer Bug Bounty leaderboard
Find execution layer bugs to get added to this leaderboard
Consensus Layer Bug Bounty leaderboard
Find consensus layer bugs to get added to this leaderboard
Frequently asked questions
Submitting anonymously or with a pseudonym is OK, but will make you ineligible for ETH/DAI rewards. To be eligible for ETH/DAI rewards, we require your real name and a proof of your identity to be sent, encrypted using PGP on our secure drop website, to our legal team at the Ethereum Foundation who are the sole reviewers of the documentation. Donating your bounty to a charity doesn’t require your identity.
Please let us know if you do not want your name/nick displayed on the leader board.








































































































