Glamsterdam Bug Bounty
The Glamsterdam upgrade will be in scope once its release candidates are announced on the Ethereum Foundation blog (otevře se v nové záložce). Glamsterdam specifications and EIPs are already in scope with a 0.5× multiplier.
The special rules and multipliers below only apply to bugs specific to the Glamsterdam upgrade. Researchers should target the latest unstable client branches and check for existing issues and pull requests. Bugs already covered by an open issue or pull request are not eligible.
Released clients, EIPs and specifications are now in scope, as per the blog post (otevře se v nové záložce).
Reward multipliers
- 0.5×: From publication of the release candidate blog post until the scheduled Sepolia testnet upgrade. Medium, High and Critical findings are in scope. Glamsterdam specifications and EIPs are already eligible for this multiplier.
- 2.0×: From 24 hours after the Sepolia upgrade epoch finalizes until the Hoodi upgrade. Low, Medium, High and Critical findings are in scope.
- 1.5×: From the Hoodi upgrade until one week before the scheduled mainnet upgrade. Low, Medium, High and Critical findings are in scope.
The multiplier will be determined by when a report is submitted, not when the bug was discovered. The reward amounts shown elsewhere on this page are the standard caps; Glamsterdam multipliers adjust those caps and do not guarantee an award.
Low-severity Glamsterdam findings do not receive rewards during the 0.5× window. Eligibility is based on validated severity.
Upgrade dates are subject to change.
The existing bug bounty rules continue to apply to Glamsterdam reports. All reports unrelated to Glamsterdam follow the normal bug bounty submission rules.
Klienti zahrnutí do odměn











V rozsahu
Náš program Bug Bounty pokrývá vše od začátku do konce: od spolehlivosti protokolů (jako je model konsensu blockchainu, síťové a p2p protokoly, důkaz podílem (PoS) atd.) a souladu protokolu/implementace až po bezpečnost sítě a integritu konsensu. Součástí programu je také klasická bezpečnost klientů a bezpečnost kryptografických primitiv. Všechna odhalení chyb a hlášení zranitelností musí být provedena prostřednictvím našeho formuláře pro nahlášení chyby (otevře se v nové záložce).
Fast Confirmation Rule (otevře se v nové záložce) is now in scope of the Bug Bounty Program.
Kvalifikace závažnosti zranitelností
Závažnost se posuzuje na základě jedinečné schopnosti každé objevené zranitelnosti způsobit následující:
Nahlásit chybu
Žebříček Bug Bounty exekuční vrstvy
Najděte chyby exekuční vrstvy a dostaňte se do tohoto žebříčku
Žebříček Bug Bounty vrstvy konsensu
Najděte chyby vrstvy konsensu a dostaňte se do tohoto žebříčku
Často kladené dotazy
Anonymní podání nebo podání pod pseudonymem je v pořádku, ale ztratíte tím nárok na odměny v ETH/DAI. Abyste měli nárok na odměny v ETH/DAI, požadujeme, abyste zaslali své skutečné jméno a doklad totožnosti, zašifrované pomocí PGP na našem zabezpečeném webu, našemu právnímu týmu v Nadaci Ethereum, který je jediným recenzentem této dokumentace. Darování vaší odměny na charitu nevyžaduje vaši totožnost.
Dejte nám prosím vědět, pokud nechcete, aby se vaše jméno/přezdívka zobrazovala v žebříčku.












































































































