Glamsterdam Bug Bounty
The Glamsterdam upgrade will be in scope once its release candidates are announced on the Ethereum Foundation blog (öffnet in einem neuen Tab). Glamsterdam specifications and EIPs are already in scope with a 0.5× multiplier.
The special rules and multipliers below only apply to bugs specific to the Glamsterdam upgrade. Researchers should target the latest unstable client branches and check for existing issues and pull requests. Bugs already covered by an open issue or pull request are not eligible.
For now, only the Glamsterdam specifications and EIPs are in scope. Clients are not yet eligible.
Reward multipliers
- 0.5×: From publication of the release candidate blog post until the scheduled Sepolia testnet upgrade. Medium, High and Critical findings are in scope. Glamsterdam specifications and EIPs are already eligible for this multiplier.
- 2.0×: From 24 hours after the Sepolia upgrade epoch finalizes until the Hoodi upgrade. Low, Medium, High and Critical findings are in scope.
- 1.5×: From the Hoodi upgrade until one week before the scheduled mainnet upgrade. Low, Medium, High and Critical findings are in scope.
The multiplier will be determined by when a report is submitted, not when the bug was discovered. The reward amounts shown elsewhere on this page are the standard caps; Glamsterdam multipliers adjust those caps and do not guarantee an award.
Low-severity Glamsterdam findings do not receive rewards during the 0.5× window. Eligibility is based on validated severity.
Upgrade dates are subject to change.
The existing bug bounty rules continue to apply to Glamsterdam reports. All reports unrelated to Glamsterdam follow the normal bug bounty submission rules.
Im Bug-Bounty-Programm enthaltene Clients











Im Geltungsbereich
Unser Bug-Bounty-Programm erstreckt sich von Anfang bis Ende: von der Solidität der Protokolle (wie dem Blockchain-Konsensmodell, den Wire- und Peer-to-Peer-Protokollen, Proof-of-Stake usw.) und der Protokoll-/Implementierungskonformität bis hin zur Netzwerksicherheit und Konsensintegrität. Klassische Client-Sicherheit sowie die Sicherheit kryptografischer Primitive sind ebenfalls Teil des Programms. Alle Bug-Offenlegungen und Schwachstellenmeldungen müssen über unser Bug-Meldeformular (öffnet in einem neuen Tab) erfolgen.
Fast Confirmation Rule (öffnet in einem neuen Tab) is now in scope of the Bug Bounty Program.
Einstufung des Schweregrads von Schwachstellen
Der Schweregrad wird basierend auf der spezifischen Fähigkeit jeder entdeckten Schwachstelle bewertet, Folgendes zu tun:
Einen Bug melden
Bestenliste des Ausführungsschicht-Bug-Bounty-Programms
Finden Sie Bugs in der Ausführungsschicht, um in diese Bestenliste aufgenommen zu werden
Bestenliste des Konsensschicht-Bug-Bounty-Programms
Finden Sie Bugs in der Konsensschicht, um in diese Bestenliste aufgenommen zu werden
Häufig gestellte Fragen
Eine anonyme Einreichung oder die Verwendung eines Pseudonyms ist in Ordnung, schließt dich jedoch von ETH/DAI-Belohnungen aus. Um für ETH/DAI-Belohnungen in Frage zu kommen, benötigen wir deinen echten Namen und einen Identitätsnachweis. Diese müssen mit PGP verschlüsselt über unsere sichere Drop-Website an das Rechtsteam der Ethereum Foundation gesendet werden, welches als einziges die Dokumentation überprüft. Wenn du deine Prämie an eine wohltätige Organisation spendest, ist kein Identitätsnachweis erforderlich.
Bitte lass uns wissen, falls du nicht möchtest, dass dein Name/Spitzname auf der Bestenliste angezeigt wird.










































































































