Glamsterdam Bug Bounty
The Glamsterdam upgrade will be in scope once its release candidates are announced on the Ethereum Foundation blog (新しいタブで開きます). Glamsterdam specifications and EIPs are already in scope with a 0.5× multiplier.
The special rules and multipliers below only apply to bugs specific to the Glamsterdam upgrade. Researchers should target the latest unstable client branches and check for existing issues and pull requests. Bugs already covered by an open issue or pull request are not eligible.
Reward multipliers
- 0.5×: From publication of the release candidate blog post until the scheduled Sepolia testnet upgrade. Medium, High and Critical findings are in scope. Glamsterdam specifications and EIPs are already eligible for this multiplier.
- 2.0×: From 24 hours after the Sepolia upgrade epoch finalizes until the Hoodi upgrade. Low, Medium, High and Critical findings are in scope.
- 1.5×: From the Hoodi upgrade until one week before the scheduled mainnet upgrade. Low, Medium, High and Critical findings are in scope.
The multiplier will be determined by when a report is submitted, not when the bug was discovered. The reward amounts shown elsewhere on this page are the standard caps; Glamsterdam multipliers adjust those caps and do not guarantee an award.
Low-severity Glamsterdam findings do not receive rewards during the 0.5× window. Eligibility is based on validated severity.
Upgrade dates are subject to change.
The existing bug bounty rules continue to apply to Glamsterdam reports. All reports unrelated to Glamsterdam follow the normal bug bounty submission rules.
バウンティ対象のクライアント











対象範囲
私たちのバグバウンティ・プログラムは、プロトコルの健全性(ブロックチェーンのコンセンサスモデル、ワイヤーおよびp2pプロトコル、プルーフ・オブ・ステーク(PoS)など)やプロトコル/実装の準拠から、ネットワークのセキュリティやコンセンサスの完全性まで、エンドツーエンドに及びます。古典的なクライアントのセキュリティや暗号プリミティブのセキュリティもプログラムの一部です。すべてのバグの開示および脆弱性の報告は、バグ報告フォーム (新しいタブで開きます)を通じて行う必要があります。
脆弱性の深刻度の基準
深刻度は、発見された各脆弱性が以下の事象を引き起こす固有の能力に基づいて評価されます。
バグを報告する
実行レイヤーのバグバウンティ・リーダーボード
実行レイヤーのバグを発見して、このリーダーボードに掲載されましょう
コンセンサス・レイヤーのバグバウンティ・リーダーボード
コンセンサス・レイヤーのバグを発見して、このリーダーボードに掲載されましょう
よくある質問
匿名または仮名での提出は可能ですが、ETH/DAIの報酬の対象外となります。ETH/DAIの報酬を受け取るには、本名と身分証明書を、当社の安全なドロップウェブサイト上でPGPを使用して暗号化し、イーサリアム財団の法務チーム(文書の唯一の審査担当)に送信していただく必要があります。報奨金を慈善団体に寄付する場合は、身元を明かす必要はありません。
リーダーボードに名前やニックネームを表示したくない場合は、お知らせください。








































































































