Glamsterdam Bug Bounty
The Glamsterdam upgrade will be in scope once its release candidates are announced on the Ethereum Foundation blog (새 탭에서 열림). Glamsterdam specifications and EIPs are already in scope with a 0.5× multiplier.
The special rules and multipliers below only apply to bugs specific to the Glamsterdam upgrade. Researchers should target the latest unstable client branches and check for existing issues and pull requests. Bugs already covered by an open issue or pull request are not eligible.
Reward multipliers
- 0.5×: From publication of the release candidate blog post until the scheduled Sepolia testnet upgrade. Medium, High and Critical findings are in scope. Glamsterdam specifications and EIPs are already eligible for this multiplier.
- 2.0×: From 24 hours after the Sepolia upgrade epoch finalizes until the Hoodi upgrade. Low, Medium, High and Critical findings are in scope.
- 1.5×: From the Hoodi upgrade until one week before the scheduled mainnet upgrade. Low, Medium, High and Critical findings are in scope.
The multiplier will be determined by when a report is submitted, not when the bug was discovered. The reward amounts shown elsewhere on this page are the standard caps; Glamsterdam multipliers adjust those caps and do not guarantee an award.
Low-severity Glamsterdam findings do not receive rewards during the 0.5× window. Eligibility is based on validated severity.
Upgrade dates are subject to change.
The existing bug bounty rules continue to apply to Glamsterdam reports. All reports unrelated to Glamsterdam follow the normal bug bounty submission rules.
바운티 대상 클라이언트











범위 내
우리의 버그 바운티 프로그램은 프로토콜의 건전성(블록체인 합의 모델, 와이어 및 p2p 프로토콜, 지분 증명 (PoS) 등)과 프로토콜/구현 준수부터 네트워크 보안 및 합의 무결성에 이르기까지 엔드투엔드로 포괄합니다. 고전적인 클라이언트 보안과 암호화 기본 요소의 보안도 프로그램의 일부입니다. 모든 버그 공개 및 취약점 제출은 버그 제출 양식 (새 탭에서 열림)을 통해 이루어져야 합니다.
취약점 심각도 기준
심각도는 발견된 각 취약점이 다음을 수행할 수 있는 고유한 능력을 바탕으로 평가됩니다.
버그 제출하기
실행 계층 버그 바운티 리더보드
실행 계층 버그를 찾아 이 리더보드에 이름을 올리세요
합의 레이어 버그 바운티 리더보드
합의 레이어 버그를 찾아 이 리더보드에 이름을 올리세요
자주 묻는 질문
익명이나 가명으로 제출해도 괜찮지만, ETH/DAI 보상 대상에서는 제외됩니다. ETH/DAI 보상을 받으려면 실명과 신원 증명을 보안 드롭 웹사이트에서 PGP로 암호화하여 문서를 단독으로 검토하는 이더리움 재단 법무팀에 보내야 합니다. 바운티를 자선 단체에 기부하는 경우에는 신원 증명이 필요하지 않습니다.
리더보드에 이름/닉네임이 표시되는 것을 원하지 않으시면 알려주세요.








































































































