Glamsterdam Bug Bounty
The Glamsterdam upgrade will be in scope once its release candidates are announced on the Ethereum Foundation blog (mở trong tab mới). Glamsterdam specifications and EIPs are already in scope with a 0.5× multiplier.
The special rules and multipliers below only apply to bugs specific to the Glamsterdam upgrade. Researchers should target the latest unstable client branches and check for existing issues and pull requests. Bugs already covered by an open issue or pull request are not eligible.
Released clients, EIPs and specifications are now in scope, as per the blog post (mở trong tab mới).
Reward multipliers
- 0.5×: From publication of the release candidate blog post until the scheduled Sepolia testnet upgrade. Medium, High and Critical findings are in scope. Glamsterdam specifications and EIPs are already eligible for this multiplier.
- 2.0×: From 24 hours after the Sepolia upgrade epoch finalizes until the Hoodi upgrade. Low, Medium, High and Critical findings are in scope.
- 1.5×: From the Hoodi upgrade until one week before the scheduled mainnet upgrade. Low, Medium, High and Critical findings are in scope.
The multiplier will be determined by when a report is submitted, not when the bug was discovered. The reward amounts shown elsewhere on this page are the standard caps; Glamsterdam multipliers adjust those caps and do not guarantee an award.
Low-severity Glamsterdam findings do not receive rewards during the 0.5× window. Eligibility is based on validated severity.
Upgrade dates are subject to change.
The existing bug bounty rules continue to apply to Glamsterdam reports. All reports unrelated to Glamsterdam follow the normal bug bounty submission rules.
Các máy khách có trong chương trình tiền thưởng











Trong phạm vi
Chương trình tiền thưởng lỗi của chúng tôi bao trùm từ đầu đến cuối: từ tính đúng đắn của các giao thức (chẳng hạn như mô hình đồng thuận chuỗi khối, các giao thức wire và p2p, bằng chứng cổ phần, v.v.) và sự tuân thủ giao thức/triển khai cho đến bảo mật mạng lưới và tính toàn vẹn của đồng thuận. Bảo mật máy khách cổ điển cũng như bảo mật của các nguyên thủy mật mã cũng là một phần của chương trình. Tất cả các tiết lộ lỗi và báo cáo lỗ hổng phải được thực hiện thông qua biểu mẫu gửi báo cáo lỗi (mở trong tab mới) của chúng tôi.
Fast Confirmation Rule (mở trong tab mới) is now in scope of the Bug Bounty Program.
Tiêu chuẩn về mức độ nghiêm trọng của lỗ hổng
Mức độ nghiêm trọng được đánh giá dựa trên khả năng riêng biệt của mỗi lỗ hổng được phát hiện để thực hiện những điều sau:
Gửi báo cáo lỗi
Bảng xếp hạng Tiền thưởng Lỗi Lớp thực thi
Tìm các lỗi lớp thực thi để được thêm vào bảng xếp hạng này
Bảng xếp hạng Tiền thưởng Lỗi Lớp đồng thuận
Tìm các lỗi lớp đồng thuận để được thêm vào bảng xếp hạng này
Các câu hỏi thường gặp
Gửi báo cáo ẩn danh hoặc dùng biệt danh là được, nhưng sẽ khiến bạn không đủ điều kiện nhận phần thưởng ETH/DAI. Để đủ điều kiện nhận phần thưởng ETH/DAI, chúng tôi yêu cầu bạn gửi tên thật và bằng chứng nhận dạng, được mã hóa bằng PGP trên trang web gửi dữ liệu an toàn của chúng tôi, cho đội ngũ pháp lý của Tổ chức Ethereum, những người duy nhất xem xét tài liệu. Việc quyên góp tiền thưởng của bạn cho một tổ chức từ thiện không yêu cầu danh tính của bạn.
Vui lòng cho chúng tôi biết nếu bạn không muốn tên/biệt danh của mình hiển thị trên bảng xếp hạng.












































































































