Welcome to the Ethereum Foundation Bug Bounty Program

Required burn
—
Minimum severity
Low

Before submitting

  1. Check the scope

    Only targets listed on bounty.ethereum.org are eligible. Anything else is ignored.

  2. Include a reproducible proof of concept

    • A Kurtosis devnet, or a state test (EVM/goevmlab)
    • Unit tests alone are not accepted
  3. Compiler bugs are an exception Solidity/Vyper

    • No devnet or state test needed
    • The source that miscompiles
    • The affected versions, plus one that works

Getting started: Kurtosis testnet guide Ethereum package.

Due to a large increase in reports, response time is likely to be multiple days.

Confirm your proof of concept

Are you sure you want to edit your report?

Your current burn request will be cancelled.