LayerZero, Immunefi Offer Bug Bounty With $15M Max Payout

KYC is required for participation, and there are range of rewards available for bug hunters

article-image

Kelvin Degree/Shutterstock modified by Blockworks

share

LayerZero, a cross-chain messaging protocol, has established a bug bounty with a maximum reward of $15 million alongside partner Immunefi.

That number surpasses MakerDAO’s bug bounty, which offered a maximum of $10 million after launching in February 2022.

LayerZero will reserve the maximum bounty reward for those who find vulnerabilities at the “highest severity level,” and it will be paid out for each new bug found by participants.

LayerZero’s decision to partner with Immunefi mirrors the thinking of other prominent projects who have adopted the Web3 platform for their own bug bounties, including MakerDAO, Compound and Chainlink. Immunefi raised $24 million in its Series A round back in September 2022 and now claims to have paid out over $75 million in bounties. 

Immunefi’s terms for LayerZero’s bounty are public and outline the rewards by “threat level” and by “groups.” Group 1 includes the chains Ethereum, BNB Chain, Avalanche, Polygon, Arbitrum, Optimism, and Fantom, while Group 2 is for every other chain out there. 

The highest threat level for bugs is “critical,” as defined by Immunefi. For smart contracts, a critical threat entails voting manipulation in governance proposals, direct theft of user funds and NFTs, among a host of other things.

According to Immunefi’s terms, “Critical smart contract vulnerability payouts for Group 1 are a minimum of USD $250,000, or 10% of the value at risk at the time of report submission, with a hard cap of USD $15,000,000, whichever is larger. Value at risk should be calculated primarily (though not exclusively) based on concrete and demonstrable funds at risk.”

For Group 2, the minimum payout is $25,000 or, again, 10% of the value that’s at risk. The cap is $1.5 million. 

Importantly, smaller payouts are up for grabs for lower threat bugs that participants are able to find. The lowest minimum prize is $1,000.

Supplementary rewards beyond minimum payouts or the 10% metric is “at the discretion of the team.”

Additionally, know-your-customer is needed to participate in this bounty. That means to get paid, you’ll have to send an invoice with your name, address and payment instructions. A government identification and an Office of Foreign Assets Control (OFAC) screening are also required. 

Blockworks reported in April that LayerZero secured $120 million in funding to expand into the Asia-Pacific region’s gaming sector, boosting the company’s valuation to $3 billion.


Get the news in your inbox. Explore Blockworks newsletters:

Tags

Decoding crypto and the markets. Daily, with Byron Gilliam.

Upcoming Events

Old Billingsgate

Mon - Wed, October 13 - 15, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

Industry City | Brooklyn, NY

TUES - THURS, JUNE 24 - 26, 2025

Permissionless IV serves as the definitive gathering for crypto’s technical founders, developers, and builders to come together and create the future.If you’re ready to shape the future of crypto, Permissionless IV is where it happens.

Brooklyn, NY

SUN - MON, JUN. 22 - 23, 2025

Blockworks and Cracked Labs are teaming up for the third installment of the Permissionless Hackathon, happening June 22–23, 2025 in Brooklyn, NY. This is a 36-hour IRL builder sprint where developers, designers, and creatives ship real projects solving real problems across […]

recent research

Research Report Templates (8).png

Research

Meta-aggregators like Titan and Kamino Swap improve price execution for users, making the Solana swapping landscape more competitive. Jupiter has incorporated meta-aggregation features into its latest routing engine to keep users on its front end (own the user, own the flow). At large, teams are treating swaps as a commoditized complement, offering incredibly cheap or free swaps to own the end-user and increase demand for high-margin product offerings (multi-product DeFi). On another note, the divergence in the concentration of aggregator volume between DEXs suggests increased specialization at the DEX layer by asset type.

article-image

Onboarding the world to Bitcoin takes a series of firsts

article-image

If we get an altcoin season, it’ll be focused on tokens deemed “ fundamentally valuable enough for traditional public money and capital” to get involved with

article-image

Solana dropped nearly 10% amid mass crypto liquidations triggered by rising geopolitical strife

article-image

Investors moved to safe assets like the US dollar and gold, but bonds faltered

article-image

The Amex offers up to 4% bitcoin back, but the deal is a bit ironic considering crypto’s goals

article-image

Short answer: Subnets are now cheaper to bootstrap than a Celestia rollup