
Arbitrum
Leading Ethereum Layer 2 scaling solution using optimistic rollup technology
ARBETHLayer 2KYC RequiredPoC Required
Verified ProgramKYC RequiredPoC Required
Max Bounty$2,000,000
Min Bounty$1,000
PayoutUSDC
Findings0
Accepted0
Chains2
Live SinceAug 2021
11 Audit Reports Available
2023-12-offchain-labs-arbitrum-token-bridge-creator-securityreview.pdfTrail of Bits
2023-122025-06-offchain-arbitrum-block-hash-pusher-securityreview.pdfTrail of Bits
2025-062025-06-offchain-arbitrum-mint-burn-precompile-securityreview.pdfTrail of Bits
2025-062025-12-offchain-arbitrum-chains-genesis-generator-securityreview.pdfTrail of Bits
2025-122026-1-offchain-arbitrum-quorum-changes-securityreview.pdfTrail of Bits
2026PeckShield-Audit-Report-Spool-Arbitrum-v1.0.pdfPeckShield
2023-08-arbitrum-findingsCode4rena
2023-082024-05-arbitrum-foundation-findingsCode4rena
2024-05ArbitrumHacken
Show detailsHexens
2024MakerDAO Arbitrum Token Bridge Audit MakerDAO 14 October 2024 - 15 October 2024Cantina
2024-Oct01Severity & Rewards
02Program Rules
- 01Proof of Concept is required for all submissions. Reports without a working PoC demonstrating the vulnerability will not be considered.
- 02KYC verification is required before bounty payout. Researchers must complete identity verification to receive rewards.
- 03Only previously unreported vulnerabilities are eligible. Duplicate submissions will be closed.
- 04Vulnerabilities must be reported through the WhiteClaws platform. Public disclosure before resolution disqualifies the submission.
- 05Testing must not disrupt live protocol operations. Use mainnet forks or testnets for Proof of Concept execution.
- 06For Critical severity findings, the security team may arrange direct communication for expedited resolution.
โ IN SCOPE
- โRollup core contracts
- โBridge and inbox contracts
- โFraud proof system
- โSequencer inbox
CRITICAL FUNCTIONS
processIncomingMessages()confirmNode()forceInclusion()HIGH FUNCTIONS
createChallenge()outboxExecute()setSequencer()โ OUT OF SCOPE
- โFrontend explorer
- โArbitrum Nova chain
- โThird-party dApps on Arbitrum
โ Protocol Information
Security Contacts
Bounty program indexed and verified by WhiteClawsProgram data sourced from on-chain analysis and public bounty disclosures.