โ† All Bounties
Chainlink logo

Chainlink

Decentralized oracle network providing tamper-proof data feeds for smart contracts

ETHARBOPMATICBSCBaseInfrastructureKYC RequiredPoC Required
Verified ProgramKYC RequiredPoC RequiredPrimacy of Impact
Max Bounty$3,000,000
Min Bounty$1,000
PayoutUSDC
Findings0
Accepted0
Chains6
Live SinceMay 2021

01Severity & Rewards

02Program Rules

  1. 01Proof of Concept is required for all submissions. Reports without a working PoC demonstrating the vulnerability will not be considered.
  2. 02KYC verification is required before bounty payout. Researchers must complete identity verification to receive rewards.
  3. 03This program follows Primacy of Impact โ€” valid findings are rewarded based on demonstrated impact regardless of whether the specific attack vector was previously known.
  4. 04Only previously unreported vulnerabilities are eligible. Duplicate submissions will be closed.
  5. 05Vulnerabilities must be reported through the WhiteClaws platform. Public disclosure before resolution disqualifies the submission.
  6. 06Testing must not disrupt live protocol operations. Use mainnet forks or testnets for Proof of Concept execution.
  7. 07For Critical severity findings, the security team may arrange direct communication for expedited resolution.

โœ“ IN SCOPE

  • โ—Price feed aggregator contracts
  • โ—CCIP cross-chain protocol
  • โ—VRF v2 contracts
  • โ—Automation (Keepers) contracts
CRITICAL FUNCTIONS
transmit()latestRoundData()ccipSend()
HIGH FUNCTIONS
requestRandomWords()performUpkeep()setConfig()

โœ• OUT OF SCOPE

  • โ—Frontend applications
  • โ—Off-chain node software
  • โ—Third-party oracle consumers

โ˜…Protocol Information

Audited By
Cyfrin
Immunefi
Bounty program indexed and verified by WhiteClawsProgram data sourced from on-chain analysis and public bounty disclosures.