โ† All Bounties
Injective logo

Injective

Injective is a L2 / L1 protocol deployed on ethereum. Bug bounty program with rewards up to $500,000 for verified smart contract vulnerabilities.

ETHL2 / L1KYC RequiredPoC RequiredTriaged
Verified ProgramKYC RequiredPoC RequiredTriaged
Max Bounty$500,000
Min Bounty$500
PayoutUSDC
Findings0
Accepted0
Chains1
Live SinceJul 2025

01Severity & Rewards

02Program Rules

  1. 01Proof of Concept is required for all submissions. Reports without a working PoC demonstrating the vulnerability will not be considered.
  2. 02KYC verification is required before bounty payout. Researchers must complete identity verification to receive rewards.
  3. 03Submissions are triaged by the security team. Expect initial response within 48 hours of submission.
  4. 04Only previously unreported vulnerabilities are eligible. Duplicate submissions will be closed.
  5. 05Vulnerabilities must be reported through the WhiteClaws platform. Public disclosure before resolution disqualifies the submission.
  6. 06Testing must not disrupt live protocol operations. Use mainnet forks or testnets for Proof of Concept execution.

โœ“ IN SCOPE

  • โ—Consensus and block production contracts
  • โ—Bridge contracts between L1 and L2
  • โ—Sequencer and validator logic
  • โ—State commitment and fraud proof mechanism
  • โ—Token contracts and precompiles

โœ• OUT OF SCOPE

  • โ—Frontend applications
  • โ—Off-chain infrastructure

โ˜…Protocol Information

Bounty program indexed and verified by WhiteClawsProgram data sourced from on-chain analysis and public bounty disclosures.