
Optimism
Ethereum Layer 2 scaling solution using optimistic rollups with the OP Stack
OPETHLayer 2KYC RequiredPoC RequiredTriaged
Verified ProgramKYC RequiredPoC RequiredPrimacy of ImpactTriaged
Max Bounty$2,000,042
Min Bounty$1,000
PayoutUSDC
Findings0
Accepted0
Chains2
Live SinceJan 2022
14 Audit Reports Available
2022-11-optimism-securityreview.pdfTrail of Bits
2022-11Optimism-MtCannon-Spearbit-Security-Review-December-2024.pdfSpearbit
2024Optimism-Spearbit-Security-Review-July-2025.pdfSpearbit
2025Optimism-Spearbit-Security-Review-May-2025.pdfSpearbit
2025Optimism-Upgrade-15a-Spearbit-Security-Review-April-2025.pdfSpearbit
2025Optimism-Upgrade13-Spearbit-Security-Review-January-2025.pdfSpearbit
2025Optimism-Verify-Upgrade16-Spearbit-Security-Review-September-2025.pdfSpearbit
20252023-01-optimism-judgingSherlock
2023-012023-03-optimism-judgingSherlock
2023-032024-07-optimism-findingsCode4rena
2024-07Optimism SafetyCheckerConsensys Diligence
2021-03OptimismHacken
Optimism Layer 2 Security Audit OP Labs 27 February 2025 - 01 March 2025Cantina
2025-FebOptimism Cycle 19 Security Review Optimism 22 January 2024 - 05 February 2024Cantina
2024-Jan01Severity & Rewards
02Program Rules
- 01Proof of Concept is required for all submissions. Reports without a working PoC demonstrating the vulnerability will not be considered.
- 02KYC verification is required before bounty payout. Researchers must complete identity verification to receive rewards.
- 03This program follows Primacy of Impact โ valid findings are rewarded based on demonstrated impact regardless of whether the specific attack vector was previously known.
- 04Submissions are triaged by the security team. Expect initial response within 48 hours of submission.
- 05Only previously unreported vulnerabilities are eligible. Duplicate submissions will be closed.
- 06Vulnerabilities must be reported through the WhiteClaws platform. Public disclosure before resolution disqualifies the submission.
- 07Testing must not disrupt live protocol operations. Use mainnet forks or testnets for Proof of Concept execution.
- 08For Critical severity findings, the security team may arrange direct communication for expedited resolution.
โ IN SCOPE
- โOP Stack smart contracts
- โL1 and L2 bridge contracts
- โFault proof system
- โCross-domain messaging
CRITICAL FUNCTIONS
proveWithdrawalTransaction()finalizeWithdrawalTransaction()depositTransaction()HIGH FUNCTIONS
relayMessage()setGasConfig()disputeGame()โ OUT OF SCOPE
- โFrontend explorer
- โOff-chain sequencer
- โThird-party OP Stack chains
โ Protocol Information
Security Contacts
Bounty program indexed and verified by WhiteClawsProgram data sourced from on-chain analysis and public bounty disclosures.