Feed
Bounty Rolling

Lombard Finance bug bounty on Immunefi

Lombard Finance pays up to $250,000 for critical smart contract bugs through its Immunefi bounty. Open year round, terms updated September 10, 2026.

The Lombard Finance bug bounty on Immunefi pays security researchers for vulnerabilities in the protocol's smart contracts and web applications. The program launched on September 4, 2024 and its scope and terms were last updated on September 10, 2026.

Smart contract findings pay up to $250,000 for critical issues, with a minimum of $50,000. High severity findings pay between $10,000 and $50,000. Medium findings pay a flat $2,500 and low findings a flat $1,000. For web and app findings, critical issues pay $15,000 to $30,000, high issues a flat $10,000 and medium issues a flat $2,000.

The scope lists 52 assets covering the protocol's Bitcoin and DeFi smart contracts. The full list is on the scope page of the program.

A proof of concept is required for every severity level. KYC is required before a payout. Testing on mainnet or on public testnets is not allowed; all testing must be done on local forks. Immunefi's standard eligibility rules and list of prohibited activities apply.

Payouts are handled by the Lombard team, are denominated in USD and are paid in USDC on Ethereum. The price is calculated from the average of CoinMarketCap and CoinGecko at the time the report was submitted.

Source · immunefi.com/bug-bounty/lombard-finance/information Published 10 September 2026 · Added here 11 September 2026