Feed
Bounty Rolling

USDT0 bug bounty on Immunefi

USDT0 pays up to $6,000,000 on Immunefi for critical bugs that break USDT redemptions. The program was last updated September 1, 2026.

The USDT0 bug bounty on Immunefi pays for bugs in the omnichain USDT0 system built on LayerZero's OFT standard. Immunefi shows the program as live since 30 January 2025 and last updated on 1 September 2026. The maximum bounty is $6,000,000.

Critical smart contract reports that affect USDT redemptions on Ethereum, by exploiting the Lockbox on Ethereum or by minting unbacked USDT0 on destination chains, pay 10 percent of the funds directly affected. The cap is $6,000,000 on EVM compatible chains and $1,000,000 on non EVM chains. The minimum critical reward is $50,000. Medium reports pay a flat $5,000. Payouts are denominated in USD and paid in fiat USD by wire, or in USDT and USDT0.

Reports with impacts already covered by the LayerZero bug bounty are forwarded there. For protocol insolvency, the amount at risk is the USDT held in the USDT0 lockbox on Ethereum. KYC is required, including identity, proof of address, and OFAC screening. Official contributors, employees, and auditors who took part in the review are not eligible.

Submit through Immunefi with a proof of concept. Testing must be done on local forks, not on mainnet or public testnets.

Source · immunefi.com/bug-bounty/usdt0 Published 1 September 2026 · Added here 17 September 2026