Feed
Bounty Rolling

ENS bug bounty on Immunefi: up to $250,000

ENS pays security researchers up to $250,000 for critical smart contract bugs. The bounty runs on Immunefi with no closing date.

The ENS bug bounty program pays security researchers for vulnerabilities in the Ethereum Name Service contracts. It runs on Immunefi and has been live since 10 May 2024. The program page was last updated on 27 August 2026.

Rewards follow the severity of the finding. A critical smart contract report pays up to $250,000, set at 10 percent of the funds affected. A high report pays $25,000 to $100,000. A medium report pays a flat $10,000 and a low report a flat $2,500. Ten assets are in scope.

Rewards are paid in USDC on Ethereum and denominated in US dollars. The conversion rate is the average price between CoinMarketCap and CoinGecko at the time the report was submitted. KYC is generally not required.

A proof of concept is mandatory for all severity levels, so a report has to show the bug working, not only describe it. Reports go through the Immunefi program page.

Source · immunefi.com/bug-bounty/ens/information Published 27 August 2026 · Added here 18 September 2026