Bounty Rolling

Horizen bug bounty on Immunefi

Horizen pays up to $10,000 in USDC for bugs in its ZEN staking contracts and staking web app, through Immunefi. Open on a rolling basis.

The Horizen bug bounty on Immunefi pays security researchers for bugs in the official ZEN staking program. The scope is the ZenStaker smart contracts and the staking web application. Horizen describes itself as a privacy first OP Stack L3 that settles to Base. The program has been live since 15 July 2026 and was last updated on 24 September 2026.

Rewards are paid in USDC on Ethereum and are denominated in USD. A critical smart contract bug that affects staked principal pays 10% of the funds directly affected, up to $10,000, with a minimum of $5,000. A critical bug limited to the reward buffer contract pays a flat $3,000, and a high smart contract bug also pays a flat $3,000. For the website and app, a critical bug pays $3,000 and a high bug pays $1,000.

A runnable proof of concept is required. Exploit transactions must never be broadcast to the Horizen mainnet or testnet; the network details on the page are for local forking only. Reporters must complete identity verification before a bounty is paid.

Reports go through the Submit a Bug button on the Immunefi program page. The page lists earlier audits of the staking code by Trail of Bits, Code4rena, Cantina, Sherlock and Offbeat Security.

Source · immunefi.com/bug-bounty/horizen/information Published 24 September 2026 · Added here 5 October 2026

Quick answers

How much does it pay?

Up to $10,000. It is paid as prizes to the winning entries.

When is the deadline?

There is no fixed deadline. Applications are reviewed as they arrive.

Who can apply?

Security researchers. A runnable proof of concept is required, and KYC must be completed before a bounty is paid. Applicants from anywhere in the world can enter, unless the eligibility rules say otherwise.

How do I apply?

Through the official page at immunefi.com. The link is at the top of this page.