
LayerZero bug bounty on Immunefi: up to $15,000,000
LayerZero pays up to $15,000,000 on Immunefi for critical bugs in its cross chain smart contracts. Live since May 2023, updated October 2026.
The LayerZero bug bounty runs on Immunefi. LayerZero is an omnichain interoperability protocol that lets developers work with contracts across dozens of blockchains. The bounty covers its Solidity smart contracts on Ethereum, BNB Chain, Arbitrum, Optimism, Base and many other chains.
A critical bug on the main chains (Group 1: Ethereum, BNB Chain, Avalanche, Polygon, Arbitrum, Optimism and Fantom) pays at least $250,000 or 10% of the value at risk, whichever is larger, with a hard cap of $15,000,000. On all other chains (Group 2) the minimum is $25,000 and the cap is $1,500,000. High bugs pay up to $250,000, medium up to $25,000 and low up to $10,000.
Critical and high impacts follow Primacy of Impact, so a bug can count even if the affected asset is not listed, as long as the impact is in scope. Impacts on OFT and ONFT contracts are treated as low severity. Testnet and mock files are not covered.
Every report must include a runnable proof of concept. To receive a reward you must complete KYC with an invoice, proof of address and a government ID, and pass OFAC screening. Phishing, denial of service and automated testing that creates heavy traffic are not allowed.
Reports go through the Immunefi page. The program has been live since 17 May 2023, was last updated on 2 October 2026 and has no end date.
Quick answers
How much does it pay?
Up to $15,000,000. It is paid as prizes to the winning entries.
When is the deadline?
There is no fixed deadline. Applications are reviewed as they arrive.
Who can apply?
Security researchers who pass KYC with a government ID and proof of address and pass OFAC screening. Every report needs a runnable proof of concept. Applicants from anywhere in the world can enter, unless the eligibility rules say otherwise.
Is it online or in person?
Online. You can take part from anywhere the rules allow.
How do I apply?
Through the official page at immunefi.com. The link is at the top of this page.
Are known issues from audits paid?
No. Vulnerabilities already listed in the LayerZero Audits repository on GitHub are not eligible for a reward.
Can I test on mainnet?
No. Testing on mainnet or public testnet code is prohibited. Use local forks instead.
How are rewards paid?
LayerZero Labs pays directly in USDC, USDT or BUSD, or in US dollars by wire transfer, at the team's choice.