You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For any discoveries of critical vulnerabilities outside of the scope of the bug bounty program, please also send reports to security@scroll.io.
13
+
</Aside>
14
+
11
15
Scroll treats security as a top priority.
12
16
13
17
Aside from rigorous testing, an internal security team, and comprehensive code reviews, we have also engaged with multiple security audit firms to conduct audits on our codebase. We have also launched a bug bounty program to encourage the community to participate in the security of our protocol.
@@ -17,12 +21,6 @@ Aside from rigorous testing, an internal security team, and comprehensive code r
17
21
exception. We encourage users to use the protocol with caution and at their own risk.
18
22
</Aside>
19
23
20
-
### Scope
21
-
22
-
The scope of the bug bounty program covers the blockchain infrastructure and the smart contracts for bridging and rollup. For a detailed breakdown of bug categories, please refer to the bug bounty page.
23
-
24
-
Besides the listed scopes in the bug bounty program, we also encourage reporting any vulnerabilities identified to Immunefi, which we will still consider for rewards. For any discoveries of critical vulnerabilities outside of the scope of the bug bounty program, please also send reports to security@scroll.io.
25
-
26
24
## Independent Audits
27
25
28
26
Scroll has worked with several industry-leading security audit firms to review our codebase, with critical code receiving reviews from multiple teams, including [Trail of Bits](https://www.trailofbits.com/), [OpenZeppelin](https://www.openzeppelin.com/), [Zellic](https://www.zellic.io/), and [KALOS](https://www.kalos.xyz/).
@@ -79,3 +77,9 @@ Rewards depend on the severity of reported vulnerabilities:
79
77
-**Critical**: up to \$1,000,000
80
78
-**High**: \$10,000 - \$50,000
81
79
-**Medium**: \$5,000
80
+
81
+
### Scope
82
+
83
+
The scope of the bug bounty program covers the blockchain infrastructure and the smart contracts for bridging and rollup. For a detailed breakdown of bug categories, please refer to the bug bounty page.
84
+
85
+
Besides the listed scopes in the bug bounty program, we also encourage reporting any vulnerabilities identified to Immunefi, which we will still consider for rewards.
0 commit comments