Bug bounties
Crowdsourced review
Bug bounties: Crowdsourced review. Layer: Deployed system. Characteristic finds: Whatever survived everything else, on the code actually running. Blind to: Everything, until someone looks — no pre-launch assurance. Coverage claim: None. Cost profile: Contingent; needs credible max payout. Maintained by: Run by the deploying team, usually on a bounty platform; the linked ZKsync Era programme is one example of a published ZK scope, not a recommendation. Choose it when: Every production system, funded proportionally to value at risk and live from mainnet day one. State explicitly whether circuits, prover, verifier contract and setup artefacts are in scope.
What it is
An open-ended funded programme covering deployed code, with published severity classification and reward scale. The better ZK programmes state explicitly whether circuits, prover, verifier contract and setup artefacts are in scope, whether completeness failures (valid inputs rejected, funds stuck) count alongside soundness failures, and what proof of concept is required at each severity.
Strengths and tradeoffs
- The only mechanism covering the code you actually run, indefinitely, after every deployment
- Attracts specialists, including tool authors running new techniques against live targets
- Cost is contingent on findings rather than fixed
- Establishes a legitimate disclosure channel, reducing the chance a finder goes public instead
- No assurance before launch and no coverage guarantee ever
- An underfunded maximum payout is a negative signal for a system securing large value
- Scope must be drafted carefully: proof forgery for arbitrary statements must be unambiguously critical
- Demands 24/7 triage and a rehearsed emergency response
Choose it whenEvery production system, funded proportionally to value at risk and live from mainnet day one. State explicitly whether circuits, prover, verifier contract and setup artefacts are in scope.
Related pages
Sources cited on this page · 5
- 0xPARC ZK Bug Tracker — bug taxonomy (frozen since late 2024; Circom/application-circuit skew)reference
- On formal verification and a bug in SP1 Hypercube — a JALR conformance bug found by RISC-V architecture tests outside the verified scope (EF zkEVM)analysis
- Missing subfield membership check in OpenVM pairing — CVE-2026-46669disclosure
- It pays to be Circomspect — motivation and bug classes (Trail of Bits)analysis
- Arguzz — testing zkVMs for soundness and completeness bugs (USENIX Security '26)paper
All 48 sources for §03 are listed on the section page →
Cite this page
MarketComp (2026). Bug bounties. The ZK Field Manual (Version 1.3). MarketComp. https://zkpick.com/audit/bug-bounties/
@misc{zkfieldmanual-bug-bounties,
title = {Bug bounties — The ZK Field Manual},
author = {MarketComp},
year = {2026},
version = {1.3},
howpublished = {\url{https://zkpick.com/audit/bug-bounties/}},
note = {Accessed: YYYY-MM-DD}
}