Bug bounty
Triaged by Hackenproof

RISC Zero Blockchain Verifiers: Program info

RISC Zero Blockchain Verifiers

Company: RISC Zero
This program is active now
Program infoHackers (8)Reports

The RISC Zero zkVM is a verifiable computer that works like a real embedded RISC-V micro-processor, enabling programmers to write ZK proofs like they write any other code.

This program covers the RISC Zero blockchain verifiers which provides the onchain verification RISC ZERO zkVM Groth16 proof claims.

In scope
TargetTypeSeverityReward
https://github.com/risc0/risc0-ethereum/tree/main/contracts/src
copy
Copy
success Copied
Smart Contract
Critical
Bounty
Target
https://github.com/risc0/risc0-ethereum/tree/main/contracts/src
copy
Copy
success Copied
TypeSmart Contract
Severity
Critical
RewardBounty

Focus Area

scoping clarification

Only the active version of the RISC Zero managed contract deployed to Ethereum Mainnet and active in the RISC Zero router contract.

This will generally be the same version as deployed on Sepolia and the authoritative source for addresses shall be: contracts/deployment.toml.

The focus of this bounty program shall be inaccurate verification of Groth16 RISC Zero zkVM receipt claims, with invalid claims that successfully verify being considered the most critical. Upstream contract dependencies that impact the security of the RISC Zero contract are considered in scope if exploitable on Ethereum mainnet.

Vulnerabilities related to the RISC Zero zkVM should be submitted to the corresponding Bug Bounty Program.

Payable bounties will require sufficient information for RISC Zero engineers to independently reproduce the results.

Program Rules

  • This program is only scoped to the targets above, RISC Zero web pages, demo applications, or SaaS services are not in scope for this program.
  • Make every effort not to damage or restrict the availability of products, services, or infrastructure
  • Avoid compromising any personal data, interruption, or degradation of any service
  • Perform testing only within the scope
  • Don’t spam forms or account creation flows using automated scanners
  • In case you find chain vulnerabilities we’ll pay only for vulnerability with the highest severity.
  • Don’t break any law and stay in the defined scope
  • Any details of found vulnerabilities must not be communicated to anyone who is not a HackenProof Team or an authorized employee of this Company without appropriate permission

Disclosure Guidelines

  • Do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.
  • No vulnerability disclosure, including partial is allowed for the moment.
  • Please do NOT publish/discuss bugs.

Eligibility and Coordinated Disclosure

  • Employees, consultants, or agents of RISC Zero auditing vendors are inelegible for RISC Zero Bug Bounty Programs.
  • External audits are available for reference only, no bounties shall be paid against audit disclosed issues.
  • You must be the first reporter of a vulnerability.
  • The vulnerability must be a qualifying vulnerability
  • Any vulnerability found must be reported no later than 24 hours after discovery and exclusively through hackenproof.com
  • You must send a clear textual description of the report along with steps to reproduce the issue, include attachments such as screenshots or proof of concept code as necessary.
  • You must not be a former or current employee of us or one of its contractor.
  • ONLY USE the EMAIL under which you registered your HackenProof account (in case of violation, no bounty can be awarded)
  • Provide detailed but to-the point reproduction steps
Rewards
Range of bounty$1,000 - $100,000
Severity
Critical
$0
High
$0
Medium
$0
Low
$0
Stats
Scope Review1583
Submissions18
Total rewards0
Types
blockchain
smart contract
Languages
Solidity
Project types
Other
Hackers (8) View all
cadila909
1
Zakaria eddafry
2
Amin Beheshti
3
kindman
4
ali jaafer
5
SLA (Service Level Agreement)
Time within which the program's triage team must respond
Response TypeBusiness days
First Response5d
Triage Time5d
Reward Time21d
Resolution Time3d