Stacks is a Bitcoin Layer 2 blockchain ecosystem that enables smart contracts and decentralized applications to use Bitcoin as a secure base layer. The Stacks Bug Bounties program on Immunefi is a continuous, perpetual initiative designed to secure core components like the Clarity VM, POX contract, node implementations, and sBTC. Security researchers are invited to find and responsibly disclose vulnerabilities across these critical assets. Participants can earn tiered rewards paid in STX, ranging up to $250,000 for critical findings, based on the severity and impact of the reported vulnerability.
To participate in the Stacks Bug Bounty program, security researchers must first review the comprehensive program details, scope, and rules outlined on the official Immunefi page. It is crucial to understand the strictly defined assets and impacts in scope, such as the Clarity VM and sBTC, while avoiding duplicate reports by checking open pull requests and issues on the stacks-core GitHub repository.
Testing must be exclusively conducted on private or local testnets and forks, as interacting with mainnet or public testnets is strictly prohibited. Once a vulnerability is discovered, researchers need to prepare a detailed bug report accompanied by a functional Proof-of-Concept (PoC) and submit it through the dedicated Immunefi form. Successful payouts are handled directly by the Stacks Endowment team in STX and require the participant to complete full KYC verification in compliance with AML and OFAC regulations.
Review the full program scope, rules, and out-of-scope items on the Immunefi page.
Create an account or log in to the Immunefi platform.
Conduct all security testing exclusively on private testnets or local forks.
Prepare a comprehensive bug report with a required functional Proof-of-Concept (PoC).
Submit the report via the dedicated Immunefi submission dashboard.
Complete the mandatory KYC verification process to be eligible for payouts.
Await triage and validation by the Immunefi and Stacks teams for STX reward distribution.