[TPP-Draft] ZKsync Immunefi Bug Bounty Program 2026

:ballot_box: This proposal passed with a majority of ~986M ZK in-favor of the proposal. See final results here.

Title ZKsync Immunefi Bug Bounty Program 2026
Proposal Type TPP
One Sentence Summary The ZKsync Token Assembly approves $1.6M USD in ZK (80M ZK @ $0.02) to fund the ZKsync bug bounty program on Immunefi for 2026 and $400k USD in ZK (20M ZK @ $0.02)) for bug bounty payouts made in 2025.
Proposal Author ZKsync Security Council
Proposal Sponsor TBD
Date Created February 2026
Version v1.0
Total ZK Requested This proposal grants the minter role to two capped minters totaling 100M ZK to fund the ZKsync Immunefi Bug Bounty program (1) 2026: 80M ZK; and (2) 2025 Retro: 20M ZK
Link to proposal discussion TBA

Summary

This proposal seeks approval to fund the ZKsync bug bounty program on Immunefi with $1,600,000 USD equivalent in ZK tokens (80M ZK) for forward-looking bug bounties, alongside $400,000 USD equivalent in ZK tokens (20M ZK) in reimbursement to Matter Labs for bug bounty payouts made in 2025. The total token request is 100M ZK.

Abstract

ZKsync’s security is critical infrastructure for both the protocol, and the broader ecosystem of ZK Chains. Vulnerabilities in ZKsync core contracts, circuits, tooling, or infrastructure can have cascading effects across ZKsync, ZK Stack deployments, and other ZK chains that rely on ZKsync technology.

The proposal establishes two distinct USD-denominated capped minters, one for forward-looking bug bounty funding and one for a one-time retroactive reimbursement. This structure provides clear scope separation, strong controls, and transparent accounting for a critical ecosystem-wide security function.

This proposal authorizes funding for:

  • Ongoing ZKsync bug bounty rewards administered via Immunefi, and
  • Reimbursement for historical bug bounty payouts made by Matter Labs in 2025.

Motivation

A robust bug bounty program is a critical security measure for ZKsync. Vulnerabilities in ZKsync affect not just a single network, but shared protocol components and tooling used across the ZK ecosystem.

Effective bug bounty programs:

  • Incentivize responsible disclosure over adversarial exploitation
  • Attract highly skilled security researchers to contribute to the protocol
  • Reduce systemic risk before vulnerabilities reach production

The existing Immunefi Bug Bounty program is a critical part of the emergency response procedure. With the Emergency Upgrade Board continuously on standby, upgrades in response to critical submissions are able to be escalated and executed within hours.

Historically, Matter Labs funded bug bounty payouts directly to ensure uninterrupted security coverage while Token Assembly funding mechanisms were still maturing. As ZKsync governance evolves, it is appropriate to:

  • Transition ongoing bug bounty funding into a governance-authorized structure, and
  • Retroactively reimburse prior, verifiable security expenditures that benefited the ecosystem as a whole

This proposal formalizes both objectives while maintaining strict caps, clear accountability, and full transparency.

Specification

This proposal authorizes two USD-denominated capped minters, converted to ZK using a price of 0.02 USD. The capped minters are calculated using a conservative reference price of $0.02 per ZK, ensuring the ZKsync security is prioritized irrespective of market conditions.

If the prevailing market price of ZK is higher at the time of reimbursement, fewer tokens will be minted and any portion of the cap that is not utilized will remain unminted.

1. 2026 Bug Bounty Funding

A capped minter with $1,600,000 USD equivalent (80M ZK @ $0.02) will be granted minting rights to fund future ZKsync bug bounty rewards. The ZKsync Security Council will be the admin, and will work with Immunefi and other ZKsync security maintainers to distribute bounties.

The scope of bounties for this program include the following components where vulnerabilities affect all ZK chains and applications that rely on ZKsync technology:

  • ZKsync protocol contracts
  • ZK Stack components
  • Critical tooling and infrastructure supporting ZKsync-based chains
  • Submissions under SEAL Safe Harbour Agreement passed in GAP 2

ZKsyncBugBounty2026 Capped Minter (Forward-Looking Bug Bounty)

Parameter Value
Name ZKsyncBugBounty2026
Contract Address To be deployed
Admin ZKsync Security Council
Target ZK Token
Value (USD) at deployment $1,600,000
Assumed ZK Price $0.02
Cap (ZK) 80M ZK
Start Time 10 February 2026
End Time 31 December 2026
Minter Role TBC

2. 2025 Bug Bounty Reimbursement

Matter Labs will be granted a capped minter for $400,000 USD (20M ZK @ $0.02) to cover bug bounty payouts made in 2025 on behalf of the ZKsync protocol. This one-time reimbursement will be limited strictly to historical, verifiable bug bounty rewards paid out in the 2025 calendar year.

ZKsyncBugBounty2025Retro Capped Minter (2025 Reimbursement)

Parameter Value
Name ZKsyncBugBounty2025Retro
Contract Address To be deployed
Admin ZKsync Security Council
Target ZK Token
Value (USD) at time of deployment $400,000
Assumed ZK Price $0.02
Cap (ZK) 20M ZK
Start Time 10 February 2026
End Time 31 December 2026
Minter Role TBC

Accountability Framework

  • The ZKsync Security Council reviews and verifies all bug bounty claims and payouts.
  • Conflicts of interest require recusal.
  • All reimbursements under this TPP are publicly documented and verifiable onchain.

Participants

  • ZKsync Security Council: Oversight, verification, and pausing authority on capped minters. Oversight on the ZKsync Immunefi bug bounty program.
  • Matter Labs: Primary day-to-day manager of the Immunefi bug bounty program.

Links

On behalf of Dedaub, we believe that funding the security of ZKsync is crucial for its mission.

A well funded Bug Bounty program provides the appropriate incentives for well-equipped whitehat hackers to independently audit the ecosystem, therefore we are in favor of this proposal.

:high_voltage:[TPP-17] Immunify Bug Bounty Program* was submitted onchain. Pending a 3 day delay, voting for TPP-17 will start on Monday, February 16th at ~17:00 UTC.

:link: Read the full proposal: ZKsync | [TPP-17] ZKsync Immunefi Bug Bounty Program 2026

The following reflects the views of L2BEAT’s governance team, composed of @krst and @Manugotsuka, and it’s based on their combined research, fact-checking, and ideation.

We voted FOR.

We support continuing to fund the ZKsync bug bounty program through a capped and DAO-approved structure. The Immunefi program already defines severity tiers, minimum rewards, and a maximum payout for critical smart contract issues, providing clarity for researchers. We also received confirmation that circuit-level vulnerabilities, proof generation issues, and other ZK-specific risks are within scope, which is appropriate given the protocol’s design.

While we are comfortable with the structure overall, periodic public updates on payouts and remaining allocation would further strengthen transparency and give the DAO clearer visibility into how the program evolves over time.

1 Like