Skip to main content

Bug Bounty Program with Immunefi

Program overview​

The Lido bug bounty program has operated on Immunefi since May 2021. It helps protect user funds, protocol governance, and the applications and infrastructure that support the protocol.

Researchers can receive rewards of up to $2,000,000. The current assets, impacts, reward levels, and submission requirements are available on the Lido program page on Immunefi.

Program track record​

As of August 19, 2026, the program has:

  • rewarded 43 reports;
  • paid more than $395,000 to security researchers.

These figures use the All Time view in Immunefi program analytics. The payout total is rounded down. A rewarded report is a report recorded as paid in those analytics.

Published security disclosures provide details about findings that are safe to discuss after remediation.

How reports are assessed​

Reports are assessed against their demonstrated impact, reproducibility, and the published program rules. The claimed severity is a starting point; the final assessment depends on the effect that the report can have on the protocol or an in-scope application.

Formal scope keeps expectations clear, but it does not capture every useful security contribution. Contributors have also made discretionary payments for reports outside the formal scope when the work introduced valuable security considerations or new ways to assess risk.

Submit a report​

Review the current scope and submit reports through the Lido program page on Immunefi. Do not disclose a suspected vulnerability publicly before it is resolved and approved for disclosure.