EXECUTED
Ended Feb 23 at 4:48 PM UTC

[TPP-17] ZKsync Immunefi Bug Bounty Program 2026

By
Votes
985.63Mfor
1.98Magainst
3.48Mabstain
630MQuorum Reached
Skip to Votes

[TPP-17] ZKsync Immunefi Bug Bounty Program 2026

TitleZKsync Immunefi Bug Bounty Program 2026
Proposal TypeTPP
One Sentence SummaryThe ZKsync Token Assembly approves $1.6M USD in ZK (80M ZK @ $0.02) to fund the ZKsync bug bounty program on Immunefi for 2026 and $400k USD in ZK (20M ZK @ $0.02)) for bug bounty payouts made in 2025.
Proposal AuthorZKsync Security Council
Proposal SponsorCyfrin
Date Created13 February 2026
Versionv1.0
Total ZK Requested100M ZK ($2m USD)
Link to proposal discussionZKsync Forum post
Summary of ActionsGrant minter role to 2 ZK capped minters:<br /> ZKsyncBugBounty2026: 0xc98b9FD0D62514E30c54857A58cc12c94495679D <br /> ZKsyncBugBounty2025Retro: 0x724C33f00eE832c2A4216a6F6986d9C4029849d4

Summary

This proposal seeks approval to fund the ZKsync bug bounty program on Immunefi through two capped minters totalling 100M ZK:

  1. ZKsyncBugBounty2026with $1.6m USD equivalent in ZK tokens (80M ZK) for forward-looking bug bounties; and
  2. ZKsyncBugBounty2025Retrowith $400k USD equivalent in ZK tokens (20M ZK) in reimbursement to Matter Labs for bug bounty payouts made in 2025.

Abstract

ZKsync’s security is critical infrastructure for both the protocol, and the broader ecosystem of ZK Chains. Vulnerabilities in ZKsync core contracts, circuits, tooling, or infrastructure can have cascading effects across ZKsync, ZK Stack deployments, and other ZK chains that rely on ZKsync technology.

The proposal establishes two distinct USD-denominated capped minters, one for forward-looking bug bounty funding and one for a one-time retroactive reimbursement. This structure provides clear scope separation, strong controls, and transparent accounting for a critical ecosystem-wide security function.

This proposal authorizes funding for:

  • Ongoing ZKsync bug bounty rewards administered via Immunefi, and
  • Reimbursement for historical bug bounty payouts made by Matter Labs in 2025.

Motivation

A robust bug bounty program is a critical security measure for ZKsync. Vulnerabilities in ZKsync affect not just a single network, but shared protocol components and tooling used across the ZK ecosystem.

Effective bug bounty programs:

  • Incentivize responsible disclosure over adversarial exploitation
  • Attract highly skilled security researchers to contribute to the protocol
  • Reduce systemic risk before vulnerabilities reach production

The existing Immunefi Bug Bounty program is a critical part of the emergency response procedure. With the Emergency Upgrade Board continuously on standby, upgrades in response to critical submissions are able to be escalated and executed within hours.

Historically, Matter Labs funded bug bounty payouts directly to ensure uninterrupted security coverage while Token Assembly funding mechanisms were still maturing. As ZKsync governance evolves, it is appropriate to:

  • Transition ongoing bug bounty funding into a governance-authorized structure, and
  • Retroactively reimburse prior, verifiable security expenditures that benefited the ecosystem as a whole

This proposal formalizes both objectives while maintaining strict caps, clear accountability, and full transparency.

Specification

This proposal authorizes two USD-denominated capped minters, converted to ZK using a price of 0.02 USD. The capped minters are calculated using a conservative reference price of $0.02 per ZK, ensuring the ZKsync security is prioritized irrespective of market conditions.

If the prevailing market price of ZK is higher at the time of reimbursement, fewer tokens will be minted and any portion of the cap that is not utilized will remain unminted.

Bug Bounty Capped Minter Structure

1. 2026 Bug Bounty Funding

A capped minter with $1,600,000 USD equivalent (80M ZK @ $0.02) will be granted minting rights to fund future ZKsync bug bounty rewards. The ZKsync Security Council will be the admin, and will work with Immunefi and other ZKsync security maintainers to distribute bounties.

The scope of bounties for this program include the following components where vulnerabilities affect all ZK chains and applications that rely on ZKsync technology:

  • ZKsync protocol contracts
  • ZK Stack components
  • Critical tooling and infrastructure supporting ZKsync-based chains
  • Submissions under SEAL Safe Harbour Agreement passed in GAP 2

ZKsyncBugBounty2026 Capped Minter (Forward-Looking Bug Bounty)

ParameterValue
NameZKsyncBugBounty2026
Contract Address0xc98b9FD0D62514E30c54857A58cc12c94495679D
AdminZKsync Security Council 0xfFB6126FF8401665081b771bB11cCD0e09f95D5A
TargetZK Token
Cap (ZK)80M ZK
Start Time16 February 2026
End Time31 December 2026
Minter RoleTo be granted by admin as needed

2. 2025 Bug Bounty Reimbursement

Matter Labs will be granted a capped minter for $400,000 USD (20M ZK @ $0.02) to cover bug bounty payouts made in 2025 on behalf of the ZKsync protocol. This one-time reimbursement will be limited strictly to historical, verifiable bug bounty rewards paid out in the 2025 calendar year.

ZKsyncBugBounty2025Retro Capped Minter (2025 Reimbursement)

ParameterValue
NameZKsyncBugBounty2025Retro
Contract Address0x724C33f00eE832c2A4216a6F6986d9C4029849d4
AdminZKsync Security Council 0xfFB6126FF8401665081b771bB11cCD0e09f95D5A
TargetZK Token
Cap (ZK)20M ZK
Start Time16 February 2026
End Time31 December 2026
Minter RoleMatter Labs Multisig 0xb84cFd9EBA97d991afa2E7B76b900804eE911Ab7

Accountability Framework

  • The ZKsync Security Council reviews and verifies all bug bounty claims and payouts.
  • Conflicts of interest require recusal.
  • All reimbursements under this TPP are publicly documented and verifiable onchain.

Participants

  • ZKsync Security Council: Oversight, verification, and pausing authority on capped minters. Oversight on the ZKsync Immunefi bug bounty program.
  • Matter Labs: Primary day-to-day manager of the Immunefi bug bounty program.

Links

Votes
985.63Mfor
1.98Magainst
3.48Mabstain
630MQuorum Reached

Voters
0xb455...e167Matter Labsvoted for
118.28M
0x1b68...eead0x1b68...eeadvoted for
94.67M
https://forum.zknation.io/t/tpp-draft-zksync-immunefi-bug-bounty-program-2026/903/5
0x0000...59deSyncSwapvoted for
90.46M
62.05M
ZKSync needs a good bug bounty and Immunefi are one of the best.
57.99M
0xc118...ad2cCyfrinvoted for
57.35M
0x3fb1...4c8a0x3fb1...4c8avoted for
56.32M
0xdedd...360dKeatingvoted for
55.75M
0x1f76...5ed60x1f76...5ed6voted for
51.18M
0x0fbb...5881Moonsong Labsvoted for
50.01M
0xe8d8...3f310xe8d8...3f31voted for
42.11M
40.76M
0x3ae5...3b3c0x3ae5...3b3cvoted for
28.79M
0xe452...b835Spearbitvoted for
28.18M
0xefd6...20340xefd6...2034voted for
24.24M
0xbe1d...c9530xbe1d...c953voted for
23.91M
0xbe97...1b760xbe97...1b76voted for
19.67M
0x09fa...3bb0Demaciavoted for
16.36M
0xc639...915dInes txFusionvoted for
14.8M
0x2198...6ee60x2198...6ee6voted for
13.51M
0xb14d...1f9a0xb14d...1f9avoted for
8.58M
0xa408...6a090xa408...6a09voted for
3.41M
0x2596...6fc50x2596...6fc5abstained
3.34M
0xeb40...2ee70xeb40...2ee7voted for
1.6M
0x83cc...0b7c0x83cc...0b7cvoted against
1.28M
0xbec6...c51c0xbec6...c51cvoted for
1.25M
0x0542...43e10x0542...43e1voted for
1.16M
it's still crazy to me this is 1% of mcap...
0x1729...b8790x1729...b879voted for
946.65K
0x5419...35180x5419...3518voted for
813.39K
0x25cc...038a0x25cc...038avoted for
803.37K
0x1bc9...33ca0x1bc9...33cavoted for
569.49K
0x5212...17b30x5212...17b3voted for
400.98K
0x09cd...74b50x09cd...74b5voted for
400.78K
0xcd0d...07d70xcd0d...07d7voted against
290.51K
0xb356...c8260xb356...c826voted for
269.64K
The Event Horizon Community voted FOR on this Proposal (ehZKS-24): EventHorizon.vote/vote/zksync/ehZKS-24
0x00df...49e80x00df...49e8voted against
253.32K
0x22e2...83750x22e2...8375voted for
240.65K
0xab9c...c17f0xab9c...c17fvoted for
235.96K
0x231d...a7640x231d...a764voted for
200K
0xc2be...2cbc0xc2be...2cbcvoted for
200K
0x6609...79c10x6609...79c1voted for
191.62K
0xffa1...11b20xffa1...11b2voted for
182.9K
0x59a9...ac020x59a9...ac02voted for
167.16K
0x1b1e...40110x1b1e...4011voted for
158.3K
0x2f2f...f78a0x2f2f...f78avoted for
155.19K
0xaa58...42610xaa58...4261voted for
151.99K
0x00a7...5f480x00a7...5f48voted for
145.59K
0x0991...c26a0x0991...c26avoted for
145.14K
0x8c57...a7a10x8c57...a7a1voted for
142.94K
0xf0c2...b8aa0xf0c2...b8aavoted for
130.36K
Bugs are bad
0xc640...c0c30xc640...c0c3voted for
129.79K
0xeab8...62d10xeab8...62d1voted for
128.77K
0xed32...6fcd0xed32...6fcdvoted for
125.7K
0x9c52...2a550x9c52...2a55voted for
123.84K
0x9fb8...a7d60x9fb8...a7d6voted for
108.71K
0xe6f9...87be0xe6f9...87bevoted for
102.43K
0x3062...b7740x3062...b774voted for
97.15K
0x9816...e53d0x9816...e53dvoted for
95.18K
0x0e29...2bdf0x0e29...2bdfvoted for
88.97K
0x4494...236b0x4494...236bvoted for
69.4K
0x92c4...f8e60x92c4...f8e6voted for
67.02K
0xe93d...e2b50xe93d...e2b5voted for
66.81K
0x4d32...bbfa0x4d32...bbfavoted for
65.86K
0x8c57...0f610x8c57...0f61voted for
63.69K
0xef45...1f6a0xef45...1f6avoted for
61.75K
0x1307...b54e0x1307...b54evoted for
59.15K
0x01a6...763e0x01a6...763evoted for
58.35K
0xfe50...42f40xfe50...42f4voted for
56.88K
0x0253...d11a0x0253...d11avoted for
53.26K
0xc68d...04030xc68d...0403voted for
50K
0xaea3...9f710xaea3...9f71voted for
48.91K
Bug Bounty is a must have for every serious organization in crypto.
0x1082...e1470x1082...e147voted for
46K
0xb529...94030xb529...9403voted for
45.28K
0xb360...28bd0xb360...28bdvoted for
44.02K
0x735a...8abf0x735a...8abfvoted for
40.81K
0xd483...84e50xd483...84e5voted for
40.14K
0x1005...32a20x1005...32a2voted for
40.09K
0x168f...74000x168f...7400voted for
38.59K
0xd525...14190xd525...1419voted for
37.24K
0x0dcd...8c800x0dcd...8c80abstained
37.24K
0x14b8...7b480x14b8...7b48voted for
35.79K
0xf8e6...1c0a0xf8e6...1c0avoted for
33.9K
0x1539...eb960x1539...eb96voted for
32.09K
0x66e1...29a80x66e1...29a8voted for
31.73K
0x3778...e48a0x3778...e48avoted for
30.47K
0xf256...a57a0xf256...a57avoted for
29.87K
0xd02e...d18b0xd02e...d18bvoted for
29.46K
0xe4e0...27670xe4e0...2767voted for
25.44K
0x25b6...02960x25b6...0296voted for
24.3K
0xbe7a...b9ba0xbe7a...b9bavoted for
23.74K
0x4166...b7e00x4166...b7e0voted for
22.4K
0x9087...47ea0x9087...47eavoted for
21.55K
0x638b...f3a80x638b...f3a8voted for
20.98K
0xb208...97870xb208...9787voted for
20.46K
0xdb57...bc2e0xdb57...bc2evoted for
20.44K
0xd6b8...9b800xd6b8...9b80voted against
20K
0x61df...7c1e0x61df...7c1evoted against
19.12K
0xf882...f1be0xf882...f1bevoted against
19.01K
0x13a4...21230x13a4...2123voted for
16.29K
0x19f1...11380x19f1...1138voted for
15.66K
0xb068...10a50xb068...10a5voted for
15.4K
0x3037...a9dd0x3037...a9ddvoted for
15.23K
0x0be3...2a0c0x0be3...2a0cvoted for
14.93K
0x8458...176f0x8458...176fabstained
14.81K
0x1fd4...14dd0x1fd4...14ddvoted for
14.69K
0x4b75...5a810x4b75...5a81abstained
14.57K
0xa49f...6c070xa49f...6c07voted for
14.37K
De acuerdo.
0xfc74...4c7c0xfc74...4c7cvoted for
14.01K
0x7f55...49490x7f55...4949voted for
13.32K
0x3ddc...05b00x3ddc...05b0voted for
12.99K
0xd91e...f3b40xd91e...f3b4abstained
12.63K
0x7c6b...7bb60x7c6b...7bb6voted for
12.58K
0x4cb7...7cd50x4cb7...7cd5voted for
12.5K
0x8e56...c5690x8e56...c569voted for
12.03K
0xaf91...b93a0xaf91...b93avoted for
11.27K
0xc4f5...9dac0xc4f5...9dacvoted for
11.27K
0xe321...321a0xe321...321avoted for
11.02K
0xadcf...79390xadcf...7939voted for
10.91K
0xf24b...47290xf24b...4729voted for
10.38K
0xd0d0...1dc50xd0d0...1dc5voted for
10.08K
0x407d...99aa0x407d...99aavoted for
10.08K
0x8a52...0dd30x8a52...0dd3voted for
10.02K
0x9b8f...e7e10x9b8f...e7e1voted for
10.01K
0x01b8...45ad0x01b8...45adabstained
9.99K
0x3f05...1a770x3f05...1a77voted for
9.89K
0xdc4a...54320xdc4a...5432voted against
9.87K
0xfacc...fb6d0xfacc...fb6dvoted for
9.83K
0x0875...f9b10x0875...f9b1voted for
9.75K
0xa8cb...690e0xa8cb...690evoted for
9.71K
0x1e74...2a900x1e74...2a90abstained
9.63K
0x4039...64d80x4039...64d8voted for
9.38K
0xcc4f...baa50xcc4f...baa5abstained
9.3K
0x0b1c...15210x0b1c...1521voted against
9.09K
0x2c36...db870x2c36...db87voted against
9.06K
0x51dc...98990x51dc...9899voted for
8.8K
0x195f...cd9d0x195f...cd9dvoted against
8.68K
mvkck f,flr f,e[e
0x3aaf...2ecc0x3aaf...2eccvoted for
8.53K
0x05bd...55bf0x05bd...55bfvoted for
8.24K
0xcecd...46e10xcecd...46e1voted for
7.94K
0x2623...86890x2623...8689voted for
7.83K
0xbf39...8a190xbf39...8a19voted for
7.58K
0x01fe...7a7d0x01fe...7a7dvoted for
7.55K
0xeb22...bc580xeb22...bc58voted for
7.48K
0xb941...0b870xb941...0b87voted against
7.32K
0xab1d...06380xab1d...0638voted for
7.31K
0x952c...044e0x952c...044evoted for
7.16K
0x279a...dbea0x279a...dbeavoted for
7.05K
0x04af...f5ee0x04af...f5eevoted for
7.02K
0x261e...7f930x261e...7f93voted for
6.95K
0x8b3c...43c30x8b3c...43c3voted for
6.9K
0xa0ef...2d560xa0ef...2d56voted for
6.86K
0x4602...3c4a0x4602...3c4avoted against
6.76K
0x9081...6fb70x9081...6fb7voted against
6.58K
0xafe1...d8720xafe1...d872voted for
6.52K
0xfe8c...77450xfe8c...7745abstained
6.48K
0x8ae0...7a560x8ae0...7a56voted for
6.44K
0xdcc9...04f00xdcc9...04f0voted for
6.39K
0xcf7f...92770xcf7f...9277voted for
6.27K
0xf757...a5070xf757...a507voted for
6.2K
0xe992...d6200xe992...d620voted for
6.14K
0x0d65...35b70x0d65...35b7voted for
6.1K
0xc907...95060xc907...9506voted for
6.03K
0x24e5...cac60x24e5...cac6voted for
5.95K
0x93ef...bbff0x93ef...bbffvoted for
5.92K
0xf187...5bae0xf187...5baevoted for
5.89K
0xf5bb...9f7e0xf5bb...9f7evoted for
5.86K
0xf47d...3dde0xf47d...3ddevoted for
5.83K
0xd428...c0340xd428...c034voted for
5.69K
0xbc97...f4ff0xbc97...f4ffvoted for
5.22K
0x0c5e...63dd0x0c5e...63ddvoted for
5.17K
0x5249...17cc0x5249...17ccvoted for
5.16K
0xcd0d...11680xcd0d...1168voted for
5.08K
0xa09e...e8c70xa09e...e8c7voted for
5.06K
0x2e7e...7b240x2e7e...7b24voted against
5K
0xd5ec...118e0xd5ec...118evoted against
5K
0xd647...4a300xd647...4a30voted for
5K
0xbb98...8e0c0xbb98...8e0cvoted for
5K