We’re launching a bug bounty program with Certik for zkThunder, our new zero-knowledge rollup testnet on the Mintlayer network.
This program invites security researchers to identify vulnerabilities in the zkThunder architecture, including its infrastructure, consensus layer, zero-knowledge components, and the smart contracts essential to the network’s operation (excluding user-deployed contracts).
Rewards in ML tokens will be granted based on severity and impact. Help us secure zkThunder before mainnet launch — your expertise is essential to strengthening Bitcoin-native scalability.
Program Overview Mintlayer, in partnership with CertiK, has launched a bug bounty program for zkThunder—its zero-knowledge rollup testnet designed to enhance Bitcoin-native scalability. This initiative aims to identify and mitigate security vulnerabilities within the zkThunder architecture before mainnet deployment. Security researchers are invited to investigate core components, including the consensus layer, infrastructure, zero-knowledge logic, and protocol-level smart contracts. Please note that user-deployed contracts are out of scope.
Reward Structure All submissions are assessed using a 4-tier severity model, with rewards based on the severity and potential impact of each finding. Higher-tier rewards are reserved for vulnerabilities affecting network stability, fund security, or the integrity of core zk components. Rewards are granted at the discretion of the Mintlayer team based on internal evaluation and severity classification.
Submission Requirements Bug reports must include a complete proof of concept (PoC) along with step-by-step instructions demonstrating the vulnerability's real-world impact on in-scope components. Reports that do not include executable code or fail to show end-effect on the network will not qualify for rewards.
Payouts Rewards are denominated in USD-equivalent value and paid in ML, Mintlayer’s native token. All payouts are handled directly by the Mintlayer team after successful validation and KYC compliance.