Skip to content

Commit eaa7858

Browse files
committed
security nit
1 parent 7dc2fbe commit eaa7858

File tree

1 file changed

+6
-6
lines changed

1 file changed

+6
-6
lines changed

src/content/docs/en/technology/security/audits-and-bug-bounty.mdx

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,12 @@ Aside from rigorous testing, an internal security team, and comprehensive code r
1717
exception. We encourage users to use the protocol with caution and at their own risk.
1818
</Aside>
1919

20+
### Scope
21+
22+
The scope of the bug bounty program covers the blockchain infrastructure and the smart contracts for bridging and rollup. For a detailed breakdown of bug categories, please refer to the bug bounty page.
23+
24+
Besides the listed scopes in the bug bounty program, we also encourage reporting any vulnerabilities identified to Immunefi, which we will still consider for rewards. For any discoveries of critical vulnerabilities outside of the scope of the bug bounty program, please also send reports to [email protected].
25+
2026
## Independent Audits
2127

2228
Scroll has worked with several industry-leading security audit firms to review our codebase, with critical code receiving reviews from multiple teams, including [Trail of Bits](https://www.trailofbits.com/), [OpenZeppelin](https://www.openzeppelin.com/), [Zellic](https://www.zellic.io/), and [KALOS](https://www.kalos.xyz/).
@@ -73,9 +79,3 @@ Rewards depend on the severity of reported vulnerabilities:
7379
- **Critical**: up to \$1,000,000
7480
- **High**: \$10,000 - \$50,000
7581
- **Medium**: \$5,000
76-
77-
### Scope
78-
79-
The scope of the bug bounty program covers the blockchain infrastructure and the smart contracts for bridging and rollup. For a detailed breakdown of bug categories, please refer to the bug bounty page.
80-
81-
Besides the listed scopes in the bug bounty program, we also encourage reporting any vulnerabilities identified to Immunefi, which we will still consider for rewards. For any discoveries of critical vulnerabilities outside of the scope of the bug bounty program, please also send reports to [email protected].

0 commit comments

Comments
 (0)