Security Disclosure
Report a vulnerability
We work with security researchers to keep the Livepeer network and its surrounding services safe. Two channels, depending on what you've found.
Reporting Channels
Where to send your report
Pick the channel that matches what you found — the right one gets a faster response.
01 — Protocol
Smart contracts & on-chain protocol
On-chain protocol issues — contracts, staking, delegation, reward logic — handled on Immunefi with cash bounties scaled by severity.
- Cash bounties scaled by severity (Immunefi tiers)
- Triage and response handled on-platform
- Coordinated disclosure timelines
02 — Non-protocol
Web, explorer & developer services
Issues in this website, the explorer, or Foundation-operated developer services. Reports are recognized through public acknowledgment. This is an informal program and terms may evolve.
- Safe harbor for good-faith research
- Public acknowledgment of valid reports
- We aim to respond within 5 business days
Scope
What this program covers
Email scope is limited to Foundation-operated services. Anything else routes elsewhere.
In scope
- livepeer.org (this website)
- explorer.livepeer.org
- Developer dashboard & gateway services
Out of scope
- Smart contracts & on-chain protocolReport via Immunefi
- Livepeer Inc-operated products and subdomains
Includes
livepeer.studio,livepeer.monster, and any*.livepeer.orgsubdomain not listed as in-scope above. Contact security@livepeer.org. - Third-party products built on LivepeerContact the operator
- Already-reported issues, social engineering, DoS / volumetric attacks
Writing a Report
What to include
Short but complete. The clearer the repro, the faster the fix.
01
Description & impact
What the issue is, what an attacker could achieve, and which users or systems are affected.
02
Steps to reproduce
Clear, minimal steps. Include URLs, payloads, request/response samples, or a short PoC.
03
Environment
Browser, OS, account or wallet state, and the date / commit hash if you can identify it.
04
Suggested fix (optional)
If you have a remediation idea, share it — it's appreciated, not required.
Safe Harbor
Researching in good faith
Good-faith research that follows this policy is authorized. We won't pursue legal action, and we'll work with you to resolve the issue. Safe harbor applies only to systems listed as in-scope above — the Foundation cannot grant safe harbor over systems it does not operate.
Good faith means: don't exfiltrate user data beyond what proves impact, don't degrade service, don't disclose publicly for at least 90 days after reporting (or until we've fixed and acknowledged the issue, whichever is sooner), and don't use the finding for anything other than the report.
Adapted from the disclose.io Core Terms.
Eligibility & Award Terms
Program rules
- 01
Discretionary
Acknowledgment and any other recognition are at the Foundation's sole discretion. Submission does not entitle you to compensation.
- 02
License to remediate
By submitting a report, you grant the Foundation a perpetual, royalty-free license to use its contents to investigate and fix the issue.
- 03
No relationship
Participation does not create an employment, agency, or partnership relationship with the Foundation.
- 04
Program changes
The Foundation may modify or end the program at any time. Reports are evaluated under the rules in effect when submitted.
Smart contract reports are governed by the Immunefi program rules, not these terms.
Found something? Thank you.
Researchers who help keep the network safe make the whole ecosystem stronger.