Security Disclosure

Report a vulnerability

We work with security researchers to keep the Livepeer network and its surrounding services safe. Two channels, depending on what you've found.

Reporting Channels

Where to send your report

Pick the channel that matches what you found — the right one gets a faster response.

01 — Protocol

Smart contracts & on-chain protocol

On-chain protocol issues — contracts, staking, delegation, reward logic — handled on Immunefi with cash bounties scaled by severity.

  • Cash bounties scaled by severity (Immunefi tiers)
  • Triage and response handled on-platform
  • Coordinated disclosure timelines

02 — Non-protocol

Web, explorer & developer services

Issues in this website, the explorer, or Foundation-operated developer services. Reports are recognized through public acknowledgment. This is an informal program and terms may evolve.

  • Safe harbor for good-faith research
  • Public acknowledgment of valid reports
  • We aim to respond within 5 business days

Scope

What this program covers

Email scope is limited to Foundation-operated services. Anything else routes elsewhere.

In scope

  • livepeer.org (this website)
  • explorer.livepeer.org
  • Developer dashboard & gateway services

Out of scope

  • Smart contracts & on-chain protocolReport via Immunefi
  • Livepeer Inc-operated products and subdomains

    Includes livepeer.studio, livepeer.monster, and any *.livepeer.org subdomain not listed as in-scope above. Contact security@livepeer.org.

  • Third-party products built on LivepeerContact the operator
  • Already-reported issues, social engineering, DoS / volumetric attacks

Writing a Report

What to include

Short but complete. The clearer the repro, the faster the fix.

01

Description & impact

What the issue is, what an attacker could achieve, and which users or systems are affected.

02

Steps to reproduce

Clear, minimal steps. Include URLs, payloads, request/response samples, or a short PoC.

03

Environment

Browser, OS, account or wallet state, and the date / commit hash if you can identify it.

04

Suggested fix (optional)

If you have a remediation idea, share it — it's appreciated, not required.

Safe Harbor

Researching in good faith

Good-faith research that follows this policy is authorized. We won't pursue legal action, and we'll work with you to resolve the issue. Safe harbor applies only to systems listed as in-scope above — the Foundation cannot grant safe harbor over systems it does not operate.

Good faith means: don't exfiltrate user data beyond what proves impact, don't degrade service, don't disclose publicly for at least 90 days after reporting (or until we've fixed and acknowledged the issue, whichever is sooner), and don't use the finding for anything other than the report.

Adapted from the disclose.io Core Terms.

Eligibility & Award Terms

Program rules

  1. 01

    Discretionary

    Acknowledgment and any other recognition are at the Foundation's sole discretion. Submission does not entitle you to compensation.

  2. 02

    License to remediate

    By submitting a report, you grant the Foundation a perpetual, royalty-free license to use its contents to investigate and fix the issue.

  3. 03

    No relationship

    Participation does not create an employment, agency, or partnership relationship with the Foundation.

  4. 04

    Program changes

    The Foundation may modify or end the program at any time. Reports are evaluated under the rules in effect when submitted.

Smart contract reports are governed by the Immunefi program rules, not these terms.

Found something? Thank you.

Researchers who help keep the network safe make the whole ecosystem stronger.