Ethereum Foundation Launches $2M Bug Bounty Competition to Secure Fusaka Upgrade

16-Sep-2025

TL;DR

  • Security Incentive: Ethereum Foundation launches a $2M bug bounty to audit Fusaka’s codebase, offering tiered rewards to encourage early and thorough vulnerability discovery.
  • Technical Rollout: Fusaka will deploy across Holesky, Sepolia, and Hoodi testnets before any mainnet activation, pending stability confirmation.
  • Community Debate: Experts raise concerns about auditing timing, as bugs continue to surface on Fusaka’s devnets.

The Ethereum Foundation (EF) has announced a $2 million bug bounty competition aimed at fortifying the upcoming Fusaka upgrade. Launched on September 15, the initiative invites global security researchers to audit Fusaka’s codebase and uncover vulnerabilities before its deployment. The contest reflects Ethereum’s commitment to transparency and community-driven development, even as concerns linger over the upgrade’s readiness.

Time-Sensitive Contest Structure

The four-week competition will run from September 15 to October 13 on the Sherlock testnet. To incentivize early participation, EF has introduced a tiered reward system: findings submitted in the first week earn double points, while second-week submissions receive a 1.5x multiplier. This structure is designed to maximize scrutiny during the most critical phases of Fusaka’s development. EF emphasized that the timing aligns with its goal of ensuring robust security coverage before the upgrade reaches mainnet.

Ecosystem-Wide Support

The bounty program has attracted notable co-sponsors, including Gnosis and Lido, who contributed $100,000 and $25,000, respectively. Their involvement underscores the broader Ethereum ecosystem’s investment in Fusaka’s success. EF stated that every layer of security benefits not only developers and validators but also end users who rely on Ethereum’s infrastructure. The collaborative funding model signals a shared responsibility for safeguarding the network’s future.

Ethereum Foundation Launches $2M Bug Bounty Competition to Secure Fusaka Upgrade

Technical Enhancements and Rollout Plan

Fusaka introduces several key improvements aimed at boosting scalability and transaction throughput. Among its features are Peer Data Availability Sampling (PeerDAS) for streamlined data distribution, revised gas limits to enhance performance, and refined blob parameters to accommodate higher transaction volumes. Despite these advancements, the upgrade has faced delays and technical hurdles. Developers clarified during the latest All Core Devs call that Fusaka’s mainnet activation date remains undecided, contingent on successful testnet deployments.

Community Concerns and Developer Response

While the bounty signals proactive security measures, some experts question the timing. Christine Kim, former VP of research at Galaxy Digital, expressed concern about launching an audit while bugs are still being discovered on Fusaka’s devnets. In response, Ethereum developers reaffirmed their commitment to a cautious rollout. The upgrade is scheduled for Holesky on September 29, Sepolia on October 13, and Hoodi on October 27. Mainnet activation will proceed only after all testnets are upgraded and Devnet-5 analysis confirms network stability.

Also read: Santander’s Openbank to Expand Crypto Trading Services Across Europe
WHAT'S YOUR OPINION?
Related News