Everything is understandable, the only thing is, immunefi at this point need to update their policy, if an issue is known no matter, it should be out of scope, or disclosed to whitehats, if afraid this could lead to a blackhat taking advantage, fix it first before publishing it for any Bug bounty. Transparency is key here.
@immunefi you are not at fault due to your policy, but transparency is key for whitehats, make sure you ask projectto provide as much information as they could and any information not included or transparent to immunefi in the projects' " Information" section, it will be marked a valid finding and shouldbe paid for. It's very painful after a whitehat takes his time and effort only to end up with an out of scope or known issue.
Immunefi Statement on the Scroll Vulnerability Report
Technical Review
Following a comprehensive technical review, we would like to clarify our position regarding the recent vulnerability submission related to the Scroll network.
The Scroll network was technically vulnerable at the time of the report, but it is important to emphasize that the responsibility of addressing or resolving such issues that projects are already aware of on a particular timeline ultimately rests with the project team. In this instance, the Scroll team was already aware of the concerns related to the CCC component, having received several similar submissions in the past. In response to the latest submission, they had chosen not to patch the existing code but instead to address the issue through a complete redesign of the underlying mechanism—an effort that was already underway prior to this latest report as part of their upcoming Euclid upgrade.
This intent was substantiated by a publicly available pull request submitted in December 2024—three months before the whitehat’s submission—demonstrating that the refactoring of vulnerable mechanisms was already in development at that time.
During the mediation process, we carefully reviewed the perspectives of both the whitehat and the Scroll team. We concluded that the reported vulnerability is indeed technically valid, in-scope, has a severity of High, and was reproducible within the existing codebase.
However, since the affected component is part of a soon-to-be-deprecated system that will be retired with the Euclid upgrade, and since work on the replacement mechanism was already in progress prior to the submission, we determined that the report does not meet the criteria for a bounty under Immunefi’s program rules.
It is also important to note that Scroll had previously acknowledged similar vulnerabilities originating from the same component and resulting in the same impact as this submission, despite the unique attack method described. As part of their security posture, they opted for a long-term architectural fix over a temporary patch, given the broader problems with the component.
Commitment to Continued Dialogue
We remain open to continued engagement. If any whitehat believes that the vulnerability still persists after the Euclid upgrade or that the refactored mechanism fails to adequately mitigate the risk, we welcome any concrete evidence demonstrating that the issue remains within the new codebase. Such input will be thoroughly reviewed as part of our ongoing commitment to security.
Delays and Communication
We would also like to acknowledge the time it took to finalize our response. The mediation process involved a careful collection of evidence from the Scroll team, multiple follow-ups, and a thorough validation of the information before we could draft and communicate our position. We appreciate the patience of all parties involved.
Goodwill Gesture
As part of the mediation, we also reached out to Scroll to recommend publicly updating their bug bounty program to reflect the current refactoring phase. This will help guide whitehats in focusing their efforts on in-scope and relevant components, avoiding time spent on soon-to-be-retired mechanisms.
In recognition of the whitehat’s effort and engagement throughout this process, Scroll chose to offer a $1,000 goodwill payout. We would like to stress that this was a discretionary gesture by the project and does not constitute a bounty under the Immunefi platform. Whether or not such goodwill rewards are extended remains solely at the discretion of the project.