Horizen-logo

Horizen

|

Horizen is an EVM-native, privacy-first blockchain ecosystem: an OP Stack L3 that settles to Base, enabling regulatory-compliant, auditable private execution for onchain businesses and privacy-minded users. ZEN, the ecosystem's governance and utility token, lives as an ERC-20 on Base and on the Horizen L3. This bug bounty program focuses on the official ZEN staking program: the ZenStaker smart contracts and the staking web application.

Base
Blockchain
L2
Staking
Solidity
Typescript
ReactJS
Maximum Bounty
$10,000
Live Since
15 July 2026
Last Updated
21 July 2026
  • Runnable PoC Required

  • KYC required

Codebase

Title
Staking dApp
Description
Client-side staking frontend (Next.js static export) and the ZenStaker subgraph mapping code.
Link
Title
Staking contracts
Description
ZenStaker + RewardAccumulator Solidity contracts, built on the audited Tally/ScopeLift Staker framework.
Link

Documentation

Title
Horizen’s Documentation
Description
Documentation and further resources
Link
Go to Audits & Known Issues
Assets Body

During Phase A (from 2026-07-21) the in-scope deployment is on Horizen Testnet (chain ID 2651420); severity is assessed as if the same code were on mainnet.

The same code deploys to mainnet on 2026-07-27, when the mainnet contracts and the production site (staking.horizen.io) become the severity-defining assets and are added to scope. Contract source is pinned to staker commit ab92502e9da98784dfe3bd3ef933d4e9345ff628; the pin will be updated if contracts are redeployed.

Testnet entries remain listed as the sanctioned environment for reading state and local forking. Upstream, unmodified ScopeLift/Tally Staker code paths already covered by the published audits (base Staker.sol, extensions, calculators, notifiers) are out of scope except where Horizen's ZenStaker / RewardAccumulator integration introduces a new issue.