How can I report a security vulnerability to ENS?
Report security vulnerabilities through the ENS bug bounty programme: start at docs.ens.domains/bugs. That page sets out the bounty tiers and links to the reporting platform (Immunefi), which specialises in vulnerability reporting and disclosure and provides a structured process for submitting and tracking reports. ENS does not accept vulnerability reports through any other channel — including this help centre.
How do I submit a report?
Open docs.ens.domains/bugs and follow its link to the ENS bug bounty programme. Review the programme details, including the scope and eligibility criteria.
Create an Immunefi account if you don't already have one, and complete any required verification.
Submit your report on Immunefi, including all the detail needed for a thorough review.
How do I follow up on a report?
Track your report's status and manage follow-ups directly on Immunefi. The platform provides tools for communication and updates on your submission.
Can ENS support help with my Immunefi account?
No. ENS support cannot help with Immunefi account issues such as verification, KYC, payouts, or platform access. Resolve those directly with Immunefi's support team.
