Lombard Finance Opens $250,000 Bug Bounty for LBTC Smart Contract Vulnerabilities
Lombard Finance posted a bug bounty on Immunefi.
Caleb North·updated August 06, 2026

Up to $250,000 for critical smart contract findings. Minimum payout sits at $50,000 per valid critical submission. As of August 1, the program is live, denominated in USD, paid out in USDC on Ethereum.
The target is large. LBTC is a yield-bearing Bitcoin LST built on Babylon, designed to move BTC across chains without fragmenting liquidity. That design introduces multiple state mutation points: Babylon restaking, cross-chain messaging, mint/burn on the destination chain, redemption accounting. Each layer is an attack vector. Each invariant deserves verification.
Reward Mechanics
The reward formula is straightforward. Ten percent of funds directly affected, capped at $250,000. For critical web and application-layer bugs, the payout drops to $30,000, and only when the impact crosses a defined threshold. All other critical classifications receive a flat $15,000.
The pricing reference is the average between CoinMarketCap and CoinGecko at the moment the report is submitted. No liquidity adjustment. No KYC delay disclosed. Researchers should expect a deterministic conversion to USDC at submission time.
Severity classification follows Immunefi V2.3. The scope covers LBTC, BTC.b, the Lombard SDK, and Bitcoin Smart Accounts. Out-of-scope findings will be rejected. Read the scope table before writing the report.
The Submission Fee
One detail demands attention. Immunefi requires a non-refundable submission fee on every report. The fee is collected by the platform, not by Lombard. It applies across all severity levels and must be paid before triage begins.
This is a filter mechanism. It separates low-effort noise from committed researchers. It also shifts cost onto the whitehat. For a $15,000 payout on a flat critical, the fee must be weighed against expected return. For a valid $250,000 critical, the economics still work. Calculate before you submit.
Where the Code Breaks
LBTC rests on three assumptions: Babylon slashing behaves as designed, the cross-chain bridge preserves message ordering, and the peg contract enforces 1:1 BTC backing. Any of these can fail.
Watch for replay attacks on cross-chain mint flows. Watch for state desynchronization between Babylon restaking positions and the LST supply. Watch for accounting rounding in yield distribution. Watch for oracle manipulation on BTC.b composition.
A deterministic invariant holds: total LBTC supply must equal locked BTC plus accrued yield, minus burned supply. If that invariant breaks, funds are at risk. Document the state transition that breaks it. Include the exact block number. Include the transaction hash. Include the pre- and post-state.
Researcher Checklist
Before submission, verify each item:
- Confirm the vulnerable contract is in scope under the Immunefi program.
- Reproduce the exploit on a forked mainnet state or a local fork with identical bytecode.
- Quantify the funds directly affected in USD at submission time.
- Map the state mutation path from input to loss event.
- Capture logs, traces, and storage diffs. Attach them.
- Verify the report meets V2.3 severity criteria for the claimed classification.
- Calculate net payout after the submission fee.
- Confirm no third-party dependency would invalidate the finding before triage.
One report. One exploit path. One clear invariant violation. That is what gets a maximum payout. Noise does not.