defirisk.co
rubric v1.7.0

Disclosure channel exists

Rocket Pool's assessment for RD-F-175 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Active Immunefi bug bounty program exists (last updated March 31, 2026, 77 assets in scope, active since September 2021). No SECURITY.md in the primary repo (data-cache security_md_present: false; 404 confirmed). No dedicated security@ email. rocketpool.net/protocol/security page returns only a basic description with no disclosure content. Immunefi is the sole documented disclosure channel. No evidence of active monitoring beyond Immunefi (no disclosed payout history publicly archived). Yellow: channel exists but no active-monitoring evidence in last 12 months.

Sources #

Methodology #

Determine whether the protocol publishes a public security disclosure channel (security@ email, Immunefi program, in-house disclosure page).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol rocket-pool factor RD-F-175 score yellow collected_at 2026-05-04 15:40:28