Hi all.
Ben and I wanted to put this on the forum as a follow-up to the treasury reward-cut restart as security is one of the main things the treasury pays for, and this is what the last period of time has looked like as we’ve handled security triage and reports. Under-spending on security to protect yield is a false economy because all token value assumes the protocol keeps working.
Why this matters
LPT is priced as if the protocol, the clients, and the operator software keep working and an exploit makes that assumption false overnight. The cost of triage, bounties, and patches is small next to that. Security is the cost of existing, not a luxury.
Report volume
Sidestream’s August Protocol R&D update already put the numbers in public: Immunefi report volume more than doubled versus July’s own record. They skipped the August release to work the backlog. Every report in that window was handled inside its response SLA. That is the program doing the job it was stood up to do, under a load we had not been treating as a budget line.
The original planning assumption was a handful of reports a month. AI-assisted scanning has ended that world. A lot of the extra volume is noise from duplicates, known issues, incomplete PoCs, and technically valid edge cases with little real-world impact. That still eats triage time, and that time is what you need on the day a critical report comes in. We have been improving the Immunefi scope and known issues, and re-ordering triage so genuine high-severity reports still get through. That work is ongoing. It lets us handle more with the same team, but it cannot keep up with the volume on its own.
The industry backdrop is the same shape. a16z recently charted critical and high-severity CVEs going parabolic into 2026. Reporting cadence varies a lot by vendor, so treat that chart as a signal, not a precise count. Google’s M-Trends 2026 shows attackers moving faster too: in 2018 they exploited bugs two months after the fix was out, in 2025 a week before it. Our own numbers show the same shift . What is important is that we all understand we need to be both proactive and responsive.
Critical and high severity CVEs, Epoch.ai / a16z, 3 Sep 2026
Recent incidents
These are at different levels of write-up. Listing them together makes the pattern visible: this is a capacity problem more than any one bug, and it is no longer only about the contracts.
Protocol (earlier disclosures are on the forum)
- L1 → L2 Migrator address validation (June). Critical, Immunefi. Contract paused, then replaced. No funds lost, not exploited to our knowledge. Bounty paid.
- TicketBroker dust-payment griefing (August). Low severity, Immunefi. Patched in the June release window. No funds lost, not exploited to our knowledge. Bounty paid.
Client and operator software
- Gateway ticket validation (June). Critical. Reported through security@livepeer.foundation. A malicious orchestrator could get a gateway to send tickets that bypassed its payment limits. Patched privately together with the active gateways before any public disclosure. Not exploited to our knowledge. Reporter paid.
- Exposed go-livepeer admin port (late August). Two orchestrators had left their admin port open to the internet, which let others trigger stake operations on their node. A small amount of funds was taken from them. These operations are now opt-in with a clear warning.
- go-livepeer client bug (late August). Could let others trigger stake operations on a node. Reported through Immunefi, though out of scope. Possibly exploited against one orchestrator during our investigation, with a small amount of funds taken. Patched quickly, with affected orchestrators and gateways updated privately before any public disclosure, which limited the impact. Reporter paid at our discretion.
- Inc-node key compromise (late August). Keys on an Inc node were compromised and used to pay an attacker via winning tickets. Confirmed publicly by Doug on Discord. Any further details are Inc’s to share.
- Agent orchestrator sweep (late August). While investigating the Inc-node compromise, the team found a further issue and took the agent orchestrator fleet offline as a precaution for a security sweep. The launch calendar moved around it.
We are not listing these to cause alarm. Each was contained and fixed. Fuller write-ups of the software issues will follow later. While the Protocol R&D SPE covers the protocol side, much of the software-side response ran on Foundation and Inc time on top of other work, and the Foundation has been covering the costs as they come. That isn’t a durable setup.
What it cost
The Foundation has paid about $60K in bug bounties so far in 2026, already more than any previous full year, and costs are still rising with the report volume. That comes in addition to the Protocol R&D SPE, which funds the triage and response work itself.
The Immunefi program has long been described, fairly, as modest next to the value it protects. The last few months are why that planning assumption is out of date. The cost of not paying lands on every holder: an unpatched client or a stalled launch is more expensive than the bounty.
The number is here so it can be discussed in the open. How it gets funded later, whether through the treasury, an Immunefi reserve, or a line in the Protocol SPE, is a later conversation. We are not attaching a proposal to this post.
What we are doing
On the protocol side, we keep building on what is in place. Sidestream remains first responder on Immunefi under the Protocol R&D SPE and is expanding its proactive work, from self-audits to AI-assisted scanning.
On node operations and software, we are stepping up. LIP-118 reward delegation already keeps orchestrator stake away from the key that runs day to day, and we are looking at doing the same for gateways. Through the Network Engineering SPE II, the orchestrator software is being split into smaller, easier-to-secure components and will get continuous security testing. We are also bringing the incident process we use for the protocol to the software, and recently extended the bug bounty to it as well. The software bounty program is temporarily paused while we remove redundant code and sharpen the scope, so reports are worth both our time and researchers’. To support all of this, we are hiring a dedicated security engineer.
If you operate a node: read the updated orchestrator security guide, use reward delegation, keep clients current, and keep signing keys off the working host.
Close
This post is here to open the discussion on the current state of security and what security needs the project has going forward. We’ll keep discussing in the open but let us know if you have any questions at security@livepeer.foundation, or just reply in this thread.
— Rick, with Ben
