A bug bounty program with Immunefi was launched on October 11, 2022. This bug bounty program is focused on the Beanstalk smart contracts and preventing the loss of Farmersβ assets within Beanstalk and other ecosystem smart contracts. The maximum bounty is 1,100,000 Beans.
You can find the bug bounty program and submit bug reportsΒ here:
Beanstalk Bug Bounties | Immunefi
Rewards are distributed according to the impact of the vulnerability based on the Immunefi Vulnerability Severity Classification System V2.2. The following is a simplified 3-level scale, focusing on the impact of the vulnerability reported. The complete scope can be found below.
immunefi.com

Below is a log of Immunefi bug reports, including the BIC's evaluations and related documentation.
Starting after report #44213, only valid bug reports will be published. Reports closed as invalid will no longer be documented here, due to the high volume of automated submissions.
If you have questions about anything you see, join the Beanstalk Discord and ask in the (#βΒ β’ questions) channel!