Security research platform · web3
Immunefi
The dominant web3 bug bounty platform - DeFi, smart contracts, bridges, and protocols, with the largest single payouts in the industry.
Overview
Research on Immunefi
Severity is impact-driven: for Critical you typically must show a working PoC of funds actually at risk (often on a forked mainnet), not just a theoretical bug.
- Program type
- Web3 / smart-contract bounty
- Regions
- Global
- Payout
- USD / crypto; critical bounties commonly reach six-seven figures (often scaled to funds-at-risk)
Field notes
Practical guidance
- Requires real Solidity/EVM (or the target chain's) skill - this is not web-app hunting.
- PoC on a mainnet fork (Foundry/Hardhat) is the expected proof; 'could' arguments get downgraded.
- Read each project's severity classification - % of funds at risk maps directly to the reward.
Primary source
Official links
Version history: normalized permanent page created 2026-08-20. Verify current platform terms before testing.