40+Criticals confirmed every month

Put 85,000+ security researchers on your code before your launch, or continuously once you are live. Immunefi has paid more than the rest of the market combined, $140M+ for valid findings across 650+ protocols.

Contact Our Team

Trusted By 650+ Protocols

Layer ZeroChain LinkSkyArbitrumBabylon LabsBerachainOptimismENSEthenaFiredancerHyperlaneJitoMad Shield
MorphoOndo FinancePendleScrollSeiSigmaprimeStacksThe GraphThree SigmaPlumeHourglassInferenceAlchemix
$140M+paid in bounties across 650+ protocols
$25B+in hacks and thefts prevented
93%of crypto's critical vulnerability disclosures come through Immunefi
650+protocols protected
$180B+in assets protected
85,000+security researchers in the Immunefi community

Research

Nine in ten long-running programs have found a critical

Across 593 Bug Bounty Programs on Immunefi, confirmed, paid criticals become more common the longer a program runs. Among the programs that found a critical, most found more than one, and a third had criticals surface in two or more separate years.

Read the full study

Programs with a confirmed critical, by time live

1+ years61.4%
2+ years73.9%
3+ years87.2%
4+ years92.9%
5+ years93.9%

593 programs, January 2021 to February 2026. Audit Competitions and attackathons excluded.

What protocol teams say

Bug Bounty Program

Immunefi is where the best security researchers are, so that’s where ether.fi runs its program, covering both smart contracts and web infrastructure. At ether.fi’s scale, outside review needs to be continuous, not periodic.

Seongyun KoVP of Engineering @ ether.fi
Audit Competition

From the speed of the launch and real-time reporting, to accessing top-level security researchers, Immunefi’s Audit Competition exceeded expectations.

Badger DAOProtocol team
Managed Triage

We chose Immunefi for its established position in Web3 bug bounties and its access to a broad community of security researchers. The main value for us has been identifying and addressing meaningful issues early, before they become larger problems. Their triage process has also been helpful in filtering reports before they reach our engineering team, saving time and reducing noise. Overall, it has been a valuable part of our security process.

FlareProtocol team
Bug Bounty Program

By launching an Aave bug bounty program with Immunefi, we ensure we have the most efficient infrastructure with a successful track record to help us make our code more secure.

Emilio FrangellaHead of Smart Contracts @ Aave Companies
Audit Competition

Doing an Audit Competition on Immunefi was definitely a great decision. The Immunefi team has enabled us to identify and mitigate vulnerabilities swiftly and effectively. Immunefi’s Audit Competition has significantly enhanced our security posture.

RykerFounder @ ZeroLend
Managed Triage

Immunefi has an easy to use platform, a strong hunter community, an extremely responsive team ready to help with any issues, and is always pushing the boundaries of features and ideas. It makes it very easy to evolve and grow with them. The community engagement has been great. The careful curation of the program has allowed us to receive and pay out valid bugs while still filtering out spam. Our track record of paying out for valid bugs and code changes means we get a lot of attention, and Immunefi helps keep the signal high and noise low.

OverkoalafiedCOO Alchemix
Bug Bounty Program

Immunefi has been instrumental in uncovering vulnerabilities in Lido on Polygon that even top auditing firms missed.

Jakov BuratovićCIO @ Shard Labs (Lido on Polygon)
Bug Bounty Program

For zkSync, partnering with Immunefi was a no-brainer; with their wide reach and large community, they have helped us secure the protocol and get whitehats rewarded for their hard work in the process.

Anton AstafievVP of Security @ Matter Labs (zkSync)
Bug Bounty Program

As the largest interoperability network for Tether Assets, at USDT0 we chose Immunefi because it gives us access to the strongest security researcher community in Web3, and by running the one of the largest bounty program globally, we're making it clear that proactively finding and fixing vulnerabilities is a top priority for us.

Lorenzo RomagnoliCo-Founder USDT0

Tell us what you are shipping

Send us what is deployed or about to be, and what has already been reviewed. We'll come back with what we would recommend and why.

Contact Our Team