Immunefi Live Bug Bounty Programs

0 Active contests
Active prize pool
235 Bug bounties
1 Platforms

Last updated Jul 21, 2026 · 10:55 UTC

Showing 281–294 of 294

59 audit contests235 bug bounty programs

Protocol Source Prize Window Link
Bug Bounty Comp | Lido: Dual Governance
Audit contest
Immunefi Finished
$2.0M
Jul 29 - Aug 12, 2025
14 days
View
Attackathon | Plume Network
Solidity
Immunefi Finished
$200K
Jul 17 - Aug 14, 2025
28 days
View
Mitigation Audit | Flare | FAssets
Solidity
Immunefi Finished
$25K
Sep 18 - Sep 25, 2025
7 days
View
Attackathon | VeChain Hayabusa Upgrade
Audit contest
Immunefi Finished
$160K
Oct 01 - Oct 26, 2025
25 days
View
Audit Comp | Folks Finance: Wormhole NTT on Algorand
Audit contest
Immunefi Finished
$30K
Oct 16 - Oct 27, 2025
11 days
View
Audit Comp | Belong
Cairo Solidity
Immunefi Finished
$30K
Oct 20 - Oct 29, 2025
9 days
View
Audit Comp | Alchemix V3
Audit contest
Immunefi Finished
$100K
Oct 14 - Nov 04, 2025
21 days
View
Audit Comp | Firelight
Solidity
Immunefi Finished
$15K
Nov 07 - Nov 17, 2025
10 days
View
Audit Comp | Vechain | Stargate Hayabusa
Solidity
Immunefi Finished
$40K
Nov 10 - Nov 24, 2025
14 days
View
Attackathon | XRPL Lending Protocol
Cpp
Immunefi Finished
$200K
Oct 27 - Nov 24, 2025
28 days
View
Bug Bounty Comp | Lido V3
Solidity
Immunefi Finished
$2.0M
Nov 12 - Dec 09, 2025
27 days
View
Audit Comp | Folks Finance: Staking Contracts
Solidity
Immunefi Finished
$25K
Mar 11 - Mar 17, 2026
6 days
View
Audit Comp | Base Azul
Rust Solidity
Immunefi Finished
$250K
Apr 21 - May 04, 2026
13 days
View
Audit Comp | Firedancer V1
Cpp
Immunefi Finished
$1.0M
Apr 09 - May 09, 2026
30 days
View
Loading timeline...
Immunefi Finished

Bug Bounty Comp | Lido: Dual Governance

$2.0M Prize pool
Jul 29 - Aug 12, 2025
View on Immunefi
Immunefi Finished

Attackathon | Plume Network

$200K Prize pool
Jul 17 - Aug 14, 2025
View on Immunefi
Immunefi Finished

Mitigation Audit | Flare | FAssets

$25K Prize pool
Sep 18 - Sep 25, 2025
View on Immunefi
Immunefi Finished

Attackathon | VeChain Hayabusa Upgrade

$160K Prize pool
Oct 01 - Oct 26, 2025
View on Immunefi
Immunefi Finished

Audit Comp | Folks Finance: Wormhole NTT on Algorand

$30K Prize pool
Oct 16 - Oct 27, 2025
View on Immunefi
Immunefi Finished

Audit Comp | Belong

$30K Prize pool
Oct 20 - Oct 29, 2025
View on Immunefi
Immunefi Finished

Audit Comp | Alchemix V3

$100K Prize pool
Oct 14 - Nov 04, 2025
View on Immunefi
Immunefi Finished

Audit Comp | Firelight

$15K Prize pool
Nov 07 - Nov 17, 2025
View on Immunefi
Immunefi Finished

Audit Comp | Vechain | Stargate Hayabusa

$40K Prize pool
Nov 10 - Nov 24, 2025
View on Immunefi
Immunefi Finished

Attackathon | XRPL Lending Protocol

$200K Prize pool
Oct 27 - Nov 24, 2025
View on Immunefi
Immunefi Finished

Bug Bounty Comp | Lido V3

$2.0M Prize pool
Nov 12 - Dec 09, 2025
View on Immunefi
Immunefi Finished

Audit Comp | Folks Finance: Staking Contracts

$25K Prize pool
Mar 11 - Mar 17, 2026
View on Immunefi
Immunefi Finished

Audit Comp | Base Azul

$250K Prize pool
Apr 21 - May 04, 2026
View on Immunefi
Immunefi Finished

Audit Comp | Firedancer V1

$1.0M Prize pool
Apr 09 - May 09, 2026
View on Immunefi

About Immunefi

Immunefi launched in 2020 and is the dominant ongoing-bounty platform in Web3. Unlike audit competitions which run for fixed windows, Immunefi bounties are ongoing programs where each valid vulnerability submission earns a direct per-bug reward. Critical-severity payouts have reached $15 million (Wormhole, MakerDAO). Immunefi also recently added time-boxed audit competitions.

This page shows only programs aggregated from Immunefi. For audit contests on other platforms, see the full Web3 audit competition tracker.

Smart Contract Audit Competition & Bug Bounty Platforms Compared

Six major platforms host the Web3 audit competitions and smart contract bug bounty programs aggregated above. Click any platform to see only its active contests.

Comparison of the major smart contract audit competition and bug bounty platforms.
Platform Type Typical Prize Contest Length Best For
Code4rena Audit contests $50K to $500K 3 to 14 days DeFi protocols pre-launch
Sherlock Contests + bounties $50K to $300K 7 to 30 days Insurance-backed audits
CodeHawks Audit contests + First Flights $5K to $200K 3 to 21 days Newer auditors building a track record
Cantina Mega-comps + bounties $200K to $2M+ 14 to 30 days Experienced researchers, high-value protocols
Immunefi Ongoing bug bounties Up to $15M per critical Ongoing Production protocol vulnerability hunting
HackenProof Bounties + crowdsourced audits $1K to $1M+ Ongoing or time-boxed Managed Web3 programs and exchange/protocol bounties

Frequently Asked Questions

What is the largest bounty ever paid on Immunefi?

Immunefi has paid multiple $10M+ bounties for critical vulnerabilities. Notable payouts include $10M from Wormhole and $10M from MakerDAO. Critical-severity ceilings on the largest programs reach $15 million per finding.

How do I submit a bug to Immunefi?

Find the protocol's program page on immunefi.com, review the scope and severity classification, then submit a detailed proof-of-concept through the Immunefi platform. Submissions are triaged by Immunefi's in-house team before reaching the protocol team.

What are the best smart contract bug bounty platforms?

The leading Web3 bug bounty platforms are Immunefi (largest, $15M max payouts on DeFi protocols), Cantina (Spearbit's bounty program plus audit competitions), HackenProof (managed Web3 bounties and crowdsourced audits), Sherlock (audit contests with insurance-backed bounties), and Code4rena (best known for time-boxed audit competitions). Codehawks rounds out the field with Cyfrin-run contests focused on emerging protocols and beginner-friendly First Flights.

Which audit competition platform pays the most?

Cantina runs the largest audit competitions ($2M+ prize pools for protocols like EigenLayer and Uniswap v4). Immunefi pays the highest per-bug bounty (up to $15M for critical findings). Code4rena and Sherlock typically run $100K-$500K audit contests. Codehawks First Flights are smaller but accessible to newer auditors.

How do smart contract audit competitions work?

Audit competitions invite security researchers to review a protocol's smart contract code for a fixed prize pool over 1-4 weeks. Rewards are split based on unique valid findings, weighted by severity (critical, high, medium). Code4rena, Sherlock, Codehawks, and Cantina are the main platforms.

How much can you earn in a smart contract audit competition?

Top auditors earn $10,000-$500,000+ per competition. Cantina and Code4rena regularly run $500K-$2M prize pool contests. Bug bounties can pay up to $15M per critical finding on platforms like Immunefi.

What is the difference between a bug bounty and an audit contest?

Audit contests run for a fixed time window with a fixed prize pool shared among all valid findings. Bug bounties are ongoing programs where each valid submission earns a direct per-vulnerability reward (often $50K-$15M depending on severity). Bug bounties require finding a real vulnerability in production code.

How do I get started with smart contract auditing?

Learn the most common vulnerability classes first: reentrancy, flash loan attacks, oracle manipulation, and access control. The SCH Smart Contract Hacking Course covers all the core attack patterns that audit competitions test, starting from zero experience.

How to Start Competing in Smart Contract Audits

A practical path from learning vulnerability classes to submitting your first contest finding.

  1. Learn the core vulnerability classes

    Master reentrancy, access control, oracle manipulation, flash loan attacks, and arithmetic overflows. These five classes account for most contest findings.

  2. Practice on retired contests

    Read every public report from past Code4rena and Sherlock contests. Try to spot findings yourself before reading the writeup. This is how every top auditor trained.

  3. Start with CodeHawks First Flights

    First Flights are small audit contests designed for newer auditors. Prize pools are under $20K, scope is small, and competition is lighter. They build real submission history.

  4. Enter your first full competition

    Pick an active audit contest from the tracker above filtered by Solidity and a $50K-$200K prize range. Spend 20 to 40 hours on the contest, even if you only find one valid medium-severity issue.

  5. Build a public track record

    Publish your findings, share writeups on Twitter and Mirror, and start accumulating valid submissions across multiple platforms. A documented track record is what opens bug bounty access and full-time auditor roles.