HomeOpportunities › Immunefi bug bounties

Immunefi · Paid bounty platform

Immunefi bug bounties

Always open — programs run continuously Set per program by each protocol; Immunefi's own headline is $110,000,000+ paid out to date

The highest ceiling on this page and the steepest climb. Immunefi is where protocols pay whitehats to find security flaws, and it has paid out over $110,000,000. Be honest with yourself about the bar: this rewards real smart-contract security skill, not enthusiasm, and most students should treat it as a goal to grow into rather than a first paid credential.

Cost
Free to submit on 161 of the 187 listed programs; 26 charge a submission fee
Format
Fully remote
Duration
Self-paced — from a few days reviewing a codebase to weeks on one protocol
Eligibility
Global and remote — but check each program: 107 of the 187 listed require KYC and 26 charge to submit

Dates & timeline

Bounty programsRolling — 187 programs live at the time of writing
Your effortSelf-paced; you choose a protocol and review its in-scope code
After you submitThe project triages your report and judges severity and scope
PaymentPaid by the protocol once a report is accepted as valid

Rewards

Why it's worth your time

Immunefi is a bug bounty marketplace for blockchain protocols. Projects publish a scope — which contracts are in play, what counts as a valid finding, and what each severity tier pays — and independent security researchers submit vulnerability reports against it. If your report is judged valid and in scope, the protocol pays the reward. The platform's own figure for total bounties paid is over $110,000,000, across the 187 bounty programs listed at the time of writing.

This one sits differently from the rest of the bounties section. Superteam Earn is scoped micro-work you can win in a weekend; Immunefi is adversarial security research against code that is holding real money, judged by people whose job is to reject invalid reports. The payouts are large precisely because the work is hard and most submissions fail. It belongs on this page because the ceiling is genuinely high and it is open to anyone globally — but if you have not already spent serious time on Solidity and smart-contract security, your realistic first paid line comes from somewhere else on this page.

Two practical frictions worth knowing before you start. 107 of the 187 listed programs require KYC, so you will need to identify yourself to claim a reward on most of them. And while the majority are free, 26 programs charge a fee to submit a report — a deliberate filter against spam submissions. Check both on the program page before you invest time.

How to apply

1

Be realistic first. If you have not written and audited Solidity before, spend your time on Superteam Earn or a competition instead and come back to this later.

2

Browse the bounty programs and filter to ones that are free to submit to before you read any code.

3

Read the scope literally. Rewards are only paid for vulnerability classes the program lists as in scope, on the exact contracts it names.

4

Check the KYC requirement on the program page — most programs need it, and finding out after you have a valid finding is a bad time to discover it.

5

Write the report as a reproducible proof of concept, not a description. Triagers reject reports they cannot reproduce.

Frequently asked questions

Is Immunefi realistic for a 2nd-year student?

Only if you already have real smart-contract security skill. This is adversarial security research judged against code holding live funds, and most submissions are rejected. It is on this page because the ceiling is high and it is open to anyone, but for a first paid credential the bounty and competition items are far better odds.

How much has Immunefi paid out?

Over $110,000,000 in bounties to date, according to Immunefi's own headline figure. Individual rewards are set by each protocol by severity tier rather than by the platform.

Is it free to take part?

Mostly. 161 of the 187 currently listed programs are free to submit to, but 26 charge a submission fee as a spam filter. Check the individual program page before you start work.

Do I need to give ID to get paid?

On most programs, yes. 107 of the 187 listed programs require KYC before a reward is released. Check this on the program page before investing time, not after you have a finding.

Can students in India take part?

Yes. Immunefi is open globally and the work is fully remote. Individual programs may have their own KYC and payout requirements.

Official links

Hiring now

US startups hiring on Tierones

Part-time, remote coding internships with funded US startups — quoted in USD per hour, open to verified 2nd- and 3rd-year students. Free for students, always.

Browse open roles

More opportunities

Want the roles that never hit public lists?

Create your free profile