generated: '2026-07-19' method: searched probe: true source: https://immunefi.com/bug-bounty/ethena/ policy: - https://immunefi.com/bug-bounty/ethena/ contact: - https://immunefi.com/bug-bounty/ethena/ program: platform: Immunefi scope: Smart contracts max_reward_usd: 3000000 reward_basis: 10% of funds directly affected, up to USD $3,000,000 for critical smart-contract bugs poc_required: true badge: Immunefi Standard Badge audits_reference: https://docs.ethena.fi/resources/audits evidence: - source: https://immunefi.com/bug-bounty/ethena/ kind: bug-bounty - source: https://docs.ethena.fi/resources/audits kind: audit-reports notes: >- Ethena runs a public bug bounty on Immunefi (up to $3M for critical smart-contract findings, PoC always required) and publishes completed third-party audit reports (Zellic, Quantstamp, Spearbit, Pashov, Code4rena, Cyfrin, Chaos Labs). No /.well-known/security.txt is published on ethena.fi (404 as of this probe).