aid: immunefi name: Immunefi description: >- Immunefi is a crowdsourced web3 security platform that operates the largest onchain bug bounty ecosystem, connecting security researchers with blockchain protocols and rewarding them for responsibly disclosed vulnerabilities. Alongside bug bounties it runs audit competitions and attackathons, PR reviews, Safe Harbor agreements, onchain monitoring, and Magnus, a unified security command center. Immunefi authors and versions the Immunefi Vulnerability Severity Classification System, the severity taxonomy most web3 bounty programs are written against. Its only public machine-readable surface is an unauthenticated JSON endpoint at immunefi.com/public-api/bounties.json that returns the full catalog of live bug bounty programs, including assets in scope, reward tables by severity, impacts, ecosystems and program metadata. image: https://images.ctfassets.net/t3wqy70tc3bv/1XjTFUMSo1pLNrTF0aIH4U/353cf547e2cd9dcfc4e464ce9c328c07/Logo_square.png url: https://raw.githubusercontent.com/api-evangelist/immunefi/refs/heads/main/apis.yml x-type: company x-source: harvest:secondary-market specificationVersion: '0.20' created: '2026-08-23' modified: '2026-08-23' tags: - Company - Security - Bug Bounty - Vulnerability Disclosure - Web3 - Blockchain - Smart Contracts - Application Security - Cryptocurrency - Crowdsourced Security apis: - aid: immunefi:bounties name: Immunefi Bug Bounty Programs API description: >- An unauthenticated, read-only JSON endpoint published on Immunefi's own domain that returns the complete catalog of bug bounty programs listed on the platform. Each record carries the project name and slug, program and product type, ecosystems, languages, maximum bounty, reward token, KYC and invite-only flags, launch and update dates, the full assets-in-scope list, the reward table keyed by severity and asset type, prioritized and out-of-scope impacts, program overview and rules prose, and any linked audits. The route serves the entire collection as a single JSON array; there is no filtering, pagination, or per-program path. humanURL: https://immunefi.com/bug-bounty/ baseURL: https://immunefi.com/public-api tags: - Bug Bounty - Security - Web3 properties: - type: Examples url: examples/immunefi-bounty-program-example.json - type: DataModel url: data-model/immunefi-data-model.yml - type: Authentication url: authentication/immunefi-authentication.yml - type: RateLimits url: rate-limits/immunefi-rate-limits.yml maintainers: - FN: Kin Lane email: kin@apievangelist.com - FN: APIs.json email: info@apis.io common: - type: Website url: https://immunefi.com/ - type: Blog url: https://immunefi.com/blog/ - type: BlogRSS url: https://immunefi.com/blog/feed - type: GitHubOrganization url: https://github.com/immunefi-team - type: Support url: https://immunefisupport.zendesk.com/hc/en-us - type: TermsOfService url: https://immunefi.com/terms-of-use/ - type: PrivacyPolicy url: https://immunefi.com/privacy-policy/ - type: SignUp url: https://bugs.immunefi.com/ - type: Security url: https://immunefi.com/bug-bounty/immunefi/ - type: VulnerabilityDisclosure url: security/immunefi-vulnerability-disclosure.yml - type: DomainSecurity url: security/immunefi-domain-security.yml - type: Webhooks url: asyncapi/immunefi-webhooks.yml - type: Conformance url: conformance/immunefi-conformance.yml - type: Conventions url: conventions/immunefi-conventions.yml - type: Lifecycle url: lifecycle/immunefi-lifecycle.yml - type: Packages url: packages/immunefi-packages.yml - type: Plans url: plans/immunefi-plans-pricing.yml - type: LLMsTxt url: llms/immunefi-llms.txt x-enrichment: date: '2026-08-23' status: enriched artifacts_added: 17 pass: local-v1