generated: '2026-08-23' method: searched source: https://immunefi.com/bug-bounty/immunefi/ note: >- Immunefi is itself a bug bounty platform and runs a public bug bounty program for its own properties on its own platform. The program record is also returned by the public API at https://immunefi.com/public-api/bounties.json (slug "immunefi"), which is where the reward table, assets in scope and impact list below were read from verbatim. program: type: bug-bounty name: Immunefi Bug Bounty url: https://immunefi.com/bug-bounty/immunefi/ platform: Immunefi (self-hosted) status: live launch_date: '2020-12-02' last_updated: '2025-11-17' invite_only: false kyc_required: true max_bounty: 50000 reward_currency: USDC program_types: - Smart Contract - Websites and Applications features: - Safe Harbor Documents Signed - 'Managed Triage: Expert Assessment' - Arbitration rewards: - severity: critical asset_type: smart_contract min: 10000 max: 50000 model: range - severity: high asset_type: smart_contract min: 5000 max: 10000 model: range - severity: medium asset_type: smart_contract fixed: 5000 model: fixed - severity: low asset_type: smart_contract fixed: 1000 model: fixed severity_taxonomy: name: Immunefi Vulnerability Severity Classification System version: v2.3 url: https://immunefi.com/immunefi-vulnerability-severity-classification-system-v2-3/ note: Immunefi authors this taxonomy; it is not a third-party framework. security_txt: present: false probes: - url: https://immunefi.com/.well-known/security.txt status: 308 note: >- Responds 308 with a Location header pointing at the identical URL — a self-referential redirect loop, so no RFC 9116 document is ever served. Every /.well-known/* path on immunefi.com behaves the same way, including a deliberately nonsense control path. - url: https://bugs.immunefi.com/.well-known/security.txt status: 404 disclosure_policy: published: true url: https://immunefi.com/bug-bounty/immunefi/ safe_harbor: signed: true url: https://immunefi.com/safe-harbor/ note: >- Immunefi operates a Safe Harbor program (adopted from the SEAL Safe Harbor framework) and records "Safe Harbor Documents Signed" as a program feature on its own bounty.