Immunefi · Vulnerability Disclosure

Immunefi Vulnerability Disclosure

Vulnerability disclosure

Immunefi publishes a vulnerability disclosure policy for reporting security issues.

CompanySecurityBug BountyVulnerability DisclosureWeb3BlockchainSmart ContractsApplication SecurityCryptocurrencyCrowdsourced Security
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

immunefi-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-23'
method: searched
source: https://immunefi.com/bug-bounty/immunefi/
note: >-
  Immunefi is itself a bug bounty platform and runs a public bug bounty program for its own
  properties on its own platform. The program record is also returned by the public API at
  https://immunefi.com/public-api/bounties.json (slug "immunefi"), which is where the reward
  table, assets in scope and impact list below were read from verbatim.
program:
  type: bug-bounty
  name: Immunefi Bug Bounty
  url: https://immunefi.com/bug-bounty/immunefi/
  platform: Immunefi (self-hosted)
  status: live
  launch_date: '2020-12-02'
  last_updated: '2025-11-17'
  invite_only: false
  kyc_required: true
  max_bounty: 50000
  reward_currency: USDC
  program_types:
  - Smart Contract
  - Websites and Applications
  features:
  - Safe Harbor Documents Signed
  - 'Managed Triage: Expert Assessment'
  - Arbitration
  rewards:
  - severity: critical
    asset_type: smart_contract
    min: 10000
    max: 50000
    model: range
  - severity: high
    asset_type: smart_contract
    min: 5000
    max: 10000
    model: range
  - severity: medium
    asset_type: smart_contract
    fixed: 5000
    model: fixed
  - severity: low
    asset_type: smart_contract
    fixed: 1000
    model: fixed
  severity_taxonomy:
    name: Immunefi Vulnerability Severity Classification System
    version: v2.3
    url: https://immunefi.com/immunefi-vulnerability-severity-classification-system-v2-3/
    note: Immunefi authors this taxonomy; it is not a third-party framework.
security_txt:
  present: false
  probes:
  - url: https://immunefi.com/.well-known/security.txt
    status: 308
    note: >-
      Responds 308 with a Location header pointing at the identical URL — a self-referential
      redirect loop, so no RFC 9116 document is ever served. Every /.well-known/* path on
      immunefi.com behaves the same way, including a deliberately nonsense control path.
  - url: https://bugs.immunefi.com/.well-known/security.txt
    status: 404
disclosure_policy:
  published: true
  url: https://immunefi.com/bug-bounty/immunefi/
  safe_harbor:
    signed: true
    url: https://immunefi.com/safe-harbor/
    note: >-
      Immunefi operates a Safe Harbor program (adopted from the SEAL Safe Harbor framework) and
      records "Safe Harbor Documents Signed" as a program feature on its own bounty.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/immunefi-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.