Immunefi is the leading security platform for blockchains. Over $180B of user funds protected across 650+ protocols.

Get full onchain protection ➡️
Pinned Tweet
Immunefi is the security infrastructure layer of crypto. We protect 70% of all DeFi TVL today. Our track record: - We work with virtually every major DeFi project: Aave, Arbitrum, Optimism, Sei, LayerZero, Ethena, Jito, ENS, The Graph, and so many more - Multiple $10M+ bounty payouts, the largest in internet history - $25 billion+ in losses prevented, calculated based on the severity and exploitability of vulnerabilities disclosed - $125m in payouts to security researchers - 80% of customers have received valid critical vulnerability disclosures via the platform - Thousands of valid vulnerability reports processed, creating the industry's most comprehensive dataset of real exploits The Immunefi token ($IMU) is the central value creation asset powering the entire Immunefi ecosystem, so that it can grow to protect all onchain value. And it will. Join us.
116
142
447
85,320
Immunefi retweeted
A big, heavily promoted bounty pool doesn’t mean you’ll ever see a dime. The clearest proof of real security value for bug bounty customers is simple: money paid out to researchers. Always has been. Always will be.
I scraped every directory page, every live program listing, every figure a crypto bug bounty platform has put in writing, all to give you the best overview of bug bounty platform impact ever written. You'll find it all here.
Article

Bounty Pools Are Marketing, Bounty Payouts Are Security: A Review of Bug Bounty Platforms

Five platforms host crypto bug bounties. Just three will tell you how much they have paid. If you’re a protocol deciding where to host a bounty, or a researcher deciding where to hunt, those numbers

2
2
32
3,403
Immunefi retweeted
This security researcher just earned $15K for finding a High severity bug in a smart contract 🔥 He has now earned $30K from just two paid reports in 2026. With this latest payout, his all-time earnings have jumped to over $53K, putting him in the top 100 on the 2026 leaderboard. Congrats @Anh084879445581! 🎉 A few months still left. Start hunting!
3
3
99
2,982
Immunefi retweeted
🥊
1
16
130
4,544
This junior security researcher just got his first-ever payout! 🎊 Gab found his first critical smart contract bug, netting him a whopping $10K. Out of nowhere, he rocketed into the top 100 on the @Immunefi leaderboard, landing at #80 while still a junior researcher. Congrats, Gab! 🔥
9
5
140
5,201
Bitget has lost around $351.6M from its hot and warm wallets this evening, CEO Gracy Chen confirmed. That makes this the largest crypto hack of 2026 so far, per @DefiLlama. Bitget says user funds are safe and withdrawals are paused.
[SECURITY NOTICE] Bitget Hot Wallet Incident — September 24, 2026 At 18:31 UTC on September 24, 2026, Bitget's security systems detected unauthorized transfers from some of our hot wallets. Our security team activated emergency response protocols immediately. What we have confirmed: -Estimated funds affected: approximately $351.6 million -Cold wallets remain fully secure. Bitget operates a three-tier wallet architecture — the breach contained only a portion of the hot wallet and warm wallet layers. -User funds are safe. The full amount of this loss falls within the coverage of Bitget's User Protection Fund, which currently holds over $464 million Actions we have taken: -Emergency response team activated within minutes of detection -Abnormal transfer addresses identified, flagged, and reported -Withdrawals temporarily suspended as a precautionary measure, pending security review -Law enforcement and on-chain security firms have been formally notified and are engaged What this means for you: -Your account balances are accurate and your assets are protected -Deposits and trading remain fully operational Withdrawals are temporarily paused and will be restored as soon as the security review is complete -What comes next: We will provide updates on an hourly basis across this channel and all official platforms. A full incident report — including root cause analysis and corrective actions — will be published within 24 hours. We will not speculate on the attack vector until the investigation is complete. Bitget has navigated multiple market cycles. We will not run from this. Every dollar and every decision will be accounted for, transparently and in full. Updates will be posted here and across all official Bitget channels as they become available. — Gracy Chen, CEO, Bitget
9
3
55
4,882
Bitget has not named the attack vector yet. But if this year is any indication, the odds point to operational infrastructure. In H1 2026, those attacks were about 15% of hacks but responsible for 76% of losses, per @trmlabs.
1
9
652
The August 2026 Immunefi Ecosystem Update is here: Attackers had their busiest month of 2026. So did researchers on Immunefi. Immunefi platform: ➡️ Biggest month on record in terms of confirmed vulnerabilities; researchers submitted 424 valid reports against 154 in August 2025, and confirmed criticals went from 14 to 126. ➡️ Payouts rose 12% year over year, and researcher payouts passed $143 million all-time. Immunefi paid $802,000 to 126 whitehats in August. Foundation: ➡️ Hacker Pledging backers earned 1.23M+ IMU Full Breakdown: docs.immunefi.foundation/aug…
2
10
867
Security researcher @brandon_shi just found a critical vulnerability, netting him a $50k bounty! This jumps him to #19 on the 90-day leaderboard, with $56k earned in the past 90 days alone. 2026 is shaping up to be one of the most profitable years for several security researchers on Immunefi. A few months still left. Start hunting!
11
3
154
7,241
AI security agents are going to find many of the same bugs. That also means they could share the same blind spots. But how do you know what your agent keeps missing if you only test it in isolation? Hunting on Immunefi shows you how your agent competes with other agents on real-world targets. Immunefi Studio takes it one step further. Without submitting reports, you can see where it performs well, where it falls short, and what you need to improve to make it more accurate and efficient. If you're building or working on an AI security agent, send us a DM.
7
1
33
3,241
Security researcher @v4rvl is the Best Community Contributor for the @QuantusNetwork audit competition. From actively supporting other security researchers in Discord to providing extensive, structured feedback on how we could improve the competition, triage, and overall process, @v4rvl made a real impact beyond just finding bugs. Thank you @v4rvl 🫶
3
3
58
3,865
Security researcher Naresh_Kandula identified the Most Valuable Finding in the @QuantusNetwork Audit Competition. Report ID: 88609 Here's what Quantus had to say: "The report identifies a high-security account bypass that allows an attacker with a compromised key to bypass the guardian delay and drain almost the entire account balance in a single block by attaching a massive tip to a failing whitelisted call." Congrats on the finding, Naresh!
8
3
87
5,340
Security researcher @skydev0h had the highest accuracy rate in the @QuantusNetwork audit competition, with 3/3 submissions confirmed as valid reports. Across Immunefi, Skydev has a 90% accuracy rate, with 45 valid reports out of 50 resolved submissions. He has also earned over $44k in the last 90 days and is speedrunning the Immunefi leaderboard, now sitting at 14th. He’s also one of the biggest power users of Immunefi Studio and provides us with valuable feedback. Absolute monster!
4
2
76
4,110
The @QuantusNetwork Audit Competition is a wrap! 🏆 Top Winners: 🥇 @therealbytes - $3,286 🥈 @ZealynxSecurity - $2,366 🥉 @Valistheaeth - $2,145 🏅@hnaito_eth - $1,449 🏅@maakayjunior - $1,324 Congrats to all participants & winners! 🎖
5
6
82
22,565
Two new columns now exist on the leaderboard: chief findings and duplicates, shown per researcher. ✦ Quantus had 143 confirmed valid submissions ✦ 66 were original findings ✦ 77 were duplicates ✦ One high-severity bug was reported 25 times 📊 Leaderboard: immunefi.com/audit-competiti…
2
10
1,614