Quick Answer

  • Immunefi is a continuous bug bounty marketplace — programs don't expire, and severity/payout is usually scaled against the protocol's TVL (Immunefi's own guidance suggests up to 10% of funds at risk for a critical).
  • There's no first-to-find pressure like a contest, but there's real opportunity cost — time spent on a low-yield program is time not spent on a high-TVL one with sloppier code.
  • An automated scan won't find the business-logic bug that pays out — it will tell you in under a minute whether a contract even has the kind of attack surface (external calls, custom access control, unusual math) worth your time.
Continuous bug bounty

Triaging Immunefi Programs Without Burning Your First Three Hours

Immunefi programs stay open indefinitely, and payouts scale with the protocol's TVL — sometimes into seven figures for a critical finding. The bottleneck isn't motivation, it's picking which program and which contract to dig into first.

How Immunefi Works

Each Immunefi program has its own scope document, in-scope contracts, severity classification (usually Immunefi's standard 5-tier scale from critical to low), and a max payout tied to the protocol's TVL. You pick a program, read the scope, and start reviewing — there's no clock running against other researchers the way there is on a contest platform, but there's also no guaranteed payout for time spent if you don't find anything valid.

Working Immunefi Into Your Triage Pass

1

Pull the in-scope contracts

Grab the repo or the verified contract address from the program's scope page. If it's already deployed and verified, paste the address straight into a scanner instead of hunting for the GitHub repo.

2

Get an attack-surface inventory fast

Run a scan to get the function list, access-control modifiers, external call sites, and any obvious pattern hits (reentrancy shape, unchecked returns, timestamp dependence) before you've read a single line yourself.

3

Triage the findings, don't trust them

Treat every flagged pattern as a lead, not a finding. A modifier-less external function isn't a bug by itself — it tells you where to start reading closely.

4

Go deep on what the scan can't see

Business logic, economic incentive design, cross-contract invariants, and anything involving the protocol's specific accounting math is where real Immunefi payouts come from. That part is still entirely manual.

Where This Actually Helps
  • Fast function/modifier inventory on a codebase you've never seen before
  • Flagging obvious access-control gaps and reentrancy-shaped code worth a closer look
  • Deciding in minutes whether a program's scope is even worth committing hours to
  • Scanning by deployed address when a program only links a block explorer, not a repo
What It Won't Do For You
  • Find the business-logic or economic-design bug that actually pays out
  • Understand a protocol's specific accounting model or cross-contract invariants
  • Write your PoC or your report — that's still on you
  • Replace reading the actual scope document and severity classification

Why Triage Speed Matters Even Without a Contest Clock

Immunefi doesn't reward being first the way Code4rena or Sherlock contests do — there's no duplicate-splitting mechanic. But there's still a real cost to spending six hours reading a contract that turns out to be a thin wrapper around a well-audited library with nothing custom in it.

A fast pattern scan across the in-scope contracts tells you which files actually have custom logic worth your time versus which ones are boilerplate ERC-20/ERC-721 extensions you've already seen a hundred times. That's the actual value: allocating your limited hours toward the contracts that look different, not finding the bug for you.

Scanning by Address When There's No Clean Repo

Plenty of Immunefi scope pages link a deployed contract address on a block explorer rather than a clean GitHub repo, especially for older or forked protocols. Paste the address directly — SmartContractAuditor.ai pulls the verified source from Etherscan, BscScan, Polygonscan, Arbiscan, or the Optimism explorer and runs the same scan you'd get from pasted code.

If the contract isn't verified on the explorer, that's itself worth noting — an unverified contract in scope for a bug bounty is unusual and sometimes a sign the program is newer or less mature than its payout table suggests.

Frequently Asked Questions

Duron Epps, Founder — SmartContractAuditor.ai
Last updated August 2026

Get an Attack-Surface Read Before You Commit Hours

Paste code, upload a file, or scan a live Immunefi target by its deployed address.

Free scan · No sales call · By-address scanning covers Ethereum, BSC, Polygon, Arbitrum, Optimism