Quick Answer
Immunefi programs stay open indefinitely, and payouts scale with the protocol's TVL — sometimes into seven figures for a critical finding. The bottleneck isn't motivation, it's picking which program and which contract to dig into first.
Each Immunefi program has its own scope document, in-scope contracts, severity classification (usually Immunefi's standard 5-tier scale from critical to low), and a max payout tied to the protocol's TVL. You pick a program, read the scope, and start reviewing — there's no clock running against other researchers the way there is on a contest platform, but there's also no guaranteed payout for time spent if you don't find anything valid.
Pull the in-scope contracts
Grab the repo or the verified contract address from the program's scope page. If it's already deployed and verified, paste the address straight into a scanner instead of hunting for the GitHub repo.
Get an attack-surface inventory fast
Run a scan to get the function list, access-control modifiers, external call sites, and any obvious pattern hits (reentrancy shape, unchecked returns, timestamp dependence) before you've read a single line yourself.
Triage the findings, don't trust them
Treat every flagged pattern as a lead, not a finding. A modifier-less external function isn't a bug by itself — it tells you where to start reading closely.
Go deep on what the scan can't see
Business logic, economic incentive design, cross-contract invariants, and anything involving the protocol's specific accounting math is where real Immunefi payouts come from. That part is still entirely manual.
Immunefi doesn't reward being first the way Code4rena or Sherlock contests do — there's no duplicate-splitting mechanic. But there's still a real cost to spending six hours reading a contract that turns out to be a thin wrapper around a well-audited library with nothing custom in it.
A fast pattern scan across the in-scope contracts tells you which files actually have custom logic worth your time versus which ones are boilerplate ERC-20/ERC-721 extensions you've already seen a hundred times. That's the actual value: allocating your limited hours toward the contracts that look different, not finding the bug for you.
Plenty of Immunefi scope pages link a deployed contract address on a block explorer rather than a clean GitHub repo, especially for older or forked protocols. Paste the address directly — SmartContractAuditor.ai pulls the verified source from Etherscan, BscScan, Polygonscan, Arbiscan, or the Optimism explorer and runs the same scan you'd get from pasted code.
If the contract isn't verified on the explorer, that's itself worth noting — an unverified contract in scope for a bug bounty is unusual and sometimes a sign the program is newer or less mature than its payout table suggests.