@immunefi

Immunefi is the leading security platform for blockchains. Over $180B of user funds protected across 650+ protocols.

Get full onchain protection ➡️
Joined November 2020
Immunefi is the security infrastructure layer of crypto. We protect 70% of all DeFi TVL today. Our track record: - We work with virtually every major DeFi project: Aave, Arbitrum, Optimism, Sei, LayerZero, Ethena, Jito, ENS, The Graph, and so many more - Multiple $10M+ bounty payouts, the largest in internet history - $25 billion+ in losses prevented, calculated based on the severity and exploitability of vulnerabilities disclosed - $125m in payouts to security researchers - 80% of customers have received valid critical vulnerability disclosures via the platform - Thousands of valid vulnerability reports processed, creating the industry's most comprehensive dataset of real exploits The Immunefi token ($IMU) is the central value creation asset powering the entire Immunefi ecosystem, so that it can grow to protect all onchain value. And it will. Join us.
116
142
55
441
83,140
Happy weekend to all the security researchers out there hunting
6
7
1
94
3,449
Why should you, as an AI security agent builder, choose Immunefi? Immunefi gives you a real-world environment to test, benchmark, and prove what your agent can actually do. ✦ There are currently 174 programs on Immunefi with a combined maximum bounty pool of $109.5 million, including some of the most consequential protocols in DeFi. These are protocols protecting or moving billions of dollars. ✦ Immunefi’s leaderboard gives agent builders a way to prove performance through outcomes validated by a neutral third party. ✦ Immunefi Studio helps reduce noise before reports ever reach projects, giving teams a way to catch false positives, improve report quality, and increase their agent’s accuracy over time. ✦ And because other AI security agents are hunting on the same platform, operators can benchmark their performance against other agents using real, verifiable results. If you are building an AI security agent, DM us!
6
4
31
3,171
This security researcher just earned $150k from a single report. That’s 2.5 years of Harvard tuition or a Porsche 911, however you like to spend your money. The payout pushes them to #5 on the 90-day leaderboard and #22 on the 2026 leaderboard. There’s still a lot on the table in 2026 for security researchers hungry enough to go after it. Congrats @SagaKrypto 🎉
14
7
6
277
11,018
For years, this has been and continues to be one of the most frustrating experiences a whitehat can have: submitting a report and getting back “duplicate” without any transparency. That is why we have been innovating our product around this issue. Now, when your report is closed as a duplicate, you get a detailed report showing: ✦ The original report ✦ When it was submitted ✦ Severity and status
Very weird times at the ASB - opened my pending vulnerabilities, all are acknowledged, but all of the sudden 60% of them are now marked as "duplicates with internal findings". The problem is that there's no way to know that besides taking Apple's word as it is.
15
6
1
89
11,263
A blackhat hacker attempted to drain roughly $7.8 million in rsETH from a Safe wallet, only to have the exploit front-run by an MEV bot that took the funds first. This is why you should never try to whitehat funds if you do not have explicit authorization. The moment you broadcast the transaction, you can expose the exploit path to bots and other attackers and lose control of the funds entirely.
5
4
46
4,742
“AI systems are adding capabilities to query systems, to use our code, to download arbitrary packages. This inevitably is going to be the next crypto attack vector.” • Alec Harrell, Security Lead at Jito Immunefi provides continuous security through bug bounties built to help projects catch emerging attack vectors like these.
2
2
27
3,046
Thank you to every AI agent builder who has reached out to test and benchmark their agents on Immunefi. We are committed to building better infrastructure for the growing number of security researchers using AI agents on Immunefi, not to building attacking agents to compete with you. We want to help them improve their workflows, increase accuracy, benchmark performance, and understand how their agents compare against others. Immunefi is the place where AI security agents can prove how well they perform in the real world. If you are building an AI security agent, send us a DM.
8
6
1
55
4,398
Tomorrow, Immunefi founder and CEO @MitchellAmador takes the stage at @EBlockchainCon alongside other industry leaders. If you’re a founder or security leader in Barcelona, come hear Mitchell discuss one of the hardest questions in security: how should you spend a limited security budget to maximize protection? His perspective is backed by years of internal Immunefi data and insights from across the crypto security industry. See you in Barcelona!
1
4
1
30
3,098
An SR Summer winner just found a Critical vulnerability, earning him a $25,000 bounty. @skydev0h joined Immunefi in April 2026 and has already earned $44,000 in bounties. He has also been one of the most active users of Immunefi Studio, consistently testing it and sharing valuable feedback with the team. So it is no surprise that his submission accuracy rate now sits at 90%, earning him a High-Signal SR classification. SR Summer may be over, but the run continues. Congrats, @skydev0h! 🎉
8
3
1
137
5,796
Wishing this for every security researcher who likes this post.
9
7
1
279
6,166
Immunefi retweeted
This is now live for selected programs, and some of you already have access! Right now, it’s a rich reader. As mentioned, we’ll keep adding features to make it more useful for our SRs. Want an invite? DM me, but only if you bring a feature request 😏
Security researchers, we’re prototyping InstaScope V3 directly inside Immunefi Studio. The idea is that you can open an Immunefi bug bounty and immediately explore its verified in-scope contracts, organized by chain and deployed target. You can inspect proxy and implementation source, navigate the complete file tree, review source snapshots and ABI functions, and generate a Foundry project when you’re ready. But the editor is only the base layer. What security context or protocol modeling would make this genuinely useful for your investigations? Live on-chain state? Call graphs? Storage layouts and inheritance? Privileged roles and access control? Cross-chain relationships? Duplicates map? Known attack surfaces? Something else entirely? Please share your ideas, including ambitious ones. I’ll try to add the feasible suggestions in weekly iterations until this becomes somewhere you spend more time investigating than in your local editor. Honest feedback is very welcome, including “I wouldn’t use this,” as long as you tell me why 🙂
4
7
1
13
3,563
Security has felt pretty gloomy lately with all the hacks happening, so here’s some data to cheer you up: ✦ For every critical vulnerability exploited, roughly four were caught and responsibly disclosed first. ✦ Out of ~1,238 criticals responsibly disclosed during a certain period , there were ~320 criticals exploited. ✦ Of those 1,238 criticals caught, 1,143 were submitted through Immunefi by security researchers. ✦ That means roughly 93% of all responsibly disclosed criticals in crypto went through Immunefi. Hacks might get all the headlines, but vulnerabilities that stop before they become hacks usually don’t. Don't become a statistic, get secured on Immunefi
6
6
43
3,470
The number of security researchers who have received a pledge has now climbed to 409, up from 399 just a few days ago. More and more people are backing the capabilities of elite security researchers. No matter how much AI advances, security is not going away. As long as software exists, there will be vulnerabilities to find, systems to defend, and value at risk. The researchers who consistently prove they can find those vulnerabilities will capture a growing share of that value. Many of those researchers are already on Immunefi, with years of public performance data backing their reputation. In August 2026 alone, 128 unique researchers received a payout on Immunefi. Hacker Pledging lets $IMU holders back those researchers and earn rewards when they earn bounties. When a researcher finds a valid bug and gets paid, their pledgers can earn too.
1
3
34
3,376
This Junior Security Researcher just found his first valid bug! 🎉 He joined Immunefi in April 2026, and his first paid report is a High-severity vulnerability that earned him $40,000. With just one paid report, he jumped to #28 on the Immunefi 90-day leaderboard and #80 on the 2026 leaderboard. He also has a few confirmed reports still in the pipeline, so his ranking could climb even higher. Very impressive start. Congrats sl90!
4
14
1
262
8,809
If you are a founder deciding where to put a limited security budget, how do you think about the best way to spend your money while maximizing the security you get in return? Immunefi CEO @MitchellAmador takes the stage at @EBlockchainCon 2026 on September 17th in Barcelona, alongside other panelists, to answer this question and more for founders and security personnel. Meet Mitchell in Barcelona on September 17!
3
3
1
36
3,753
The @ensdomains Audit Competition submissions are officially close. The competition is now entering evaluation. Check the competition page for updates as submissions are reviewed: immunefi.com/audit-competiti…
4
3
2
36
5,688
If you are building an AI security agent, Immunefi is where it gets graded. Live programs, real bounties, and an accuracy rate on your submissions. Studio Review even gives you feedback on your report before you submit it. It uses the same triaging agent our triage team uses, backed by every report ever submitted to Immunefi. One agent is already ranked #17 on our 2026 leaderboard, against every human researcher on the platform. We do not run attack agents competing with you. We build tools for the researchers hunting here, agents included. Studio is currently invite-only. DM us to get your agent in.
15
9
5
57
6,132
In just six weeks, @ret2basic has had 17 confirmed or paid reports. That is almost three per week. He has found bugs across a range of attack surfaces, including Web/App, Smart Contracts, and Blockchain/DLT. He now sits at 45 on the 90-day leaderboard, but with multiple confirmed but unpaid reports still in the pipeline, he'll likely break into the top 20 very soon. Do you think you can take a spot on the leaderboard?
6
2
1
116
10,934
The @ensdomains Audit Competition closes on Monday, with less than 3 days left to hunt. The full $70,000 reward pool has now been unlocked, which means the entire pot will be distributed to eligible findings. If you have been waiting for the right moment to jump in, this is it. Take your shot at a share of the $70K before submissions close: immunefi.com/audit-competiti…
1
2
1
36
3,881
Immunefi Studio helps security researchers turn good findings into stronger reports before they reach your inbox. Studio Review checks reports for PoC clarity, impact framing, completeness, and duplicate risk, then gives researchers specific feedback they can use to improve the report before submitting. This gives projects clearer reports to assess, and it stops real vulnerabilities from getting buried in weak write-ups. When you list your bug bounty on Immunefi, you get access to researchers finding 40 to 50 confirmed criticals a month across the biggest crypto protocols, along with the tools that help them prove it. Studio Review is in invite-only beta.
7
5
1
40
3,473