Fundraising Fox

immunefi

145 employees on LinkedIn · 7 known investors

Find your way into immunefi

Immunefi is a crowdsourced security platform for Web3, offering bug bounty programs, audit competitions, invite-only programs, security audits, and PR reviews that connect protocols with security researchers to find and disclose onchain vulnerabilities. It serves web3 protocols and blockchain projects, and in 2025 launched Immunefi Magnus, a unified security operations platform for the onchain economy.

Also known as Immunefi Magnus

Founders & leadership

MAMitchell Amador
Mitchell AmadorinFounder · Chief Executive OfficerHe also founded Instituto New Economy, a blockchain think tank and association based in Portugal.

Investors · 7

Company profile

researched Aug 2026

Immunefi is a crowdsourced security platform for Web3, founded in 2020 with the stated mission of making web3 safe for onboarding the world. Its original product is the onchain bug bounty program (BBP): protocols publish scopes, assets, impacts and reward tiers, and independent security researchers submit vulnerability reports with proof of concept for validation and payment. The company developed a scaling bounty standard under which projects reward critical vulnerabilities at a rate equivalent to roughly 10% of funds at risk, which produced unusually large payouts in software security, including $10 million for a Wormhole vulnerability and $6 million for a vulnerability in Aurora.

Since 2024 Immunefi has broadened beyond bug bounties across the web3 software development lifecycle with Audit Competitions (time-bound code reviews), Attackathons (large-scale education-based competitions with a shared reward pool), Invite-Only Programs (curated researcher groups), matchmade security Audits, and continuous PR (pull request) reviews embedded in client development processes. Commercial packages around bug bounties include a BBP subscription (annual flat fee that removes the 10% platform fee on payouts and adds Slack, Discord and PagerDuty integrations), an Enterprise subscription with a dedicated account manager and end-to-end program operation, Premium BBP restricting submissions to vetted senior researchers, and Managed Triage combining AI triage agents with human triagers plus pay-to-submit pricing to reduce spam.

In 2025 the company announced Immunefi Magnus, described as a unified security operations command center for the onchain economy, organized around four pillars: Aggregate (integrating third-party tooling for CI/CD pipeline security, audits and audit competitions, bug bounty and Safe Harbor programs, onchain monitoring and threat detection, and onchain firewalls), Orchestrate (Security Swarm automations engine for autonomous detection and mitigation), Agentify (role-specific security agents), and Evolve (Codexa, a proprietary dataset of onchain vulnerabilities, exploits, bug reports and fixes used to train Immunefi AI).

Founding story

Immunefi was founded in 2020 by CEO Mitchell Amador and launched in December 2020, premised on the view that security is the primary blocker to web3 adoption given billions lost to hacks each year. Before Immunefi, Amador was CMO of SingularityNET, worked on the Steemit social platform, and founded Instituto New Economy in Portugal. [2][6][7]

Business model

Immunefi operates a two-sided platform connecting protocols that need code reviewed with independent security researchers who are paid for validated disclosures. Protocols fund the reward pools; Immunefi provides program design, launch and co-marketing, a bug reporting dashboard, triage and validation, and communications support.

Sources describe a 10% platform fee on bug bounty payouts, which an annual flat-fee BBP subscription removes; other paid tiers include an Enterprise subscription (managed programs, dedicated account manager, multi-program support), Premium BBP as an add-on, and Managed Triage with pay-to-submit pricing for submitters. Audits, audit competitions, invite-only programs and PR reviews are additional service lines. [2][4]

Traction

Company-reported figures include $190B+ in assets under protection, $25B+ in hack damage averted, 650+ secured protocols (500+ cited elsewhere), 60,000+ whitehats in the ecosystem and 83,000+ registered security researchers, 1,600+ critical mainnet bugs found (about one critical per business day), and $116M-$125M+ paid in rewards. Immunefi states 93.9% of bug bounty programs running five years or longer surface a confirmed critical. Cited clients and testimonials include Aave, zkSync, Lido on Polygon, USDT0, ether.fi, Puffer, Synthetix, Chainlink, SushiSwap, MakerDAO, Wormhole, GMX, Alchemix, Nexus Mutual, The Graph, Polygon and Optimism. At the time of its 2022 Series A the company reported $60 million paid to whitehats. [0][2][3][4][6]

Latest developments

In 2025 Immunefi announced Immunefi Magnus, a unified onchain security operations platform with early-access registration, spanning aggregation of third-party security tooling, the Security Swarm automations engine, role-specific security agents and the Codexa vulnerability dataset. The company also publishes The Web3 Security Playbook, operational guidance for protocol teams on custody, governance, infrastructure and monitoring. [0][2]

Full profile — market position, technology, go-to-market, geography, history, risks & controversies

Market position

Immunefi describes itself as the leading crowdsourced security platform for Web3 and states that 92-93% of critical vulnerability disclosures in crypto flow through it. TechCrunch coverage described it as one of the emerging bug bounty and security services platforms for DeFi and identified HackerOne, which moved from Web 2.0 into web3, and key-management firm Safeheron as competitors. [0][2][4][6][7]

Positioning rests on the size and activity of its researcher community, a scaling bounty standard that ties critical-bug rewards to funds at risk (producing record payouts such as $10M for Wormhole), a proprietary dataset of onchain exploits and fixes used to train its AI, chain-agnostic coverage, and the shift from point-in-time audits to continuous review plus a single platform aggregating third-party security tooling. [0][2][3][4]

Technology

The platform includes the Immunefi Bugs Platform, a secure dashboard for receiving and managing bug reports with multi-user team access, and self-serve program management through Magnus. Immunefi AI is built on the company's dataset of blockchain exploits, bug reports and fixes (Codexa), and is used for AI triage agents, role-specific security agents, and the Security Swarm automations engine for autonomous threat detection and mitigation. Magnus also integrates third-party tools for CI/CD security, monitoring and threat detection, and onchain firewalls. [0][2][3][4]

Go-to-market

Client acquisition runs through an onboarding form and questionnaire, followed by program drafting, client review and handoff to a launch specialist who coordinates launch timing and bounty PR with the project's marketing team; Immunefi aims to respond to interested projects within five business days. Launches are co-marketed to the researcher community, and the company publishes bugfix reviews and PR guidance for patched vulnerabilities. Supply-side growth is supported by a Learn program (Initiation, Training Grounds, Mastery), severity classification frameworks, report checklists, bugfix writeups and an audit competition report library. [3][4][5]

Blockchain protocols and web3 projects across all chains and networks, from teams launching new code to established DeFi, staking, bridge and infrastructure protocols; the researcher side of the marketplace targets whitehat security researchers and bug bounty hunters, from beginners to elite. [3][4][5]

Geography

Distributed workforce of over 50 employees around the world; the platform is chain-agnostic and serves protocols across all chains and networks. [2][3]

History

The company began with bug bounty programs enabling responsible disclosure of onchain vulnerabilities and became, by its own account, the market leader for onchain BBPs. It raised $5.5 million in 2021 and a $24 million Series A led by Framework Ventures in September 2022, bringing total funding to $29.5 million. From 2024 it expanded into audit competitions, attackathons, invite-only programs, matchmade audits and PR reviews, and in 2025 announced Immunefi Magnus, a unified SecOps platform drawing on learnings from 500+ crowdsourced security programs. [2][6]

Risks & controversies

Sources note the adversarial economics of web3 security: open code and directly monetizable exploits mean researchers can be incentivized to steal rather than disclose, and the platform's model depends on payouts large enough to outcompete that incentive. Materials also cite the limits of audits, referencing Balancer's $128M loss after eleven audits by four firms, and state that the average exploit costs $24.5M. [4][6]

Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.

Key figures

latest reported
Assets under protectionJan 2025$190B
Bounties paidJan 2025$125M
Bug bounty programs running five or more years that surface a confirmed criticalJan 202593.9%
Critical mainnet bugs foundJan 20251,600 bugs
EmployeesJan 202550 employees
Onchain hack damage avertedJan 2025$25B
Paid out to whitehat hackersSep 2022$60M
Registered security researchersJan 202583,000 researchers
Rewards paid to security researchersJan 2025$116M
Secured protocolsJan 2025650 protocols
Security researchers in ecosystemJan 202560,000 researchers
Share of Web3 critical vulnerability reports handledJan 202592%
Total funding raisedSep 2022$29.5M

Company-reported or press-reported figures, each dated to when it was claimed — not independently audited.

Timeline · 5

launches, deals, and filings
Jan 2025
Immunefi Magnus announced

Announcement of Immunefi Magnus, a unified security operations command center for the onchain economy built on four pillars: Aggregate, Orchestrate, Agentify and Evolve (Codexa dataset), with early access registration.

source ↗

Jan 2024
Expansion beyond bug bounties into audit competitions and related services

From 2024 Immunefi launched Audit Competitions, Attackathons, Invite-Only Programs, matchmade Audits and PR Reviews alongside its bug bounty programs.

source ↗

Sep 2022
Immunefi raises $24M Series A led by Framework Ventures

Series A of $24 million led by Framework Ventures with participation from Samsung Next, Electric Capital and Polygon Ventures, bringing total funding to $29.5 million.

$24M source ↗

Jan 2022
$10M bug bounty payout for Wormhole vulnerability

A record $10 million bounty was paid for a vulnerability found in the Wormhole cross-chain messaging protocol; a $6 million bounty was paid for a vulnerability in Aurora.

$10M source ↗

Dec 2020
Immunefi platform launch

Immunefi launched in December 2020 as a bug bounty and security services platform for web3 projects.

source ↗

Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.

Research sources · 8

primary sources listed

8 public sources were cited for this profile; the first-party ones are listed here.

Frequently asked questions

What does immunefi do?
Immunefi is a crowdsourced Web3 security platform running bug bounties, audit competitions and audits for onchain protocols.
Who founded immunefi?
immunefi was founded by Mitchell Amador.
Who are immunefi's investors?
immunefi's investors include BR Capital, Electric Capital, IDEO CoLab Ventures, Lattice Capital, Marin Digital Ventures, NIV, Samsung Next.