immunefi
145 employees on LinkedIn · 7 known investors
Find your way into immunefi
Immunefi is a crowdsourced security platform for Web3, offering bug bounty programs, audit competitions, invite-only programs, security audits, and PR reviews that connect protocols with security researchers to find and disclose onchain vulnerabilities. It serves web3 protocols and blockchain projects, and in 2025 launched Immunefi Magnus, a unified security operations platform for the onchain economy.
Also known as Immunefi Magnus
Founders & leadership

Investors · 7
Company profile
researched Aug 2026Immunefi is a crowdsourced security platform for Web3, founded in 2020 with the stated mission of making web3 safe for onboarding the world. Its original product is the onchain bug bounty program (BBP): protocols publish scopes, assets, impacts and reward tiers, and independent security researchers submit vulnerability reports with proof of concept for validation and payment. The company developed a scaling bounty standard under which projects reward critical vulnerabilities at a rate equivalent to roughly 10% of funds at risk, which produced unusually large payouts in software security, including $10 million for a Wormhole vulnerability and $6 million for a vulnerability in Aurora.
Since 2024 Immunefi has broadened beyond bug bounties across the web3 software development lifecycle with Audit Competitions (time-bound code reviews), Attackathons (large-scale education-based competitions with a shared reward pool), Invite-Only Programs (curated researcher groups), matchmade security Audits, and continuous PR (pull request) reviews embedded in client development processes. Commercial packages around bug bounties include a BBP subscription (annual flat fee that removes the 10% platform fee on payouts and adds Slack, Discord and PagerDuty integrations), an Enterprise subscription with a dedicated account manager and end-to-end program operation, Premium BBP restricting submissions to vetted senior researchers, and Managed Triage combining AI triage agents with human triagers plus pay-to-submit pricing to reduce spam.
In 2025 the company announced Immunefi Magnus, described as a unified security operations command center for the onchain economy, organized around four pillars: Aggregate (integrating third-party tooling for CI/CD pipeline security, audits and audit competitions, bug bounty and Safe Harbor programs, onchain monitoring and threat detection, and onchain firewalls), Orchestrate (Security Swarm automations engine for autonomous detection and mitigation), Agentify (role-specific security agents), and Evolve (Codexa, a proprietary dataset of onchain vulnerabilities, exploits, bug reports and fixes used to train Immunefi AI).
Founding story
Immunefi was founded in 2020 by CEO Mitchell Amador and launched in December 2020, premised on the view that security is the primary blocker to web3 adoption given billions lost to hacks each year. Before Immunefi, Amador was CMO of SingularityNET, worked on the Steemit social platform, and founded Instituto New Economy in Portugal. [2][6][7]
Business model
Immunefi operates a two-sided platform connecting protocols that need code reviewed with independent security researchers who are paid for validated disclosures. Protocols fund the reward pools; Immunefi provides program design, launch and co-marketing, a bug reporting dashboard, triage and validation, and communications support.
Sources describe a 10% platform fee on bug bounty payouts, which an annual flat-fee BBP subscription removes; other paid tiers include an Enterprise subscription (managed programs, dedicated account manager, multi-program support), Premium BBP as an add-on, and Managed Triage with pay-to-submit pricing for submitters. Audits, audit competitions, invite-only programs and PR reviews are additional service lines. [2][4]
Traction
Company-reported figures include $190B+ in assets under protection, $25B+ in hack damage averted, 650+ secured protocols (500+ cited elsewhere), 60,000+ whitehats in the ecosystem and 83,000+ registered security researchers, 1,600+ critical mainnet bugs found (about one critical per business day), and $116M-$125M+ paid in rewards. Immunefi states 93.9% of bug bounty programs running five years or longer surface a confirmed critical. Cited clients and testimonials include Aave, zkSync, Lido on Polygon, USDT0, ether.fi, Puffer, Synthetix, Chainlink, SushiSwap, MakerDAO, Wormhole, GMX, Alchemix, Nexus Mutual, The Graph, Polygon and Optimism. At the time of its 2022 Series A the company reported $60 million paid to whitehats. [0][2][3][4][6]
Latest developments
In 2025 Immunefi announced Immunefi Magnus, a unified onchain security operations platform with early-access registration, spanning aggregation of third-party security tooling, the Security Swarm automations engine, role-specific security agents and the Codexa vulnerability dataset. The company also publishes The Web3 Security Playbook, operational guidance for protocol teams on custody, governance, infrastructure and monitoring. [0][2]
▸Full profile — market position, technology, go-to-market, geography, history, risks & controversies
Market position
Immunefi describes itself as the leading crowdsourced security platform for Web3 and states that 92-93% of critical vulnerability disclosures in crypto flow through it. TechCrunch coverage described it as one of the emerging bug bounty and security services platforms for DeFi and identified HackerOne, which moved from Web 2.0 into web3, and key-management firm Safeheron as competitors. [0][2][4][6][7]
Positioning rests on the size and activity of its researcher community, a scaling bounty standard that ties critical-bug rewards to funds at risk (producing record payouts such as $10M for Wormhole), a proprietary dataset of onchain exploits and fixes used to train its AI, chain-agnostic coverage, and the shift from point-in-time audits to continuous review plus a single platform aggregating third-party security tooling. [0][2][3][4]
Technology
The platform includes the Immunefi Bugs Platform, a secure dashboard for receiving and managing bug reports with multi-user team access, and self-serve program management through Magnus. Immunefi AI is built on the company's dataset of blockchain exploits, bug reports and fixes (Codexa), and is used for AI triage agents, role-specific security agents, and the Security Swarm automations engine for autonomous threat detection and mitigation. Magnus also integrates third-party tools for CI/CD security, monitoring and threat detection, and onchain firewalls. [0][2][3][4]
Go-to-market
Client acquisition runs through an onboarding form and questionnaire, followed by program drafting, client review and handoff to a launch specialist who coordinates launch timing and bounty PR with the project's marketing team; Immunefi aims to respond to interested projects within five business days. Launches are co-marketed to the researcher community, and the company publishes bugfix reviews and PR guidance for patched vulnerabilities. Supply-side growth is supported by a Learn program (Initiation, Training Grounds, Mastery), severity classification frameworks, report checklists, bugfix writeups and an audit competition report library. [3][4][5]
Blockchain protocols and web3 projects across all chains and networks, from teams launching new code to established DeFi, staking, bridge and infrastructure protocols; the researcher side of the marketplace targets whitehat security researchers and bug bounty hunters, from beginners to elite. [3][4][5]
Geography
Distributed workforce of over 50 employees around the world; the platform is chain-agnostic and serves protocols across all chains and networks. [2][3]
History
The company began with bug bounty programs enabling responsible disclosure of onchain vulnerabilities and became, by its own account, the market leader for onchain BBPs. It raised $5.5 million in 2021 and a $24 million Series A led by Framework Ventures in September 2022, bringing total funding to $29.5 million. From 2024 it expanded into audit competitions, attackathons, invite-only programs, matchmade audits and PR reviews, and in 2025 announced Immunefi Magnus, a unified SecOps platform drawing on learnings from 500+ crowdsourced security programs. [2][6]
Risks & controversies
Sources note the adversarial economics of web3 security: open code and directly monetizable exploits mean researchers can be incentivized to steal rather than disclose, and the platform's model depends on payouts large enough to outcompete that incentive. Materials also cite the limits of audits, referencing Balancer's $128M loss after eleven audits by four firms, and state that the average exploit costs $24.5M. [4][6]
Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Timeline · 5
launches, deals, and filingsAnnouncement of Immunefi Magnus, a unified security operations command center for the onchain economy built on four pillars: Aggregate, Orchestrate, Agentify and Evolve (Codexa dataset), with early access registration.
From 2024 Immunefi launched Audit Competitions, Attackathons, Invite-Only Programs, matchmade Audits and PR Reviews alongside its bug bounty programs.
Series A of $24 million led by Framework Ventures with participation from Samsung Next, Electric Capital and Polygon Ventures, bringing total funding to $29.5 million.
$24M source ↗
A record $10 million bounty was paid for a vulnerability found in the Wormhole cross-chain messaging protocol; a $6 million bounty was paid for a vulnerability in Aurora.
$10M source ↗
Immunefi launched in December 2020 as a bug bounty and security services platform for web3 projects.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
▸Research sources · 8
primary sources listed
- immunefiimmunefi.com · web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does immunefi do?
- Immunefi is a crowdsourced Web3 security platform running bug bounties, audit competitions and audits for onchain protocols.
- Who founded immunefi?
- immunefi was founded by Mitchell Amador.
- Who are immunefi's investors?
- immunefi's investors include BR Capital, Electric Capital, IDEO CoLab Ventures, Lattice Capital, Marin Digital Ventures, NIV, Samsung Next.



