Five platforms host crypto bug bounties. Just three will tell you how much they have paid. If you’re a protocol deciding where to host a bounty, or a researcher deciding where to hunt, those numbers are the single most important factors for determining your security destiny… they determine whether you get real security results, and if you will actually get paid for delivering security impact.
I run one of those platforms (Immunefi), and I’m going to show you every number that matters to running a bug bounty program, including the ones that don’t flatter us.
There’s no standard way to compare bug bounty platforms. Every platform reports differently, and some don’t report at all. There’s no third-party auditor, no industry standard, no common framework… so we counted everything ourselves. Every directory page, every live program listing, every figure a platform has put in writing, you’ll find them here.
Here’s the TL;DR circa 2026:
Immunefi has paid out $137M in bug bounties, more than all other crypto bug bounty platforms combined, based on disclosed figures. The next closest is HackenProof at $26M. Immunefi has made 29 individual bounty payments of $1 million or more.
Bounty pool size predicts almost nothing in real security outcomes delivered to customers. Cantina lists 59% of Immunefi’s bounty pool and has paid 1.9% of what Immunefi has paid.
Total Paid-to-bounty-pool conversion varies dramatically between platforms. HackenProof has paid 1.8x its live bounty pool ($26m in payouts to $14.3m in their total bounty pool), Immunefi 1.25x ($137m in payouts to $109m in total bounties); Cantina 0.04x ($2.6m bounties paid vs $64.8m in total bounties).
Payouts
Payouts are the honest measure of what reaches security researchers, and the truest measure of security value delivered to end-customers. They are proof of real, positive sum security impact valued so highly that customers are willing to pay for it, no matter if it is a $10,000 or $10 million bounty. They are the ultimate measure and proof of business value in the security industry, for if they were not valuable customers would not pay the bounties.
Immunefi has paid out $137 million in bug bounty program payouts. That number deliberately excludes audit competitions, invite-only programs, and private audits, so it reflects only what researchers earned by finding vulnerabilities through bug bounty programs on live code.
The next closest platform is HackenProof, at $26 million, according to their own website. They are the second-largest bug bounty platform in crypto when it comes to payouts.
After HackenProof comes Cantina, at approximately $2.6 million, the latest data publicly shared by Cantina as of March 2026 (which is all we could find).
Then there are platforms that don’t publish payout data at all. Sherlock has no public figures, and Code4rena published none before their shutdown. How much researchers have actually earned at each is unknown.
Rank the platforms by bounty pool and Cantina comes second, HackenProof fourth. Rank them by bounties paid and the order flips. HackenProof second, Cantina last.
Cantina lists 59% of Immunefi’s bounty pool but has only paid 1.9% of what Immunefi has paid to security researchers. HackenProof lists 13% and has paid 19%.
There has been a longstanding critique that some bug bounty programs and their bounty pools are not real (‘ghost bounties’ or ‘fake bounties’), that advertising a bug bounty costs nothing until someone finds a bug and so constitutes ‘free marketing’ up until that moment. Our own data shows that bug bounty programs themselves really work: 94% of long-running Immunefi programs have surfaced and paid out a critical vulnerability.
So when a platform advertises large pools but pays almost nothing year after year, the problem cannot be the bug bounty model (proven to work elsewhere); it must be the platform hosting it. Using these metrics, we can identify which platforms are in the business of security outcomes and which are in the business of security marketing.
Returning to actual payouts, Immunefi has paid out more than Cantina and HackenProof combined by a wide margin. The gap between Immunefi and the number two is roughly $111 million (multiples of all other platforms put together). Immunefi has paid $15.8 million in 2026 through August. HackenProof reports $26 million across its entire history. No credible assumptions about Sherlock or Code4rena payouts get all four even close to $137 million.
Transparency
Transparency matters for two audiences.
Protocols need to justify security spending to investors, users, and tokenholders. When a company allocates $500,000 to a bug bounty, the community wants to know the platform’s track record of actually paying out. Reasonably so.
Researchers need confidence their work will be rewarded. A bounty that looks attractive on paper but sits on a platform with no public payout history is a harder sell than one backed by $137 million in documented payouts.
Immunefi publishes most individual payouts above $10,000 on our X feed to feature the security researchers who have earned bounties above a certain severity level, usually high or critical. Behind the bigger ones sit bugfix reviews going back years, breaking down the vulnerability and what the disclosure protected.
When Wormhole pays out $10 million through Immunefi, or a whitehat collects a $3 million bounty, you can find it. In an industry where trust is hard to come by and skepticism is the default, payout records are everyone’s main proof of work.
The programs running on Immunefi protect over $180 billion in user funds. The $137 million is what it has cost to repeatedly find bugs, with our platform now uncovering over 40 live critical vulnerabilities a month.
Immunefi has made 5,818 individual payments to security researchers, 29 of them $1 million or more.
HackenProof posts a $26 million headline and publishes monthly payout recaps, broken down by severity with named top earners. They are the one competitor that does (and kudos to them for doing so).
Cantina’s own opportunities page reports $54.1 million total paid out, listed beside 144 ended competitions and 49 live bounties. But their own March 2026 statement puts total bounty payouts at $2.6m. There is no independent validation of their payouts.
Sherlock does not publish any information on aggregate payouts, and neither did Code4rena.
Two platforms out of five show you who got paid. The rest ask you to take their word.
Security Researchers
Bug bounties are a two-sided market. The bounty attracts researchers. The researchers find bugs. More researchers, more bugs found. The size and quality of a platform’s researcher community is one of the strongest predictors of its security value.
Immunefi reports over 85,000 registered security researchers. HackenProof reports 82,000. Then a significant drop: Code4rena, prior to their shutdown, reported 16,600, meanwhile Cantina claims 22,400+, and Sherlock claims 11,000. There is no independent way to verify these figures, so we rely on what each platform says about its own researcher base.
In 2020 I estimated there were fewer than a thousand serious security professionals responsible for all key industry security duties, spread across infrastructure, auditing, and hunting for bugs in mission-critical code. Under 1,000 in total then. 85,000 registered now. We’ve come a long way.
On community size alone, Immunefi and HackenProof look comparable. Both have built security researcher communities that dwarf the rest of the field, and they are the two oldest surviving bug bounty platforms in the industry.
But in the end, community size is an input. What truly matters is what it outputs.
Immunefi’s registered base has generated $137 million in bounty payouts. HackenProof’s has generated $26 million. Roughly 5:1 in output from comparably sized pools.
The highest payouts on record pull the best hackers alive. They hunt where the money is proven to be. A platform that can demonstrate $137 million in payouts attracts the kind of researcher who finds $10 million bugs. That researcher’s presence attracts the kind of protocol willing to post $10 million bounties. This dynamic is self-reinforcing, and it’s hard to break once it’s turning.
For smaller platforms the challenge is structural. You can build a community, but until that community has a track record of major payouts, it’s hard to attract the programs that would create those payouts. The classic cold start problem.
We know first hand how hard that is. It took years and 100+ programs to get Immunefi to the scale where the network effects began working in our favor.
Program Breadth
Immunefi runs 174 live bug bounty programs, one per protocol. Cantina runs 43, Sherlock 34, and Code4rena none, having wound down its bounties and moved them to Immunefi. HackenProof’s are a little harder to calculate, so we’ll show our work.
HackenProof’s own site advertises 400+ programs. Pulling the directory shows 324 entries, and once the ended and paused listings come out, 152 are live. HackenProof also lets one project post a separate listing for each attack surface. 26 protocols appear more than once, with the directory listing Near 7 times.
Immunefi counts one protocol as one program, no matter how many surfaces sit in scope. LayerZero is a single entry whether the bounty covers contracts, endpoints, or both. Collapse HackenProof’s listings the same way, one entry per protocol, and 152 live listings resolve to 110 unique protocols on HackenProof.
Looking further, program count tells you how many listings a platform has. But it does not tell you anything about what those programs are really worth.
HackenProof’s 110 protocols carry $14.3 million in live bounties and have paid out $26 million. Their programs are demonstrably real, valuable and impactful. Cantina hosts $64.8m in bounties but has paid out just $2.6m over its entire platform lifetime, suggesting a severe lack of impact. Sherlock lists 35 bounties across 34 protocols, totaling $33.1 million in available rewards, but we don’t have any proof of real payouts. Code4rena has no live bounties, having shifted them to Immunefi.
Immunefi’s 174 programs carry a combined maximum bounty pool of $109.5 million, including some of the most consequential protocols in DeFi: LayerZero at $15 million, Sky and Stargate at $10 million each, USDT0 at $6 million, GMX and Spark at $5 million each, and Chainlink at $3 million. These are protocols that custody billions of dollars, and have paid $137m in bounties to date.
Concentration
Program concentration refers to distribution of the bounty pool between all programs on a platform.
For example, Sherlock advertises $33.1 million in bounties, but it is also highly concentrated. Just one protocol family accounts for $23.5 million of it. Usual Labs carries a $16 million bounty. A related module, Usual - Fira UZR, adds $7.5 million. Two listings, one protocol family.
The remaining 33 listings share roughly $9.6 million. Aave V4 takes $2.5 million of that, then Flying Tulip and Cap at $1 million each, SYMMIO at $809,000, and a cluster at $500,000 including Paradex, Midas and Sherlock’s own bounty. Below that it’s a long tail at $250,000 and under.
If Usual wound down its bounty or migrated, Sherlock’s listed pool would drop below $10 million overnight. Under a third of what it advertises today.
We grouped related protocols into families on every platform, including our own. Ungrouped, Immunefi’s largest listing is 13.7% of the pool. Grouped with Stargate, the LayerZero family is 22.8%.
Sherlock’s largest family is 71.1% of its pool. Cantina’s largest listing, Uniswap Labs at $15.5 million, is 23.9%. Immunefi’s largest family is 22.8%. HackenProof’s largest family, Near at $1.97 million, is 13.8%.
A researcher choosing where to spend a month reads concentration alongside pool depth: how much is on the table, and how much of it depends on one protocol being a good faith actor.
HackenProof has the flattest distribution and the shallowest pool, about 13% of ours. Cantina sits in the middle on both. Sherlock has a pool roughly 30% the size of Immunefi’s, with 71% of it resting on one family.
A researcher who shows up to work on your bounty isn’t there only for you. They’re there because the platform has 100 other programs to work on between submissions, and a track record of paying out across all of them. An overly concentrated platform has much less earning security to offer.
What This Means For Your Bounty
We’ll give the others their due. HackenProof has built the second-largest researcher community in crypto, and it’s the only competitor that shows you who got paid. Sherlock carries the largest single listing in the market, Usual Labs at $16 million. Cantina publishes a live API where every listing and its reward pool can be pulled in one request.
But when it comes to real security value delivered, Immunefi has paid 5.3x the next platform, out of a researcher base the same size. It runs the deepest bounty pool in the market and spreads it across more protocols than any other platform. And most importantly it shows you real payouts, and where the money went.
A competitor starting today isn’t starting level. Every rotation makes the next one easier: high-value programs pull better researchers, better researchers find bigger bugs, bigger bugs mean bigger payouts, and bigger payouts pull in the next high-value program.
Who’s winning is the easy question. The data answers it. The harder one is what that means when it’s your code.
The researchers who find $10 million bugs already know which platforms pay. They are hunting there now. Your bounty either sits where they are, or it sits somewhere they have no reason to look.
Put your bounty where the hunters are.
Start a bug bounty program on Immunefi today.
Data from platform websites, publicly available bounty listings, and manual analysis of competition records, January to September 2026. Audit competition and invite-only program payouts excluded throughout. Immunefi payout, pool and program figures are internal data as of 19 September 2026. Where platforms don’t publish aggregate payout figures, comparisons use currently listed bounty pools and publicly posted bounty payouts only.








