Platform rules

What an invalid report costs on each platform

A report closed as invalid, N/A or spam can cost you reputation, credits, open submission slots, a deposit or the account. The table gives each platform’s rule, from its own pages, with the date we read it.

The rule on each platform

Programmes can add their own rules on top. Read the programme page before you submit.

PlatformClosed as invalid or N/ASpam, AI misuse or abuse
HackerOneClosed as invalid or N/ANot Applicable: −5 reputation, and the same for a duplicate of an N/A report. When reputation drops, the platform limits how many reports you can submit over a set period. [1]A report is closed N/A when it is speculative, has no proof of concept, cannot be reproduced, rests on a video alone or shows no impact. [2]Spam, AI misuse or abuseSpam: −10 reputation. [1]Large-scale submission of low-quality or unverified reports, including misuse of AI tools: a final warning, then a 12-month ban, then a permanent ban. A repeated pattern of inflated severity is a Code of Conduct violation. [2]
BugcrowdClosed as invalid or N/AManaged programmes: at most 5 open submissions at a time, unless the account has a proven record of quality. [3]10 or more invalid reports: identity verification before you can submit again. [4]Spam, AI misuse or abuse10 or more invalid reports in a row: account review, and a possible 30-day suspension where they were AI-generated or automated without validation. Submission farming: a permanent ban. [4]
IntigritiClosed as invalid or N/AOpen submissions are capped by the validity of your last 20: 1 below 20%, 3 from 20%, 5 from 40%, 7 from 60%, no cap from 80%. With 5 or fewer processed, the cap is 1. [5]Spam, AI misuse or abuseReports that look like unverified AI output, or hold fabricated content or placeholder text, can be closed without response, take longer to validate, or lead to removal from the platform. AI use must be disclosed. [6]
YesWeHackClosed as invalid or N/AEach programme sets a credit price per submission. A report closed as invalid, out of scope or N/A costs the price plus twice the price: three times the price in all. [7]Spam, AI misuse or abuseSpam costs the price plus three times the price: four times in all. An accepted report pays back twice the price, plus a bonus by severity. [7]
ImmunefiClosed as invalid or N/AMisrepresenting the asset, the severity or the impact is prohibited: a temporary suspension or a permanent ban, loss of access to your reports and zero payout. [8]Spam, AI misuse or abuseTesting on mainnet or a public testnet: an immediate and permanent ban. Spam, placeholder submissions, and AI or scanner reports without the impact on the asset are prohibited. [8]
CantinaClosed as invalid or N/AWhere a bounty requires a deposit, a valid or a legitimate invalid submission gets it back. [9]Spam, AI misuse or abuseSpam, low-effort or AI submissions, and an over-inflated severity: the deposit is slashed. Repeated abuse: slashed, with possible account action. [9]
Sherlock Audit EngineClosed as invalid or N/AA dismissed issue counts 0 of 1 in your Issues Ratio, a submission cannot be withdrawn or edited, and each rewrite adds 0.5 to the count. No payout until the ratio is at least 20% and you have 2 valid findings. [10]Spam, AI misuse or abuseNo separate rule on the page cited.

What the rules ask of a report

Each line comes from the rules above. The free report check looks for all of them in a draft.

  1. A proof on a local fork

    Run it on a fork, and paste the command and its output into the report. Immunefi bans testing on mainnet or a public testnet, and HackerOne closes a report with no proof of concept.

  2. One severity, argued

    HackerOne treats a repeated pattern of inflated severity as a violation, Immunefi prohibits misrepresenting it, and Cantina slashes the deposit for it.

  3. AI use stated

    Intigriti requires you to disclose when and how AI was used. HackerOne, Bugcrowd and Intigriti hold you responsible for what an AI tool wrote.

  4. No placeholder left

    Intigriti names placeholder text as fabricated content, and Immunefi prohibits placeholder submissions.

Sources

Each number in the table points here.

  1. [1]HackerOne Help Center, “Reputation”dated 1 December 2025, checked 7 October 2026
  2. [2]HackerOne, “Code of Conduct”checked 7 October 2026
  3. [3]Bugcrowd Docs, “Submission Limits for MBB Programs”dated 4 May 2026, checked 7 October 2026
  4. [4]Bugcrowd, “Bugcrowd policy changes to address AI slop submissions”dated 10 March 2026, checked 7 October 2026
  5. [5]Intigriti Help Center, “Submission limits (open submissions)”dated 8 June 2026, checked 7 October 2026
  6. [6]Intigriti Help Center, “Community Code of Conduct”dated 9 March 2026, checked 7 October 2026
  7. [7]YesWeHack Help Center, “YesWeHack credits”checked 7 October 2026
  8. [8]Immunefi, “Rules”checked 7 October 2026
  9. [9]Cantina Documentation, “Deposits for Bounty Submissions”checked 7 October 2026
  10. [10]Sherlock Docs, “Audit Engine: For Participants”checked 7 October 2026

Check the draft before the triager does

The report check runs in your browser and sends nothing. The challenge runs on your own model and key. Free: 1 review a day.