Bug bounty report templates

Four report templates built from what each platform publishes about submissions and judging, and one Foundry scaffold for the proof. Every page lists what that platform’s judges close reports for, with the source.

Rules checked 2 Oct 2026 · Markdown, free to copy

Templates by platform

Immunefi

10 sections

Bug bounties and audit competitions. Impact is picked from the programme’s own list.

Judges close reports for

  • No runnable PoC where the programme requires one
  • An impact that is not on the programme’s list
  • Known issues and unfixed audit findings

Sherlock

11 sections

Audit contests and bounties. Only High and Medium score, against written loss thresholds.

Judges close reports for

  • Loss below the Medium threshold
  • Trusted admin or a design decision
  • Issues the README or a linked audit already lists

Cantina

9 sections

Competitions and bounties. Severity is impact × likelihood, and High and Medium need a coded PoC.

Judges close reports for

  • High or Medium without a PoC that compiles
  • Findings acknowledged in a previous report
  • Admin error, user error and design choices

HackerOne

9 sections

Web, API, mobile and open-source programmes. Outcomes are report states, and each state moves reputation.

Judges close reports for

  • Impact not demonstrated: Not Applicable
  • Core ineligible findings
  • Duplicates and issues on the policy page

Foundry PoC

ImpactPoC.t.sol

A fork-test scaffold: pinned block, named actors, concrete values, a control run and a fix run.

  • The final assertion reads the object the impact names
  • One file, one command, pasted output
  • Passes on deployed code, fails on the patched build

What each platform’s judges close reports for

The same finding is judged against a different rulebook on each platform. These are the published rules that end a report, side by side. Each template page links the source for every cell.

Published rules, checked 2 Oct 2026
RuleImmunefiSherlockCantinaHackerOne
Proof of conceptImmunefiRunnable code where the programme requires one. No reward without it.SherlockRecommended for complex issues. Invalid when the issue cannot be understood without one.CantinaCoded PoC for High and Medium in competitions, unless reputation is 80 or above.HackerOneReproduction steps and supporting material. Not Applicable when impact is not demonstrated.
Severity scaleImmunefiThe programme’s Impacts in Scope, on a four-level scale.SherlockHigh and Medium only, against written loss thresholds.CantinaImpact × likelihood matrix, with capped categories.HackerOneCVSS 3.0, 3.1 or 4.0, or manual, as the programme lists.
Known issuesImmunefiAcknowledged issues and unfixed audit findings are not eligible.Sherlockwont fix issues and acknowledged audit findings are invalid.CantinaFindings acknowledged in a previous report are invalid.HackerOneClosed as Informative or Duplicate.
DuplicatesImmunefiPreviously discovered bugs are not eligible. Refiling your own is prohibited.SherlockGrouped by root cause. Points are shared. Bounties pay the earliest.CantinaBounties pay none. Competitions scale the points down.HackerOneClosed as Duplicate. Reputation moves between +2 and −5.
Fee or penaltyImmunefiSuspension or permanent ban, and zero payout.SherlockPayouts withheld below a 20% valid ratio. Escalation costs Signal.Cantina$100 for an invalid escalation. Deposits slashed for spam.HackerOne−5 for Not Applicable, −10 for Spam.

Eight parts, on every platform

The headings change with the platform. The parts do not. Six are what the platform asks for. The last two are added, because reports get closed for overclaiming and for known issues after everything else has passed.

  1. Title ruleMechanism and consequence in one sentence, in the platform’s own title shape.
  2. SummaryWhat breaks and who loses, before any code.
  3. Exact locationFile and lines on a pinned commit, or the URL, parameter and build.
  4. Impact, mappedThe programme’s impact row or severity threshold, quoted, with the measured number beside it.
  5. Proof of conceptThe code, the command and the pasted output.
  6. Recommended fixThe change, as a diff where it fits.
  7. Limits and non-claimsWhat the report does not say, what was mocked, when the path stops working.
  8. Known-issue comparisonThe nearest known issue, named, and the difference in root cause.

Twelve checks, distilled from 105 real case files across five platforms. The wins and the closures. Every check exists because real reports were closed for that reason, and the two added sections come from that record.

Fill one in, then challenge it

A template gives the report its shape. The workbench argues against what you wrote in it: the impact row, the proof, the severity, the prior art. Find the hole in your report before the triager does. How the challenge works.