Immunefi
Bug bounties and audit competitions. Impact is picked from the programme’s own list.
- No runnable PoC where the programme requires one
- An impact that is not on the programme’s list
- Known issues and unfixed audit findings
Four report templates built from what each platform publishes about submissions and judging, and one Foundry scaffold for the proof. Every page lists what that platform’s judges close reports for, with the source.
Bug bounties and audit competitions. Impact is picked from the programme’s own list.
Audit contests and bounties. Only High and Medium score, against written loss thresholds.
Competitions and bounties. Severity is impact × likelihood, and High and Medium need a coded PoC.
Web, API, mobile and open-source programmes. Outcomes are report states, and each state moves reputation.
A fork-test scaffold: pinned block, named actors, concrete values, a control run and a fix run.
The same finding is judged against a different rulebook on each platform. These are the published rules that end a report, side by side. Each template page links the source for every cell.
| Rule | Immunefi | Sherlock | Cantina | HackerOne |
|---|---|---|---|---|
| Proof of concept | ImmunefiRunnable code where the programme requires one. No reward without it. | SherlockRecommended for complex issues. Invalid when the issue cannot be understood without one. | CantinaCoded PoC for High and Medium in competitions, unless reputation is 80 or above. | HackerOneReproduction steps and supporting material. Not Applicable when impact is not demonstrated. |
| Severity scale | ImmunefiThe programme’s Impacts in Scope, on a four-level scale. | SherlockHigh and Medium only, against written loss thresholds. | CantinaImpact × likelihood matrix, with capped categories. | HackerOneCVSS 3.0, 3.1 or 4.0, or manual, as the programme lists. |
| Known issues | ImmunefiAcknowledged issues and unfixed audit findings are not eligible. | Sherlockwont fix issues and acknowledged audit findings are invalid. | CantinaFindings acknowledged in a previous report are invalid. | HackerOneClosed as Informative or Duplicate. |
| Duplicates | ImmunefiPreviously discovered bugs are not eligible. Refiling your own is prohibited. | SherlockGrouped by root cause. Points are shared. Bounties pay the earliest. | CantinaBounties pay none. Competitions scale the points down. | HackerOneClosed as Duplicate. Reputation moves between +2 and −5. |
| Fee or penalty | ImmunefiSuspension or permanent ban, and zero payout. | SherlockPayouts withheld below a 20% valid ratio. Escalation costs Signal. | Cantina$100 for an invalid escalation. Deposits slashed for spam. | HackerOne−5 for Not Applicable, −10 for Spam. |
The headings change with the platform. The parts do not. Six are what the platform asks for. The last two are added, because reports get closed for overclaiming and for known issues after everything else has passed.
Twelve checks, distilled from 105 real case files across five platforms. The wins and the closures. Every check exists because real reports were closed for that reason, and the two added sections come from that record.
A template gives the report its shape. The workbench argues against what you wrote in it: the impact row, the proof, the severity, the prior art. Find the hole in your report before the triager does. How the challenge works.