You get paid what the bug is worth.
Join the private network, submit a reproducible finding, and get a tracked, fair reward decision after CertiK verifies it.
Backed by CertiK: 5,181 projects secured, $500B+ assessed since 2018.
Three formats, one access ladder.
Not every engagement on Hunt is a bug bounty. Challenges and audit contests are their own formats with their own rules, and your access level decides which ones you can enter.
Security challenges
Focused, time-boxed challenges open to every approved researcher. Finish one and you have a verified track record on Hunt instead of a claim.
View challengesAudit contests
Fixed-window reviews of pinned code. The scope, deadline, duplicate policy, and judging criteria are published before submissions open.
View audit contestsBug bounties
Continuous, confidential coverage of live production systems. CertiK verifies every finding before the protocol sees it and before a reward is released.
Browse bug bountiesThe report lifecycle
Submit
A researcher opens a bug bounty program or an audit contest from their workspace and submits a reproducible finding with a clear title, severity, affected asset, and a proof-of-concept. Challenges are scored on their own terms and do not enter this pipeline.
Triage
A CertiK expert reproduces the PoC, checks duplicates, and sets severity independently of the protocol. CertiK runs triage and payouts; status updates land in your dashboard.
Decision
Accepted, duplicate, or out-of-scope decisions are recorded with clear rationale so manual decisions stay documented.
Payout and disclosure
Programs publish reward ranges and payout handling terms before launch. CertiK records accepted, resolved, and paid states after human confirmation.