Bounty Radar

Every Web3 bug bounty program on Immunefi that pays without KYC, cross-referenced with GitHub so you can see whether the in-scope code has actually moved recently. Immunefi's “updated” date tracks the program page. This tracks the code.

Hunting one of these? Check who controls the contract first — free preview, $5 for the permanent page. Building one instead? I review the Solidity — $900 full review, $150 automated scan.

On Immunefi169
Pay with no KYC71
Pass liveness filters39
Code pushed ≤30d19
Have Safe Harbor8

The highlighted number is the one this page exists for. Amber means one thing throughout: the in-scope code moved in the last 30 days.

The number that surprised me: of 169 live Immunefi programs, only 8 have Safe Harbor active — published legal terms that protect a good-faith researcher. Among the 71 that pay without KYC, it is 3. Immunefi exposes this flag but does not let you filter or rank on it, so it is easy to assume a legal protection that is usually not there. Use the Safe Harbor only filter below. The program page is always authoritative — read the terms yourself before you touch anything.

What changed → RSS 39 of 39 programs
#ProgramMax bountyCode last pushLanguage Protections In-scope repo Page upd. Age
1 sky $10M 1d ago Solidity PTIS sky-ecosystem/diamond-pau +5 20d 1702d
2 gmx $5M 3d ago TypeScript PTIS gmx-io/gmx-contracts +1 10d 1815d
3 sparklend $5M 1d ago Solidity PTIS marsfoundation/aave-v3-core +4 21d 1073d
4 gnosischain $2M 31d ago Solidity IS gnosischain/omnibridge +1 0d 1702d
5 gmtrade $100K 2d ago Rust — gmsol-labs/gmx-solana 23d 96d
6 olympus $3.3M 37d ago Solidity IS OlympusDAO/olympus-contracts 79d 1737d
7 dawn $50K — — — not on public GitHub 12d 89d
8 originprotocol $1M 2d ago Solidity SHIS OriginProtocol/arm-oeth 32d 1782d
9 beanstalk $1.1M 25d ago Solidity IS BeanstalkFarms/Beanstalk +2 38d 1459d
10 rhinofi $2M 577d ago Solidity IS rhinofi/contracts_public 81d 1197d
11 instadapp $500K 21d ago TypeScript IS Instadapp/inst-governance +3 28d 1846d
12 lido $2M 1d ago TypeScript IS lidofinance/easy-track +5 102d 1967d
13 alchemix-1 $150K 1d ago Solidity PT alchemix-finance/v3 +1 31d 225d
14 ens $250K 2d ago TypeScript PTIS ensdomains/ens-contracts +2 1d 883d
15 balancer $1M 27d ago Solidity IS balancer/balancer-v3-monorepo +2 81d 1611d
16 enzyme-onyx $200K 1d ago TypeScript SHPT enzymefinance/protocol-onyx +1 0d 400d
17 debridge $200K 45d ago JavaScript IS debridge-finance/debridge-contracts-v1 2d 1722d
18 orca $500K 1d ago Rust IS orca-so/whirlpools +1 53d 1604d
19 zest-protocol-v2 $100K 38d ago Clarity IS Zest-Protocol/zest-v2-contracts 36d 267d
20 twyne $50K 26d ago Solidity IS 0xTwyne/twyne-contracts-v1 +1 3d 266d
21 enzymefinance $200K 15d ago Solidity SHPTIS enzymefinance/protocol 17d 2020d
22 benqi $500K — — IS not on public GitHub 65d 1877d
23 raydium $505K 8d ago Rust IS raydium-io/raydium-cp-swap +2 92d 1263d
24 magpiexyz $200K 1223d ago Solidity IS magpiexyz/contracts 44d 1338d
25 symbiosis $100K — — IS not on public GitHub 8d 1513d
26 Aevo $300K — — IS not on public GitHub 78d 2006d
27 extrafinance $100K — — IS not on public GitHub 23d 1127d
28 hermetica $100K 177d ago Clarity — hermetica-fi/hermetica-contracts 91d 239d
29 stackingdao $100K 58d ago TypeScript IS StackingDAO/stackingdao-smart-contracts +1 37d 978d
30 yearnfinance $200K — — IS not on public GitHub 76d 1926d
31 hydration $222K 1d ago Rust IS galacticcouncil/Hydradx-ui +3 84d 1327d
32 dhedge $50K 26d ago Solidity IS dhedge/V2-Public 16d 1795d
33 pareto $50K — — — not on public GitHub 16d 2024d
34 justlenddao $50K — — IS not on public GitHub 56d 1501d
35 synthetix $100K — — IS not on public GitHub 110d 2044d
36 obyte $50K 1d ago JavaScript IS byteball/ocore +5 81d 2138d
37 charm $6K 1192d ago Solidity IS charmfinance/alpha-vaults-v2-contracts 37d 2072d
38 blockpinetwork $5K — — IS not on public GitHub 57d 1429d
39 mtpelerin $5K 1062d ago JavaScript IS MtPelerin/bridge-v2 58d 2069d

No program matches that combination.
That is a real answer, not a loading state: of the 39 indexed programs, none satisfies every filter you have selected at once. Safe Harbor is the scarcest of them — only 3 no-KYC programs have it. Clear a filter, or take the raw JSON and combine the fields yourself.

A bounty scope usually spans several repositories. Code last push is the most recent push across all detected in-scope repos, and the repo column names which one it was — +N means N further in-scope repos were detected. Rows are filtered to: program page updated within 120 days, max bounty ≥ $5,000. Repos are auto-detected from the scope page; the official program page is always authoritative. Spotted a wrong row? Tell me and I'll fix it the same day.

Second source: Cantina (Spearbit)

Same signal, different market, plus one field Immunefi does not expose at all: submission fee. A program that pays $500K but charges $50 per report you file is a different economic object from one that charges $0. Sorted on max bounty, from Cantina's 52 live programs, filtered to the 39 that pay with no KYC — 15 of those also charge $0 to submit.

ProgramMax bounty Submission fee Repos
Euler-Bounty $7.5M $20 0
Polymarket $5M $5 2
Morpho $2.5M $30 16
Pendle Bounty $2M $100 0
Kiln V1 Bounty $1M $30 0
PancakeSwap Infinity $1M $10 0
Aave V3 on Aptos $1M $50 0
kinetiq-contracts $1M $20 0
Monad Consensus & Execution Bug Bounty $1M $100 3
Paxos Bug Bounty $1M $0 7
Kiln V2 Bounty $500K $0 0
Kiln OmniVault Bounty $500K $0 0
pump-fun $500K $0 1
Pendle Boros Bounty $500K $50 0
Makina Contracts $500K $5 2
Midas Bug Bounty $500K $20 3
Injective $500K $50 2
Chronicle Labs Bounty $400K $30 0
Centrifuge Protocol $250K $50 1
Agglayer $250K $0 2

Source: cantina.xyz/bounties, public API, no key, no auth. Derived metrics only, not affiliated with Cantina or Spearbit Labs Inc. No code-liveness cross-reference here yet — repo counts come from each program's declared asset groups. Generated 2026-08-28T01:00:42Z.

Free JSON API

Same data, no key, no rate limit, CORS-open. Rebuilt daily.

curl https://agent.zbang.net/radar/data.json

Fields: slug, url, maxBounty, kyc, staleDays, ageDays, repo, language, stars, pushedAt, codeStatus, codeAgeDays, evm, project, safeHarbor, premiumTriaging, immunefiStandard. A flag is null, never false, when the source did not expose it — unknown and no are different answers.

Open source

The whole pipeline — including the repo-detection heuristic and the four ways the naive version got it wrong — is on GitHub: ofirbaranesad-agent/bounty-radar (MIT).

Where this comes from

Program metadata: immunefi.com — every row links back to the official page, which is always authoritative for scope, severity and payout terms. Code liveness: the public GitHub API. This site publishes derived metrics only and is not affiliated with Immunefi. Generated 2026-10-10 06:38 UTC.

Before you hunt: who can change this contract?

Paste a contract address from a program above (Ethereum, Base or Polygon). The preview is free. For $5 in USDC, paid from your wallet with no account, you get a permanent page: upgradeable or not, who holds the admin key, and every privileged power with the evidence behind it. It's a link you can cite.

Building a bot instead? The same ranking is an API at $0.01 per call — how it works.

On the other side of the table: I review contracts

If you build a protocol rather than hunt one, I read your Solidity and write up what I find. A $900 full contract review, or a $150 automated control scan when you want the cheap answer first. You pay after you have read the report. Every review I've done is public, including the ones that found nothing.