What it is
GMX runs a continuous bug bounty programme on Immunefi, open to any security researcher with no application or invitation needed. It has been live since 20 October 2021 and is listed on Immunefi's index of active programmes.
What it pays
Maximum payout is 5,000,000 USD. Rewards are published per asset type
Smart Contract
- Critical: up to 5,000,000 USD
- High: 25,000 USD flat
- Medium: 10,000 USD flat
Websites and Applications
- Critical: 50,000 USD flat
- High: 25,000 USD flat
- Medium: 10,000 USD flat
No KYC is required to claim a reward.
Scope
250 assets are in scope. The programme page carries the full asset list, severity definitions and submission rules, and was last updated on 22 January 2026.
