What it is
OpenZeppelin runs a continuous bug bounty programme on Immunefi, open to any security researcher with no application or invitation needed. It has been live since 15 November 2021 and is listed on Immunefi's index of active programmes.
What it pays
Maximum payout is 25,000 USD. Rewards are published per asset type
Smart Contract
- Critical: 5,000 to 25,000 USD
- High: 2,500 to 5,000 USD
- Medium: 2,500 USD flat
- Low: 1,000 USD flat
KYC is required before a reward is released.
Scope
4 assets are in scope. The programme page carries the full asset list, severity definitions and submission rules, and was last updated on 01 April 2026.
