Feed
Bounty Rolling

Cosmos Bug Bounty Program on Immunefi

Cosmos Labs pays up to $50,000 for critical vulnerabilities in the Cosmos Stack through Immunefi. The program is open on a rolling basis.

The Cosmos Bug Bounty Program is run by Cosmos Labs on Immunefi. It pays up to $50,000 for vulnerabilities in the protocols, modules and infrastructure that make up the Cosmos Stack. The program launched on June 22, 2026 and was last updated on September 11, 2026.

Rewards are flat amounts per severity level. A critical finding pays $50,000, a high finding $12,500, a medium finding $2,500 and a low finding $1,000.

The scope covers the source code of 23 assets that Cosmos Labs calls integral components of Cosmos. This includes distributed systems protocols, cryptography, the smart contract platform, the consensus algorithm and the interoperability protocol. Web application vulnerabilities and third party services are out of scope.

Every report needs a proof of concept. Reports rated medium, high or critical must be tested end to end on a local four node network. A pay to submit fee in USDC applies, and KYC is required before a payout. Researchers who worked for or with the team maintaining the affected code in the previous 12 months cannot take part.

Reports are submitted through the Immunefi dashboard, linked from the program page.

Source · immunefi.com/bug-bounty/cosmos/information Published 11 September 2026 · Added here 11 September 2026