
Starknet bug bounty on Immunefi
StarkNet pays up to $250,000 on Immunefi for critical bugs in its layer 2 network and smart contracts. The program is open with no deadline.
The Starknet bug bounty program on Immunefi pays for vulnerabilities in the Starknet layer 2 network, which runs on Ethereum with validity proofs and uses Cairo and Solidity. The program launched in October 2022 and was last updated on August 10, 2026. It has no deadline.
Critical blockchain and smart contract bugs pay between $15,000 and $250,000, calculated as 10 percent of the funds at risk and capped at the maximum. High severity blockchain bugs pay a flat $10,000 and medium severity bugs $2,500. For websites and applications, critical bugs pay $5,000 to $10,000 and high severity bugs $1,250 to $2,500.
Forty assets are in scope. Testing must happen on local forks only. Tests on mainnet or testnet, social engineering, denial of service attacks and public disclosure of unpatched bugs are not allowed.
All smart contract reports must come with a proof of concept that shows an effect on an asset in scope. Researchers who want a reward must pass KYC with their full legal name, residential address, date of birth and a copy of a national ID or passport, and an OFAC screening.
Rewards are paid in USDC on Ethereum by the StarkNet team. Reports are submitted through the Immunefi program page.