
The Graph bug bounty on Immunefi
The Graph Foundation pays up to $50,000 on Immunefi for bugs in its indexing protocol. The program was last updated 27 August 2026.
The Graph bug bounty on Immunefi pays for bugs in The Graph, an indexing protocol that serves blockchain data through GraphQL APIs. Immunefi shows the program as live since 4 August 2021 and last updated on 27 August 2026. The maximum bounty is $50,000. Rewards are denominated in USD and paid in GRT on Arbitrum.
Critical smart contract reports pay 10 percent of the funds directly affected, with a cap of $50,000 and a minimum of $15,000. High reports pay between $5,000 and $15,000. Immunefi lists $1.6 million as the total paid to date.
The Graph Foundation says it wants reports that prevent loss of user funds, exposure of private keys, determinism bugs that give Indexers inconsistent results, and flaws in Indexer software that could lead to slashing. A proof of concept is required. For smart contract bugs the proof must be a reproducible script submitted inline, not as an external download.
KYC is required before a payout. Testing on mainnet or public testnets is forbidden. Submit reports through Immunefi.