
sBTC bug bounty on Immunefi
The sBTC bug bounty on Immunefi pays up to $250,000 for bugs in the bridge. Live since 2 July 2026.
The sBTC bug bounty runs on Immunefi. Payouts are handled by the Stacks Endowment team. Rewards are denominated in USD and paid in STX. The program covers blockchain and smart contract issues in this bridge, and the code languages named on the page are Rust, Clarity, and Bitcoin Script. It went live on 2 July 2026 and was last updated on 29 September 2026. It has no end date.
A critical bug pays 10% of the funds directly affected, from $25,000 up to $250,000, for both blockchain and smart contract issues. A high bug pays from $5,000 to $25,000 in both categories. For blockchain issues, a medium bug pays from $1,000 to $5,000 and a low bug pays a flat $1,000. A proof of concept is required for blockchain issues at every severity, and for critical and high smart contract issues.
You must pass KYC to take part. People on the OFAC SDN list, employees, official contributors, and auditors cannot take part. Known issues listed on the program page are not eligible. They include earlier Stacks attackathon reports, published audits, and existing GitHub issues and pull requests.
To report a bug, read the program rules on Immunefi and submit your report through the Immunefi platform.