
Exactly bug bounty on Immunefi
Exactly pays up to $25,000 in USDC for critical smart contract bugs, through Immunefi. Open on a rolling basis.
The Exactly bug bounty on Immunefi pays security researchers for bugs in the Exactly protocol. Exactly describes itself as a decentralized, non custodial, open source market for fixed and variable interest rates. The program page tags the protocol with Optimism. The program has been live since 8 December 2022 and was last updated on 2 October 2026.
Rewards are paid in USDC and DAI on Ethereum, in a mix chosen by the Exactly team, and the amounts are denominated in USD. The rewards table lists critical smart contract bugs from $10,000 to $25,000, and high bugs from $5,000 to $10,000. Critical rewards are 10% of the funds directly affected, up to $25,000. A later paragraph on the same page sets the critical minimum at $20,000.
Every severity needs a proof of concept. High and critical smart contract reports need code, and an explanation is not enough. Known issues and earlier audits at https://docs.exact.ly/security/audits are not eligible. KYC is required, including government identification, a legal name, and country of residence.
Testing is allowed only on local forks. Mainnet and public testnets are not allowed. Payouts are handled by the Exactly team.
Quick answers
How much does it pay?
Up to $25,000. It is paid as prizes to the winning entries.
When is the deadline?
There is no fixed deadline. Applications are reviewed as they arrive.
Who can apply?
Security researchers. A runnable proof of concept is required for all severities. KYC is required, including government identification, legal name, and country of residence. Known issues listed at https://docs.exact.ly/security/audits are not eligible. Applicants from anywhere in the world can enter, unless the eligibility rules say otherwise.
How do I apply?
Through the official page at immunefi.com. The link is at the top of this page.