
Twyne bug bounty on Immunefi
Twyne pays up to $50,000 in USDC for critical smart contract bugs, through Immunefi. Open on a rolling basis.
The Twyne bug bounty on Immunefi pays security researchers for bugs in Twyne. The program describes Twyne as a lending protocol that uses credit delegation so users can lend and borrow again inside lending markets. Rewards are paid in USDC on Ethereum. The program has been live since 16 January 2026 and was last updated on 7 October 2026.
For critical smart contract bugs, the reward is 10 percent of the funds directly affected, up to USD 50,000. The minimum critical reward is USD 20,000. The funds at risk are counted at the time the report is submitted. High severity smart contract reports pay from $3,000 to $10,000.
A proof of concept is required at every severity. KYC is not required for a payout. If the vulnerable contract can be upgraded or paused, only the first attack is considered for a reward. Reports go through the Immunefi submission page.
Quick answers
How much does it pay?
Up to $50,000. It is paid as prizes to the winning entries.
When is the deadline?
There is no fixed deadline. Applications are reviewed as they arrive.
Who can apply?
Security researchers. A proof of concept is required for every severity. KYC is not required for a payout. Applicants from anywhere in the world can enter, unless the eligibility rules say otherwise.
How do I apply?
Through the official page at immunefi.com. The link is at the top of this page.
How is a critical reward calculated?
It is 10 percent of the funds directly affected at the time the report is submitted, with a floor of USD 20,000 and a cap of USD 50,000.