Bounty Rolling

OnRe bug bounty on Immunefi: up to $100,000

OnRe pays up to $100,000 in USDC on Immunefi for critical bugs in its Solana program. Live since May 2026 with no end date.

The OnRe bug bounty runs on Immunefi. OnRe issues ONyc, a token on Solana backed by a portfolio of short duration reinsurance contracts. The bounty covers the OnRe Solana program, which controls minting, redemption and NAV calculation.

A critical smart contract bug pays 10% of the funds directly affected, up to USD 100,000, with a minimum of USD 10,000. High bugs pay a fixed USD 5,000, medium bugs USD 2,000 and low bugs USD 1,000. Rewards are paid in USDC on Solana.

The capital behind ONyc is held off chain by a regulated insurer in Bermuda. It cannot be reached from the Solana program, so it is not counted in the funds at risk. Only the first attack counts for repeatable attacks.

To get a reward you must pass KYC with an identity document and proof of address after your report is confirmed as valid. Researchers in jurisdictions excluded by OnRe's policy and in OFAC sanctioned jurisdictions cannot receive rewards. The program follows Primacy of Rules, so only the terms on the page apply.

Reports go through the Immunefi page. The program launched on May 11, 2026, was last updated on August 28, 2026 and has no end date.

Source · immunefi.com/bug-bounty/onre/information Published 28 August 2026 · Added here 8 October 2026

Quick answers

How much does it pay?

Up to USD 100,000. It is paid as prizes to the winning entries.

When is the deadline?

There is no fixed deadline. Applications are reviewed as they arrive.

Who can apply?

Security researchers who pass KYC and do not live in jurisdictions excluded by OnRe's policy or in OFAC sanctioned jurisdictions. Applicants from anywhere in the world can enter, unless the eligibility rules say otherwise.

Is it online or in person?

Online. You can take part from anywhere the rules allow.

How do I apply?

Through the official page at immunefi.com. The link is at the top of this page.

Do bugs only in the GitHub code count?

No. The bug must be in the most recently deployed program. Bugs that exist only in GitHub source code are not eligible.

Is there a minimum reward for a critical bug?

Yes. A critical smart contract bug earns at least USD 10,000.