Immunefi crossed $134 million in cumulative researcher payouts by the end of March 2026, with $7.87 million paid in Q1 alone across 1,104 reports, a 228% quarter-over-quarter jump from Q4 2025. Usual’s $16 million program on Sherlock is now the largest single bug bounty in tech history, ahead of Uniswap v4 at $15.5 million on Immunefi and LayerZero at $15 million. Cost-of-prevention math has flipped against the exploited side.
The dataset below covers Immunefi and HackerOne payouts, the largest active web3 bug bounty programs across Sherlock, Immunefi, and Cantina, the realized-loss benchmarks from CertiK and Chainalysis, and the AI crossover that reshaped the report mix. Figures trace to primary sources: Immunefi’s ecosystem update, the HackerOne Hacker-Powered Security Report, Sherlock’s bug bounty roundup, CertiK’s Hack3d annual report, and Chainalysis’s crypto theft update.
Key Takeaways
- Immunefi has paid $134 million to ethical hackers cumulatively by the end of Q1 2026, across 230 active bug bounty programs protecting more than $190 billion in total value locked.
- Q1 2026 researcher payouts on Immunefi reached $7.87 million across 1,104 paid reports, up 228% from $2.40 million in Q4 2025.
- Usual’s $16 million bug bounty on Sherlock is the largest active program in tech history, with Uniswap v4 at $15.5 million and LayerZero at $15 million behind it on Immunefi.
- HackerOne paid $81 million in bug bounties in the 12 months ending June 2025, a 13% year-over-year increase, with the top 10 programs absorbing $21.6 million of that.
- On Immunefi, 94% of long-running bug bounty programs have surfaced at least one critical vulnerability, with smart contract bounties accounting for 77.5% ($77.97 million) of total payouts.
- Crypto theft totalled $2.36 billion across 760 incidents in 2024 (CertiK) and rose to over $3.4 billion in 2025 (Chainalysis), the same window in which bug bounty payouts also accelerated.
Editor’s Choice
- HackerOne’s average yearly bounty payout per active program is approximately $42,000, with the top 100 researchers earning $31.8 million collectively over the past 12 months.
- The median confirmed bug bounty payout on Immunefi is around $2,000, while the average sits at approximately $52,800, skewed by occasional six- and seven-figure payouts.
- A single $3 million payout accounted for 38% of all Q1 2026 Immunefi researcher earnings, and the top 5 reports summed to roughly $4.5 million, over half the quarter’s total.
- AI vulnerability reports on HackerOne rose by more than 200% year over year, with prompt injection submissions surging 540% across 1,121 programs that now include AI in scope.
- Immunefi processes 93% of all critical crypto vulnerability disclosures industry-wide and has prevented over $25 billion in hacks across the platforms it protects.
- Immunefi’s March 2026 hack catalogue covers 425 publicly known incidents between 2021 and 2025, totalling $11.9 billion in losses, the comparison baseline for the $134 million cumulative bounty spend.
- Critical-severity bounties account for 87.8% ($88.34 million) of all Immunefi payouts, with high severity at 7.4% and medium severity at 3.2%.
Immunefi Payouts by the Numbers
Smart Contract vs Blockchain vs Web App Payout Mix
Splitting Immunefi’s cumulative payouts by category surfaces how concentrated bounty spend is on smart contract logic.
- Smart contracts: $77,973,118 paid out, 77.5% of the cumulative platform total.
- Blockchain (consensus-layer) bugs: $18,756,806.72, 18.6%.
- Web and app: $3,849,014.79, 3.8%.
Across the same dataset, 87.8% of payouts ($88.34 million) flowed to critical-severity findings, with 7.4% ($7.45 million) for high severity and 3.2% ($3.24 million) for medium severity.
Recent Developments
- March 2026: Immunefi published its 425-hack catalogue covering 2021-2025 with $11.9 billion in losses, the most comprehensive on-chain hack dataset to date.
- March 2026: Sherlock published its Best Web3 Bug Bounties 2026 roundup, listing Usual’s $16 million program as the largest active bounty in tech history.
- April 2026: Immunefi’s Q1 2026 ecosystem update reported $7.87 million in researcher payouts and 1,104 paid reports for the quarter.
- December 2025: Chainalysis reported over $3.4 billion in crypto theft for January through early December 2025, with DPRK-linked groups responsible for $2.02 billion of the total.
- October 2025: HackerOne released its 8th Annual Hacker-Powered Security Report, recording $81 million in total bounty payouts and a more than 200% YoY rise in AI vulnerability submissions.
- January 2025: CertiK’s Hack3d 2024 annual report logged $2.36 billion in Web3 losses across 760 on-chain incidents, a 31.61% year-over-year increase.
Largest Active Web3 Bug Bounty Programs
| Protocol | Maximum Bounty ($) | Hosting Platform |
|---|---|---|
| Usual | 16000000 | Sherlock |
| Uniswap v4 | 15500000 | Immunefi |
| LayerZero | 15000000 | Immunefi |
| Wormhole | 10000000 | Immunefi |
| Sky (MakerDAO) | 10000000 | Immunefi |
| Coinbase / Base | 5000000 | Cantina |
| GMX | 5000000 | Immunefi |
| Arbitrum | 2000000 | Immunefi |
| Optimism | 2000042 | Immunefi |
| Ethereum Core | 1000000 | Self-hosted |
Source: Sherlock Best Web3 Bug Bounties 2026, March 2026.
By the numbers: Usual’s $16 million program tops the active Web3 bug bounty list on Sherlock, and by value, most of the next tier sit on Immunefi. The cumulative maximums of the platform’s top five reach into the eight-digit range. For comparison, the largest Web2 single-bug bounty caps from Microsoft and Google sit at roughly $250,000 to $1 million.
Crypto Losses the Bug Bounty Layer Sits Against
Why it matters: Immunefi’s cumulative $134 million in researcher payouts buys disclosure across the same surface area that lost $2.36 billion in 2024 and over $3.4 billion in 2025. The ratio sits in the low single-digit percentage, a cost-of-prevention asymmetry that explains why protocol treasuries keep pushing single-bug ceilings into the eight-digit range.
For the wider on-chain risk context that frames these numbers, the cybersecurity in cryptocurrency data tracks the same incident set from the defender-side.
HackerOne and the Web2 Comparison
| HackerOne Metric (12 months to June 2025) | Value |
|---|---|
| Total bounties paid | $81 million |
| Year-over-year growth | 13% |
| Top 10 programs share | $21.6 million |
| Top 100 programs share | $51 million |
| Average payout per program | $42,000 |
| Top 100 researchers (cumulative) | $31.8 million |
Source: HackerOne 8th Annual Hacker-Powered Security Report, October 2025.
AI and the Bug Bounty Crossover
| AI Metric on HackerOne (2024-2025) | Value |
|---|---|
| AI vulnerability reports YoY | +200% |
| Prompt injection reports YoY | +540% |
| Programs including AI in scope | 1,121 |
| AI-scope program YoY growth | +270% |
| Autonomous AI agent reports submitted | 560+ |
| Researchers using AI tools | 70% |
Source: HackerOne 8th Annual Hacker-Powered Security Report, October 2025.
The crossover matters for smart contract programs because the same researcher cohort runs on both sides of the platform divide.
Median vs Mean Payouts and Why It Matters
Bounty payout distributions are heavily right-skewed, and the median-vs-mean gap is a clean single signal of how concentrated the upside sits.
- The median confirmed bug bounty payout on Immunefi is around $2,000, while the average sits at approximately $52,800.
- Critical-severity bounties take 87.8% of cumulative platform spend ($88.34 million), high-severity bounties take 7.4% ($7.45 million), and medium-severity bounties take 3.2% ($3.24 million).
- 94% of long-running bug bounty programs on Immunefi have surfaced at least one critical vulnerability.
| Severity Tier | Cumulative Payouts ($) | Share |
|---|---|---|
| Critical | 88344273 | 87.8% |
| High | 7446570 | 7.4% |
| Medium | 3243734 | 3.2% |
Source: Immunefi Research, September 2025 disclosure.
The takeaway: A median of around $2,000 next to a mean of approximately $52,800 on Immunefi describes a payout distribution skewed by occasional six- and seven-figure payouts. The headline payouts sit in the Wormhole class and the Q1 single-bounty class, but the operational median for a working researcher stays in the four-figure range.
Q1 2026 Inflection in Researcher Earnings
| Period | Payouts (USD millions) | Reports |
|---|---|---|
| Q4 2025 | 2.40 | 954 |
| Q1 2026 | 7.87 | 1104 |
Source: Immunefi Q1 2026 Ecosystem Update, April 2026.
CertiK Quarterly Loss Cadence
Personal Wallets vs Protocol Vaults
- Personal wallet compromise incidents surged to 158,000 in 2025, nearly triple the 54,000 recorded in 2022.
- Total value stolen from individuals declined from 2024’s peak of $1.5 billion to $713 million in 2025.
- Personal wallet compromises grew from just 7.3% of total stolen value in 2022 to 44% in 2024.
- DPRK cryptocurrency theft reached a cumulative estimated $6.75 billion through 2025.
| Personal Wallet Compromise Metric | 2022 | 2024 | 2025 |
|---|---|---|---|
| Wallet compromise incidents | 54000 | n/a | 158000 |
| Personal wallet share of stolen value | 7.3% | 44% | n/a |
| Stolen from individuals ($M) | n/a | 1500 | 713 |
Source: Chainalysis 2026 Crypto Theft Report, December 2025.
The context: Bug bounties cannot patch the human layer. Personal wallet compromises in 2025 reached 158,000 incidents, a phishing-and-social-engineering surface rather than a contract surface. The contract-side bug bounty payout total on Immunefi in Q1 2026 was $7.87 million. The two datasets describe different defenses.
For context on how those individual-wallet attack patterns line up against the broader Bitcoin and Ethereum risk profile, the chain-level comparison sits in the dedicated stats page.
What’s the Average Bug Bounty Payout on HackerOne?
The average yearly bug bounty payout per active program on HackerOne in the 12 months ending June 2025 was approximately $42,000. The headline figure tracks per-program spend, not per-report payouts, and per-report payouts run lower on most non-critical findings. The top 10 programs alone took a large share of the total, so the average masks a heavy concentration at the top.
How Big Is the Largest Active Smart Contract Bug Bounty?
The largest active smart contract bug bounty in 2026 is Usual’s $16 million program on Sherlock, with Uniswap v4 at $15.5 million on Immunefi and LayerZero at $15 million on Immunefi as the next two largest. The Wormhole program was the prior benchmark, paid out in full to researcher satya0x for a critical uninitialized-proxy vulnerability, which is what made the cap meaningful enough for the rest of the field to match and exceed.
Conclusion
The bug bounty layer for smart contracts entered 2026 with Immunefi’s cumulative researcher payouts at $134 million and the platform protecting more than $190 billion in total value locked across 230 active programs. Usual’s $16 million Sherlock program now sets the single-bug ceiling for the industry, a cap that would have looked aspirational at any prior point in the dataset.
The forward question is whether the Q1 2026 inflection holds. A 228% quarter-over-quarter jump in researcher payouts to $7.87 million on Immunefi, with average payout per report nearly tripling to $7,131, points to a heavier mix of critical and high-severity vulnerabilities reaching disclosure. Against the realized-loss benchmark of $3.4 billion stolen in 2025 and $2.36 billion in 2024, the bug bounty layer remains the cheapest line of defense available to a protocol treasury, and it is the only one whose costs scale with the bugs it catches rather than the value at risk.