Immunefi
Immunefi is a Singapore-based Web3 security platform operating a dominant bug bounty marketplace for crypto protocols, now extending into a unified SecOps command center (Magnus) with AI-powered threat detection. It serves 650+ protocols and 60,000+ whitehat security researchers.
- Company typePrivate
- Founded2020
- HeadquartersSingapore, Singapore
- Headcount51–100
- GTM typeB2B
- OfferingSoftware
What Immunefi does
Immunefi is a Singapore-headquartered Web3 security platform that operates the dominant bug bounty marketplace for crypto and DeFi protocols, founded in December 2020 by CEO Mitchell Amador. The company connects 650+ protocol customers with a network of 60,000+ whitehat security researchers, claiming to have secured $190 billion+ in user funds, averted $25 billion+ in hack damage, and paid $116 million+ in researcher rewards. Its flagship offering, Immunefi Magnus (launched 2025), is a unified SecOps command center organized around four pillars — Aggregate, Orchestrate, Agentify, and Evolve — that consolidates CI/CD pipeline security, audits, audit competitions, bug bounty programs, Safe Harbor, onchain monitoring, and AI-powered security agents into a single platform.
The product portfolio spans the full security lifecycle: Bug Bounty Programs (core marketplace, reportedly accounting for 92.33% of blockchain critical vulnerability disclosures), PR Reviews (GitHub-integrated pre-deployment reviews), Immunefi Audits (matched smart contract audits), Audit Competitions and Attackathons (time-bound crowdsourced reviews such as the $200K Ripple Attackathon), Invite-Only Programs (curated private engagements), Safe Harbor (legal framework co-developed with SEAL), Vaults (onchain bounty payment vaults built on Safe multisig), and Managed Triage (a tiered 24/7 subscription service). Underlying technology includes the proprietary Codexa dataset of onchain vulnerabilities, the AI security agent system, and open-source Vaults smart contracts. Revenue is generated through a mix of bug bounty platform fees, professional services audits, transaction fees on audit competitions, tiered managed-triage subscriptions, PR review engagements, and large-scale Attackathon events; pricing is quote-based across products, with the exception of free self-serve Vaults.
Immunefi has raised $29.5M in disclosed equity funding (a $5.5M round in October 2021 and a $24M Series A in September 2022 led by Framework Ventures) and supplemented capital with a strategic IMU token purchase by Anchorage Digital Ventures in March 2026. The company acquired smart contract security firm Klevoya in December 2021, has introduced a Bug-Bounty Court backed by the London Chamber of Arbitration and Mediation (December 2025), and participates in the Ethereum Foundation's $1M Trillion Dollar Security Initiative. With 50+ employees, SOC 2 Type II compliance, and sub-brands including Immunefi Foundation and Immunefi Studio, the company is positioned as a comprehensive onchain security vendor rather than a pure bug bounty marketplace.
Immunefi firmographics
Firmographics- Name
- Immunefi
- Legal name
- Immunefi
- Website
- https://immunefi.com
- Company type
- Private
- Founded year
- 2020
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- Immunefi is a Singapore-based Web3 security platform operating a dominant bug bounty marketplace for crypto protocols, now extending into a unified SecOps command center (Magnus) with AI-powered threat detection. It serves 650+ protocols and 60,000+ whitehat security researchers.
- Ownership category
- akta.pro rank
Immunefi industry classification
Industry- Product category
- Web3 Security Platform
- NAICS
- Computer Systems Design and Related Services (5415), Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
- akta.pro secondary industries
- Smart Contract Security Tooling (static/dynamic analysis, formal verification) (FSAPABAI), Monitoring, Observability & Incident Response (alerts, traces, runtime monitoring) (FSAPABAJ)
Keywords
Where Immunefi is headquartered
LocationHeadquarters
- HQ city
- Singapore
- HQ country
- Singapore
- HQ region
- Asia
Markets served
Immunefi business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Bug Bounty Platform Fees: Core revenue from protocol teams launching and running bug bounty programs on Immunefi; covers standard programs, premium programs, vaults, and triage add-ons. Self-serve and enterprise sales motions.
- Security Audits: Paid engagements where projects are matched with elite Web3 auditors; right-sized to scope and budget, with report delivery and closing call
- Audit Competitions: Time-bound crowdsourced audit competitions with capped reward pools; Immunefi takes a fee on the reward pool and provides managed triaging, marketing, and reports
- Managed Triage Services: Tiered subscription-style managed triage (Time Saver, Signal Booster, Expert Assessment) plus optional 24/7 add-on for continuous human monitoring
- PR Reviews: Recurring engagement-based revenue from GitHub pull request reviews embedded into client dev workflows
- Attackathons: Large-scale, education-based ecosystem-wide competitions (e.g., $200K Ripple Attackathon, $200K XRPL Lending Attackathon) generating engagement and platform revenue
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Multi-year contract | Managed Triage — Time Saver tier (operational efficiency, filtering out-of-scope reports) |
| Subscription | Multi-year contract | Managed Triage — Signal Booster tier (technical plausibility pre-verification) |
| Subscription | Multi-year contract | Managed Triage — Expert Assessment tier (full managed response with Decision-Ready Executive Briefs) |
| Freemium | Pay-as-you-go | Vaults — Free self-serve bounty payment vault |
| Other | Multi-year contract | Bug Bounty Programs — quote-based |
Go-to-market motion5 records
Immunefi product offering
Product offeringCore offering
Immunefi operates a crowdsourced bug bounty and onchain security services platform that connects Web3/crypto protocols with a network of 60,000+ whitehat security researchers. The platform encompasses bug bounty programs, smart contract audits, audit competitions (including Attackathons), GitHub pull request reviews, invite-only researcher programs, the Safe Harbor legal framework for whitehat rescue operations, on-chain bounty payment vaults, and tiered managed triage — all unified under the Immunefi Magnus SecOps command center. Protocol teams and crypto enterprises pay subscription, managed-service, and transaction fees to access the platform, while security researchers earn project-funded rewards for verified vulnerability reports.
Differentiator
Problem solved
Functional benefit
Brands
- Immunefi Magnus: Unified SecOps command center for the onchain economy, launched in 2025, operating across four pillars: Aggregate, Orchestrate, Agentify, and Evolve.
- Immunefi Foundation
- Immunefi Studio
Products and services
- Immunefi Magnus Unified SecOps command center for the onchain economy that aggregates the full onchain security stack into a single platform and runs AI-powered role-specific security agents across the protocol's security lifecycle. Magnus operates across four pillars: Aggregate, Orchestrate (Security Swarm automation engine), Agentify (role-specific AI security agents), and Evolve (Codexa proprietary onchain vulnerability dataset).
- Bug Bounty Programs Flagship crowdsourced bug bounty service for 650+ Web3 projects, connecting protocol teams with 60,000+ whitehat security researchers for continuous vulnerability disclosure. Standard, Premium, KYC Required, Vault-enabled, and Triaged variants are visible in the bug bounty explorer.
- Immunefi Audits Full-scope smart contract audit service that matches projects with elite Web3 security researchers who have collectively protected over $180B across Web3. Includes a structured five-step workflow from request through matched auditor, code review, fixes, final review, and delivered report.
- Audit Competitions (including Attackathons) Time-bound, crowdsourced code reviews where projects offer a capped reward pool distributed to whitehats based on graded submissions, with Attackathons extending the model to large-scale, education-based ecosystem-wide competitions.
- Immunefi PR Reviews Service embedding Immunefi security researchers directly into customers' GitHub pull requests via the Immunefi GitHub Application to provide human-powered vulnerability detection before code reaches production. Backed by 1,000+ mainnet bugs secured and $120M+ paid to top researchers.
- Invite-Only Programs Private, time-bound security programs granting exclusive access to a curated group of top-tier researchers for deep-dive code coverage during critical milestones such as pre-launch or major upgrades.
- Immunefi Safe Harbor Legal framework that lets whitehats rescue user funds during an active blackhat attack and redirect those funds to a protocol-controlled vault on Immunefi in exchange for a project-set reward, built on the Security Alliance (SEAL) Safe Harbor Agreement.
- Immunefi Vaults On-chain bounty payment system built on the Safe multisig smart contract that lets projects deposit stablecoins, ETH, or any Uniswap-listed asset and pay researchers on-chain in a single transaction. Available on Ethereum Mainnet and Optimism, with Polygon, Gnosis, Arbitrum, and other EVM chains coming soon.
- Managed Triage 24/7 professional triage service that filters, validates, and triages incoming bug reports, offering three tiers (Time Saver for operational efficiency, Signal Booster for technical plausibility verification, and Expert Assessment for decision-ready executive briefs with Funds at Risk financial context) plus an optional 24/7 add-on.
Companies that use Immunefi
Customer profileIdeal customer profiles2 records
Immunefi technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability10 records
Feature9 records
Immunefi partnerships and signals
Strategic signalRecent moves6 records
Expansion highlights5 records
Immunefi competitors and assessment
Company assessmentDirect peers
- CertiK: CertiK is a leading Web3 security firm offering smart contract audits, formal verification, and security rankings. Directly comparable as the most prominent competitor in Web3 audits and bug bounties, co-hosting Immunefi events and competing for the same protocol customers.
- Code4rena: Code4rena runs crowdsourced audit competitions for Web3 protocols, directly overlapping with Immunefi's Audit Competitions and Attackathons. Both compete for protocol security budgets and researcher mind share in the same DeFi audit segment.
- Sherlock: Sherlock is a Web3 audit and bug bounty platform offering competitive audit contests and coverage. Competes head-to-head with Immunefi's Audit Competitions and bug bounty services for DeFi protocol security budgets.
- Trail of Bits: Trail of Bits is a well-established blockchain and cybersecurity firm offering smart contract audits, security tooling, and consulting. Comparable to Immunefi's audit and security services for institutional and high-value protocol customers.
- Spearbit: Spearbit is a Web3 security services network providing elite independent security researchers for audits. Comparable to Immunefi's curated audit services and competes for protocol audit and security review engagements.
- Hacken: Hacken is a blockchain security auditor offering smart contract audits, bug bounties, and security scoring. Direct competitor in Web3 security services, particularly for DeFi protocol customers seeking end-to-end security coverage.
Broad incumbents
- OpenZeppelin: OpenZeppelin is a broader Web3 security and infrastructure provider offering audited libraries, smart contract development tools, and security services. Comparable as an incumbent Web3 security platform competing for the same protocol customer base.
- Chainalysis: Chainalysis is a blockchain analytics and compliance platform with a growing security footprint (incident response). Broader incumbent that overlaps with Immunefi's onchain monitoring and threat detection ambitions through its incident response services.
Emerging players
- Sigma Prime: Sigma Prime is a blockchain security and infrastructure firm specializing in Ethereum and consensus-layer audits (notably Lighthouse and Ethereum 2.0). Comparable as an emerging specialized player in Web3 audits with comparable client roster (Sigma Prime is also an Immunefi customer).
Regional players
- SlowMist: SlowMist is a blockchain security firm founded in Asia, offering audits, threat monitoring, and incident response. Comparable as a regional player in Web3 security, particularly strong in Asian markets where Immunefi also operates from its Singapore base.
Market position
Strengths4 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
Immunefi social profiles
Digital presenceImmunefi compliance and trust
Trust signalCompliance1 record
Immunefi financial estimates
Financial estimateRevenue estimate
Valuation estimate
Immunefi leadership team
Management profileNumber of profiles
Profiles5 records
Immunefi subsidiaries and ownership
Company hierarchySubsidiaries1 record
Immunefi funding detail
Funding detailFunding overview
Funding rounds2 records
Investors16 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Immunefi M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Immunefi
What does Immunefi do?
Immunefi operates a crowdsourced bug bounty and onchain security services platform that connects Web3/crypto protocols with a network of 60,000+ whitehat security researchers. The platform encompasses bug bounty programs, smart contract audits, audit competitions (including Attackathons), GitHub pull request reviews, invite-only researcher programs, the Safe Harbor legal framework for whitehat rescue operations, on-chain bounty payment vaults, and tiered managed triage — all unified under the Immunefi Magnus SecOps command center. Protocol teams and crypto enterprises pay subscription, managed-service, and transaction fees to access the platform, while security researchers earn project-funded rewards for verified vulnerability reports.
Is Immunefi a public or private company?
Immunefi is a private company. It is classified as venture growth investor backed and is currently operating.
When was Immunefi founded?
Immunefi was founded in 2020. It employs 51 to 100 people.
Where is Immunefi based?
Immunefi is headquartered in Singapore, Singapore, in the Asia region.
How does Immunefi make money?
Six revenue lines are on record. Bug Bounty Platform Fees are the primary driver. The others are security Audits, audit Competitions, managed Triage Services, PR Reviews and attackathons.
Who are Immunefi's main competitors?
Direct peers on record are CertiK, Code4rena, Sherlock, Trail of Bits, Spearbit and Hacken. Broad incumbents are OpenZeppelin and Chainalysis. Sigma Prime is listed as an emerging player. SlowMist is listed as a regional player.
Does Immunefi have an API?
No public API is recorded for Immunefi.
What industry is Immunefi in?
Immunefi's product category is Web3 Security Platform. Its primary akta.pro industry code is FSAPAJAL, Bug Bounty, Vulnerability Disclosure & Security Services, with a secondary code of FSAPABAI, Smart Contract Security Tooling (static/dynamic analysis, formal verification). Its NAICS code is 5415 and its SIC code is 7372.