Bug Bounty Platforms evaluated across fee disclosure & take rate, dispute recourse when payment is refused, advertised maximum vs actually paid, and coverage model & blockchain depth.
7bug bounty platforms · sorted by chainchoice score
ranked before any payout data is seen
#1 overall·computed before any payout data is seenOverall
Immunefi
Immunefi
Crypto-native continuous bug bounty marketplace with binding arbitration
Leads the pool on Coverage model & blockchain depth
79ChainChoice Score · first of 7
4199
Catalog strengths
Coverage model & blockchain depthFee disclosure & take rate
Why it leads
Best in the pool on model depth (9/10; next 8/10)
3 points ahead of Sherlock: +4.7 pts payout transparency, +1.9 pts model depth
Provider states broad availability
Evidence
4/4
criteria scored · no receipt file
Margin
+3
over Sherlock, ranked #02
Rank stability
Firm
#1 holds when every published criterion is moved ±1
Tradeoff
−2
Dispute recourse when payment is refused — behind this pool's best
Jurisdiction
Global
no restricted market on record
Score breakdowntick = pool best
Fee disclosure7/10
Dispute recourse5/10
Payout transparency6/10
Model depth9/10
Ranking-blind · a guided run tailors this to your size, custody & jurisdiction
#ProviderScoreEvidenceKey strengths
2−3
SH
Sherlock
no receipt file
Dispute recourse when payment is refusedCoverage model & blockchain depth
3−9
CY
Cyfrin CodeHawks
no receipt file
Advertised maximum vs actually paidDispute recourse when payment is refused
4−2
Cantina (Spearbit)
Cantina (Spearbit)
no receipt file
Coverage model & blockchain depthFee disclosure & take rate
5−1
HackenProof
HackenProof
no receipt file
Coverage model & blockchain depthFee disclosure & take rate
6−4
HackerOne
HackerOne
no receipt file
Advertised maximum vs actually paidDispute recourse when payment is refused
7−8
Secure3
Secure3
no receipt file
Fee disclosure & take rateCoverage model & blockchain depth
Ranking-blind — order computed before any payout data is joined
Below the table
How this ranking works
Everything the table draws on continues here: how firm the #1 is, the per-criterion arithmetic behind each score, who pays ChainChoice, and the full guide to choosing.
Direct answer
What is the best bug bounty platforms in 2026?
Immunefi ranks #1 overall for bug bounty platforms on ChainChoice. Crypto-native continuous bug bounty marketplace with binding arbitration. It holds that rank under an affiliate-blind methodology scored across 4 published, weighted criteria — the code that ranks providers physically cannot read affiliate payouts (CI-enforced), so a payout can't move a rank. The verdict re-computes on every fee change, incident, or regulatory action; full reasoning and the audit receipt are below.
Best picks
Best bug bounty platforms in 2026
A bounty platform is not an audit, and this page scores it as what it is: a standing offer to pay strangers for bugs. The decisive questions are whether the platform discloses its fee and take rate, what recourse a researcher has when a payment is refused, and how the advertised maximum compares with what has actually been paid — headline ceilings in this market are marketing, and are shown as facts rather than scored.
Best overall
Immunefi
Immunefi
Crypto-native continuous bug bounty marketplace with binding arbitration
Data checked Sep 2026
Crypto-native continuous bug bounty marketplace with binding arbitration. Strongest on coverage model & blockchain depth (9/10): Deepest crypto-native continuous-bounty footprint: "$125M+" paid, "83,000+ registered security researchers", "500+ protocols" (immunefi.com/bug-bounty-program/), plus audit competitions, and it is absorbing Code4rena's bounty customers and researchers after that platform's 13 May 2026 wind-down. Weakest on dispute recourse when payment is refused (5/10): immunefi.com/rules/ prohibits "Disputing a bug report in the dashboard once it has been paid or marked as closed, with the exception of requesting mediation"; in the directory's data 123 of 176 programmes are "Pay to Mediate" (20 of them "No Free Mediations") and arbitration — "The expected output is a final binding decision on a report, followed by enforcement (as required) of the bounty reward from the Project to the Security Researcher" — is enabled on 19 of 176. On advertised maximum vs actually paid (6/10): Immunefi's own blog publishes "The median payout for a critical is $20,000 . The mean sits at $114,355" against "$107.3 million in awards for confirmed critical vulnerabilities alone"; the public directory lists 176 programmes and marks "Total Paid" as Private on 146, while 30 disclose a figure (The Graph 1,595,724; Immunefi's own programme 76,128; Polygon "Total paid 8.2M from 86 paid reports"). Published price: "the subscription removes the 10% platform fee on all payouts" — i.e. the default is a 10% platform fee on every payout.
Best for: Coverage model & blockchain depth — 9/10
Why this score4 published criteria · leads 2 of 4
Published criterionWtScore, and the best hereGap/10Pts
Fee disclosure & take rate7.2·76.7
Dispute recourse when payment is refused7.2−254.8
Advertised maximum vs actually paid6−164.8
Coverage model & blockchain depth3.6·94.3
Σ methodology points20.6/32
Each bar is the score on that criterion’s own 0–10 scale, never rescaled to the pool. The dark line is the best any product here reached on that axis. Wt is the most the criterion can add to the 86-point weighted total. Pts is weight × score × 32; the sum is the methodology score, and each weighted point behind the leader costs 2.6 on the displayed score. how these are weighted
Why it ranks first
Why Immunefi leads this category right now
Crypto-native continuous bug bounty marketplace with binding arbitration. Strongest on coverage model & blockchain depth (9/10): Deepest crypto-native continuous-bounty footprint: "$125M+" paid, "83,000+ registered security researchers", "500+ protocols" (immunefi.com/bug-bounty-program/), plus audit competitions, and it is absorbing Code4rena's bounty customers and researchers after that platform's 13 May 2026 wind-down. Weakest on dispute recourse when payment is refused (5/10): immunefi.com/rules/ prohibits "Disputing a bug report in the dashboard once it has been paid or marked as closed, with the exception of requesting mediation"; in the directory's data 123 of 176 programmes are "Pay to Mediate" (20 of them "No Free Mediations") and arbitration — "The expected output is a final binding decision on a report, followed by enforcement (as required) of the bounty reward from the Project to the Security Researcher" — is enabled on 19 of 176. On advertised maximum vs actually paid (6/10): Immunefi's own blog publishes "The median payout for a critical is $20,000 . The mean sits at $114,355" against "$107.3 million in awards for confirmed critical vulnerabilities alone"; the public directory lists 176 programmes and marks "Total Paid" as Private on 146, while 30 disclose a figure (The Graph 1,595,724; Immunefi's own programme 76,128; Polygon "Total paid 8.2M from 86 paid reports"). Published price: "the subscription removes the 10% platform fee on all payouts" — i.e. the default is a 10% platform fee on every payout.
Best for
Coverage model & blockchain depth — 9/10
Main tradeoff
Its rulebook is no longer public. The support articles defining "No Fix, No Pay", Issuing Payouts and Arbitration Overview all now return a login wall ("Login to your account | Immunefi") — you cannot read the terms that govern whether you get paid until after you sign up. And the "no fix, no pay" rule itself means a project that acknowledges your critical but declines to fix it owes you nothing; immunefi.com/rules/ only references the rule obliquely, listing "Abusing the 'no fix, no pay' rule by stealth fixing the bug later without providing full payment to the whitehat" as prohibited conduct.
Verify before signup
"the subscription removes the 10% platform fee on all payouts" — i.e. the default is a 10% platform fee on every payout. The annual subscription price that removes it is NOT published; three tiers (BBP Subscription "Annual flat fee, zero commission on payouts", Enterprise Subscription, Premium BBP) are listed with no dollar amounts.
Recommendation summary
What should decide this category
Do you want continuous coverage of deployed code, or a time-boxed contest before launch?
Do you know what percentage the platform takes from a payout, and is it published?
What happens if you and a researcher disagree about severity — who decides, and can it be appealed?
Quick picks
Strong options in this category
Start with the lead choice first, then use the shortlist only if you still need a challenger or stronger fit for a specific setup.
Best overall
Immunefi
Immunefi
Crypto-native continuous bug bounty marketplace with binding arbitration
Crypto-native continuous bug bounty marketplace with binding arbitration. Strongest on coverage model & blockchain depth (9/10): Deepest crypto-native continuous-bounty footprint: "$125M+" paid, "83,000+ registered security researchers", "500+ protocols" (immunefi.com/bug-bounty-program/), plus audit competitions, and it is absorbing Code4rena's bounty customers and researchers after that platform's 13 May 2026 wind-down. Weakest on dispute recourse when payment is refused (5/10): immunefi.com/rules/ prohibits "Disputing a bug report in the dashboard once it has been paid or marked as closed, with the exception of requesting mediation"; in the directory's data 123 of 176 programmes are "Pay to Mediate" (20 of them "No Free Mediations") and arbitration — "The expected output is a final binding decision on a report, followed by enforcement (as required) of the bounty reward from the Project to the Security Researcher" — is enabled on 19 of 176. On advertised maximum vs actually paid (6/10): Immunefi's own blog publishes "The median payout for a critical is $20,000 . The mean sits at $114,355" against "$107.3 million in awards for confirmed critical vulnerabilities alone"; the public directory lists 176 programmes and marks "Total Paid" as Private on 146, while 30 disclose a figure (The Graph 1,595,724; Immunefi's own programme 76,128; Polygon "Total paid 8.2M from 86 paid reports"). Published price: "the subscription removes the 10% platform fee on all payouts" — i.e. the default is a 10% platform fee on every payout.
Best for: Coverage model & blockchain depth — 9/10
Fee disclosure & take rate · 30%
7/10
Dispute recourse when payment is refused · 30%
5/10
Advertised maximum vs actually paid · 25%
6/10
Coverage model & blockchain depth · 15%
9/10
Quick pick
SH
Sherlock
Contest-first audits with post-launch bounty and coverage backstop
Contest-first audits with post-launch bounty and coverage backstop. Strongest on dispute recourse when payment is refused (7/10): Best-engineered escalation ladder in the category, and it is not opt-in: Level 1 a Sherlock core-team judge; Level 2 the "Sherlock Protocol Claims Committee" enforced by a "4 of 7 multisig" with "1 week to come to a decision"; Level 3 the UMA Optimistic Oracle. Costs are published: "$1k to escalate the issue to the… Weakest on advertised maximum vs actually paid (3/10): Publishes the largest advertised bounty in the entire category — Usual Labs "16,000,000 USDC" on audits.sherlock.xyz/bug-bounties, alongside 35 other programmes with maxima down to 5,000 USDC — but publishes no total-paid figure anywhere: not per programme, not in aggregate. Pure advertised-max disclosure with no… Published price: "The Platform Fee is equal to ten percent (10%) of the Research Fee" (docs.sherlock.xyz/bug-bounties/post-launch-bounty).
Best for: Dispute recourse when payment is refused — 7/10
Fee disclosure & take rate · 30%
7/10
Dispute recourse when payment is refused · 30%
7/10
Advertised maximum vs actually paid · 25%
3/10
Coverage model & blockchain depth · 15%
7/10
Quick pick
CY
Cyfrin CodeHawks
Cyfrin's competitive audit arena; contest-only, no continuous bounty
Cyfrin's competitive audit arena; contest-only, no continuous bounty. Strongest on advertised maximum vs actually paid (7/10): The contest model structurally removes the advertised-versus-paid gap: a fixed pool (ZKsync Era 500,000 USDC, Chainlink CCIP $200,000, Gamma $50,000 USDC) is distributed in full by a published formula, so there is no headline maximum that goes unpaid. Held below 8 because no platform-wide total-paid figure is… Weakest on fee disclosure & take rate (3/10): the only fee statements are qualitative — "True to the Cyfrin ethos, we have reduced platform fees" (cyfrin.io blog, 1 July 2024) and a docs comparison row "| **Pricing** | Low platform fees | Higher platform fees |" — and the published formula and lines-of-code pool sizing divide the pool among auditors, not the platform's take. On coverage model & blockchain depth (4/10): Contest-only — there is no continuous bug bounty product, so it cannot cover live deployed code between competitions. Prize pools are "calculated based on the number of lines of code in the codebase's scope". The contests page data holds 45 contests; only one has started since April 2025 (BattleChain Confidence Pools, 7.25 ETH, July 2026). Published price: Platform fee: not published ("True to the Cyfrin ethos, we have reduced platform fees" — no figure given, cyfrin.io blog, 1 July 2024).
Best for: Advertised maximum vs actually paid — 7/10
Fee disclosure & take rate · 30%
3/10
Dispute recourse when payment is refused · 30%
4/10
Advertised maximum vs actually paid · 25%
7/10
Coverage model & blockchain depth · 15%
4/10
Quick pick
Cantina (Spearbit)
Cantina (Spearbit)
Spearbit's public bounty and competition arm, now inside an agentic security suite
Spearbit's public bounty and competition arm, now inside an agentic security suite. Strongest on coverage model & blockchain depth (8/10): continuous bounties and competitions with Cantina triage — cantina.xyz/opportunities/bounties lists "All 52 Bounties 52 Competitions Ended 144", programmes are marked "Cantina-Triaged", and cantina.security/bounties states "Every valid finding is reproduced, validated, and reviewed before it reaches your team". On advertised maximum vs actually paid (4/10): the same page publishes one platform aggregate — "Payouts available $66.1M" versus "Total paid out $54.1M" — and per-programme maxima (Uniswap "Maximum reward $15,500,000", "Findings submitted 1,002"), but no per-programme paid amount, median or mean; cantina.xyz/leaderboard lists per-researcher all-time winnings ("1 zigtur @ zigtur $932,505.92") that do not reconcile any programme's advertised maximum with what it paid. Weakest on dispute recourse when payment is refused (3/10): The researcher participation guide (docs.cantina.security/for-security-researchers/participation-guides/bug-bounty-participation) describes a mediation process but states no fee schedule, no escalation tier, no external arbiter and no binding outcome. A researcher whose severity is downgraded has no published route… Published price: Platform fee/commission: not published (absent from cantina.security/bounties and from docs.cantina.security/llms-full.txt). What IS published: "Payouts available $66.1M" across 52 live bounties versus "Total paid out $54.1M" historically.
Best for: Coverage model & blockchain depth — 8/10
Fee disclosure & take rate · 30%
4/10
Dispute recourse when payment is refused · 30%
3/10
Advertised maximum vs actually paid · 25%
4/10
Coverage model & blockchain depth · 15%
8/10
Frequently asked
Questions people ask before choosing bug bounty platforms
Does a large advertised bounty mean large payouts?
No. The headline maximum is a marketing ceiling and is shown here as a fact, never scored as an achievement. What is scorable is whether the platform lets anyone verify the gap between what it advertises and what it has genuinely paid.
Why does coverage model carry the least weight?
Because it is the most visible difference and the easiest to check yourself. A contest covers a commit for a window; continuous coverage follows deployed code afterwards. The harder questions — what the platform keeps, and what recourse exists when a payout is refused — carry 60% between them.
What matters most when picking an bounty platform?
Fee disclosure and dispute recourse — 60% of the weight between them. They are the two things a researcher cannot discover until it is too late.
Free advisor·No signup needed
Still unsure? Get your best bug bounty platforms pick
Answer a few quick questions and get one clear recommendation based on how you actually plan to use crypto — then review the evidence before deciding.
No signup·Free first pass · Private·No spam · No account
Not financial advice · Independent · Always do your own research
Browse this network
How this ranking is built
Reviewed on fee disclosure & take rate, dispute recourse when payment is refused, advertised maximum vs actually paid, and coverage model & blockchain depth.
Data checked Sep 2026 · Independent rankings · We show our work
Not financial advice · For informational purposes only · Always do your own research
//Analytics consent·GDPR · ePrivacy · TTDSG
ChainChoice measures page views and conversions with two cookieless, EU-hosted services: Plausible and Cloudflare Web Analytics. Nothing loads until you accept, and rankings are identical either way.ChainChoice measures how the engine is used — page views, conversions, referrer — through two cookieless, EU-hosted services: Plausible and Cloudflare Web Analytics. No advertising cookies, no cross-site profile, no data resale. Neither script loads until you accept, and rankings are identical whether you accept or decline.