Skip to content
ExploreHow it worksDocsFor protocols
Sign inRequest access
00Overview01Getting started02How it works03Writing a great report04Scope and rewards05Reward by threat level06Publication and disclosure07FAQ
Browse docs
00Overview01Getting started02How it works03Writing a great report04Scope and rewards05Reward by threat level06Publication and disclosure07FAQ
Researcher field guide

CertiK Hunt Docs

7 sections, in the order you need them: access first, then the report flow, proof-of-concept standards and rewards, and disclosure and conduct last.

01Getting startedWhat CertiK Hunt is, the two engagement formats, and what your access level opens.→02How it worksHow each engagement format runs, and the full journey of a bug bounty report.→03Writing a great reportRequired fields, proof-of-concept standards by asset type, and what gets reports rejected.→04Scope and rewardsScope principles, standard out-of-scope rules, how rewards are determined, currency, KYC, and eligibility.→05Reward by threat levelHow CertiK maps a vulnerability's threat level to a reward, and how feasibility factors in.→06Publication and disclosureCoordinated disclosure rules — what you can share, when, and what voids a report.→07FAQCommon questions about access levels, engagement formats, triage timelines, payments, and disclosure.→
CertiK Hunt is a security research network for challenges and bug bounties, with every finding independently verified by CertiK.
Product
Explore opportunitiesHow it worksDocsRequest access
Researchers
ChallengesBug bountiesDashboardSubmit a report
Protocols
Launch an engagementTalk to the teamCertiK main site
Security & disclosure

All report bodies are encrypted with AES-256-GCM at rest. Only the report author and authorized triagers can decrypt.

© CertiK · CertiK Hunt operates under the CertiK Disclosure Policy v3.

Legal
Terms of UseRules of ConductPrivacy Policy