Submit once. CertiK verifies.
You get paid what the bug is worth.
Join the private network, submit a reproducible finding, and get a tracked, fair reward decision after CertiK verifies it.
Backed by CertiK: 5,181 projects secured, $500B+ assessed since 2018.
Reproducible reports stay private to the author and authorized CertiK triagers.
Two formats, one access ladder
Not every engagement on Hunt is a bug bounty. Challenges are their own format with their own rules, and your access level decides which ones you can enter.
The report lifecycle
Submit
A researcher opens a bug bounty program from their workspace and submits a reproducible finding with a clear title, severity, affected asset, and a proof-of-concept. Challenges are scored on their own terms and do not enter this pipeline.
Triage
A CertiK expert reproduces the PoC, checks duplicates, and sets severity independently of the protocol. CertiK runs triage and payouts; status updates land in your dashboard.
Decision
Accepted, duplicate, or out-of-scope decisions are recorded with clear rationale so manual decisions stay documented.
Payout and disclosure
Programs publish reward ranges and payout handling terms before launch. CertiK records accepted, resolved, and paid states after human confirmation.