SR (Security Researcher) Rewards
The reward pool size will be listed on the program’s page.
If bugs and Insights are found, then the portion of the reward pool allocated to Insights is determined by how many unique bugs are found:
- 10+ unique bugs found = 3%
- 4 - 9 unique bugs found = 5%
- 1 - 3 unique bugs found = 7%
- *Immunefi may reduce the portion of the reward pool allocated to Insights to prevent Insights from earning more than bugs.
If not a single bug is found (Insights do not count as bugs) the reward pool unlocked is distributed according to the ‘Insight Rewards Formula’ listed below.
Information about bug severities and Insight reports can be found in Immunefi's Severity Classification System.
Bug Rewards Formula
SR rewards are based on the severity of bugs found, in a Sybil-resistant manner.
The chief finder of each bug earns 10% of that bug’s rewards. The chief finder is the first person to prove the greatest severity level of the bug.
LowBugPoints = 0.9 * (0.9 ^ (NumberOfFinders - 1)) / NumberOfFinders
ChiefFinder_LowBugBonus = 0.1 * (0.9 ^ (NumberOfFinders - 1))
MediumBugPoints = 2.7 * (0.9 ^ (NumberOfFinders - 1)) / NumberOfFinders
ChiefFinder_MediumBugBonus = 0.3 * (0.9 ^ (NumberOfFinders - 1))
HighBugPoints = 8.1 * (0.9 ^ (NumberOfFinders - 1)) / NumberOfFinders
ChiefFinder_HighBugBonus = 0.9 * (0.9 ^ (NumberOfFinders - 1))
CriticalBugPoints = 32.4 * (0.9 ^ (NumberOfFinders - 1)) / NumberOfFinders
ChiefFinder_CriticalBugBonus = 3.6 * (0.9 ^ (NumberOfFinders - 1))
A SR’s portion of the bug rewards is equivalent to their percentage of all bug points earned.
Insight Rewards Formula
SR rewards are based on the category of Insight found.
Documentation Improvements = 1 points
Architectural Decentralization and Composability = 2 points
Code Optimizations and Enhancements = 3 points
Security Best Practices = 5 points
A SR’s portion of the Insight rewards is equivalent to their percentage of all Insight points earned.
Only the best report of a given Insight is rewarded. Duplicate reports of Insights are NOT rewarded.
Insights are NOT eligible for mediation or appeal. Begging for an Insight will receive a warning and repeated insight begging is a bannable offence.
All Star Pool
The All Star pool is allocated exclusively for Immunefi All Stars and is 20% of the overall pool. All Stars can earn from the All Star pool in addition to earning from the primary reward pool.
The All Star Pool is only applicable to audit competitions and attackathons, not invite-only programs.
Any All Star security researcher taking part in the competition qualifies for performance-based fixed pay if they finish in the top 10%, 33%, or 50% of the competition leaderboard, with the fixed pay amount varying in tiers corresponding to their All Star rank.
The pool is initially divided into 7 shares (expressed below as percentages).
- Elite SRs (4 shares): 57.1% of ASPpool (ASP * 4 /7), with the requirement to rank in the top 10%.
- Senior SRs (2 shares): 28.5% of ASPpool (ASP * 2 /7), with the requirement to rank in the top 33%.
- Associate SRs (1 share): 14.2% of ASPpool (ASP * 1 /7), with the requirement to rank in the top 50%.
Consider a contest with an overall reward pool of $250,000 and an All Star pool of $50,000 pool. The pool is initially divided into 7 shares (each worth approximately $7,142.86), allocated as follows:
- Elite SRs: 4 shares (≈ $28,571.43), with the requirement to rank in the top 10%.
- Senior SRs: 2 shares (≈ $14,285.71), with the requirement to rank in the top 33%.
- Associate SRs: 1 share (≈ $7,142.86), with the requirement to rank in the top 50%.
If no one in a particular level meets their performance requirements, that level’s shares are removed and the All Star pool rewards are proportionally distributed to any remaining levels.
If no All Stars meet the requirements, the pool is folded back into the overall pool for everyone to earn from.
Podium Pool
The Podium Pool is reserved for any security researchers who rank in the top three of an audit competition, with a slight bonus for All Star members.
The Podium Pool will make up 10% of the overall reward pool for each competition.
For example, if the overall pool is $250,000, the Podium Pool will be $25,000.
Reward Distribution
Rewards from the Podium pool are split almost equally between 1st, 2nd, and 3rd place.
All Stars get marginally more if they place compared to non-All Stars, according to this formula:
- All Stars = 1.2 points
- Non-All StarsAll Stars = 1 point
For example:
- 2 All Star members and 1 non-All Star member place in the top 3
- Total Podium Points = 3.4
Payouts:
- A: (1.2 / 3.4) × $25,000 = $8,823.53
- B: (1.0 / 3.4) × $25,000 = $7,352.94
C: (1.2 / 3.4) × $25,000 = $8,823.53
Payment Terms
Rewards are distributed all at once after the competition has ended. No rewards are distributed during the competition.
Comments
0 comments
Article is closed for comments.