Audit Competitions Evaluation Process At-A-Glance
Audit competition evaluations occur over 3 periods. Submission, Evaluation, and Dispute period.
Submission Period
The submission period is when the competition is live.
SRs can submit new bug reports, discuss them with the project, and request help from Immunefi.
As bug reports come in Immunefi will triage them, and depending on the projects’ technology and the bug reports’ complexity Immunefi will rely partly or not at all on the projects’ input for our judging.
Both Immunefi and the project will discuss bug reports with SRs as needed and provide SRs support over Discord.
Help requests to Immunefi will not be addressed immediately. Instead they will be addressed in the evaluation period.
Evaluation Period
The evaluation period begins when the competition ends.
Immunefi will address all help requests and make a judgement on all reports based on the info provided.
SRs and the project may continue to share information to influence Immunefi’s judgement up until our decision is made on a given bug report.
Dispute Period
The dispute period begins after Immunefi has judged each report. When it begins will be announced in advance.
SRs can dispute Immunefi’s decisions in their bug reports.
Publicly disputing another SR’s bug report is prohibited.
Immunefi will now review disputes and make final judgements.
Ultimately, in a dispute with a project over a bug report Immunefi will have the final say to judge the bug report’s validity and severity.
Your report may qualify for a reevaluation if either:
- ✅ Escalated, but later closed: A report was escalated by Immunefi’s managed triaging, but later closed by the project or Immunefi.
- ✅ Confirmed, but severity changed: A report was confirmed as valid, but the severity level was changed by the project or Immunefi.
Otherwise your report does not qualify, some ineligible reasons are:
- ❌ Insufficient Information: A dispute request lacks the proper information to justify a reevaluation.
- ❌ Not escalated by Immunefi: A report closed by Immunefi’s managed triaging or through automated processes.
- ❌ Insight begging: Requesting that a closed report qualify as an insight.
Comments
0 comments
Article is closed for comments.