Researcher earns $1M via Immunefi bug bounty platform after discovering a vulnerability in several Polkadot parachains that could have been exploited for~$200M
Vishal Chawla / The Block :
Context & Ripple Effects
Immunefi has been building toward payouts of this size since its $24M Series A led by Framework Ventures last September, which funded its business of running bug bounty programs for crypto services. The platform's own coverage of the hacker economy already documented researchers earning $1M+ per find back in 2020 — this award makes good on that trajectory.
The scale gap with legacy tech is stark: Apple paid just $100K for a Sign in with Apple flaw that could hijack any user's account on third-party apps, and Poly Network offered only a $500K bounty after a hacker returned $340M+ in stolen assets. Here, $1M was paid before any theft occurred, against a ~$200M exposure across three Polkadot parachains.
First-order effects
- The Polkadot parachains involved patch the vulnerability with no funds lost, while the researcher collects one of the largest single bug bounty payouts on record from Immunefi.
Second-order effects
- Other crypto projects running Immunefi programs face pressure to match nine-figure-exposure payouts, pushing bounty budgets up sharply relative to web2 norms like Apple's $100K ceiling.
Third-order effects
- If proactive million-dollar payouts keep beating post-hack recovery offers like Poly Network's, crypto security spend structurally shifts from incident response to pre-exploit incentives, with platforms like Immunefi as the intermediary layer.
The trend: Crypto security economics are moving from post-hack negotiation to pre-emptive, platform-intermediated bounties priced against potential losses rather than severity tiers.