Filecoin reduced its bug bounty program payouts by 67%, cutting maximum rewards from $150K to $50K across multiple tiers.
Tech & Launches ·
Filecoin has reduced maximum payouts across its bug bounty program, cutting the top reward tier from $150,000 to $50,000—a 67% decrease. The critical reward cap for blockchain-level vulnerabilities, which previously topped at $150,000, now stands at $50,000. These adjustments span five reward tiers, representing a combined reduction of $255,000 across the program structure.
The bounty framework continues to calculate critical-level rewards at 10% of directly affected funds, subject to the new $50,000 ceiling. A minimum payment of $25,000 remains in place to discourage researchers from withholding reports. Severity assessment follows the Immunefi Vulnerability Severity Classification System V2.3 and the OWASP Risk Rating model, with final award amounts subject to the Filecoin Security Team's discretion based on factors including exploitation difficulty, impact, and report quality.
The rationale behind the reduction has not been disclosed in available materials. It remains unclear whether the changes reflect shifting priorities within the Filecoin Foundation or responses to previous program activity. The full program details and historical comparison are available on Immunefi.