Time
00:32
Aave Labs has proposed splitting its bug bounty program across three platforms: Immunefi, Sherlock, and Cantina.
May 15, 2026
CoinFeed News
CoinFeed reported on May 15th that, according to the official governance page, Aave Labs has proposed reorganizing the Aave DAO's bug bounty framework into multiple subsystem-specific programs, each with its own scope, severity criteria, reward framework, and operating platform. The reorganized bounty coverage will be allocated as follows: Core Aave V3, Core Aave V2, GHO, and non-liquidity protocol infrastructure will use Immunefi; Aave V4 and Aave App Stack will use Sherlock; and Aave V3 on Aptos will use Cantina. The proposal aims to better align bounty incentives with the actual risk profile of each subsystem, simplify the operational review process, and maintain flexibility before evaluating platform performance.