Status DataClose notification

Summer Security: Last Catch—Inside HackenProof's Summer 2025 Bug Bounty Event

Dmytro Matviiv
Dmytro Matviiv
CEO HackenProof

Between late August and late September 2025, HackenProof ran its biggest seasonal community event yet: a month-long bug bounty campaign spanning seven programs across Web3 infrastructure, trading, data, and consumer platforms. Here's the full story—why it happened, who took part, and how it played out.


Why HackenProof Launched a Summer-Ending Bug Hunt

Web3 kept its usual pace through the summer of 2025—fast growth and just as fast a stream of new security incidents: smart contract exploits, wallet vulnerabilities, DeFi platform breaches. HackenProof had spent recent months running recovery bug bounty programs for projects trying to claw back stolen funds and patch the flaws that let attackers in, and that frontline experience made one thing clear—proactive defense beats incident response every time.

So HackenProof decided to close out the season with something bigger than a single audit: a month-long, community-wide event that would let ethical hackers stress-test a real lineup of Web3 and crypto platforms before problems turned into headlines. The timing lined up neatly with HackenProof's upcoming 8th anniversary, giving the initiative both a practical and a celebratory reason to exist. The result was the Summer Security: Last Catch Event, running August 25 – September 25, 2025.


What the Event Offered

The format was straightforward: every valid vulnerability report earned hunters standard bounty payouts plus Pearl Bug Tokens, which doubled as entries into HackenProof's Holiday Contest for extra prizes. Beyond the payouts, the event was pitched as a skill-building exercise—a chance for both newcomers and veteran researchers to sharpen their craft while contributing to a safer Web3 ecosystem.

Joining was simple: head to the event page, hit "Join Now," register, pick a target program, and start hunting.


The Programs Behind the Event

Six partner companies opened their doors for the event, spanning infrastructure, trading, data, and consumer platforms—and because two of them split their scope into separate web and mobile programs, researchers actually had seven distinct programs to choose from:

Web3 infrastructure & smart wallets

Trading & market data

  • Flipster (Web & Mobile)—a fast-growing crypto derivatives exchange serving over 1 million users with roughly $20B in monthly trading volume
  • CoinGecko—the widely used crypto data aggregator, with researchers focused on API security and the integrity of its market data

Travel & consumer platforms

Together, the lineup gave hunters a genuinely broad testing ground—from low-level smart contract logic to large-scale consumer-facing apps—all within a single campaign.


How It Played Out

By the time the event closed on September 25, it had drawn 1,225 registered participants who collectively filed 166 vulnerability reports across the seven programs. Rewards followed each program's own severity-based payout structure, and HackenProof layered on extra incentives for top performers: branded merch boxes (T-shirts, caps, stress relievers, LEGO sets, and more) tiered by ranking. Partner Chainstack also chipped in 50 promo coupons for a month of its Growth Plan, giving participants a taste of the platform's advanced features.

HackenProof singled out five standout contributors for the quality and volume of their work: @paktiko, @MrOwl, @cengaver, @0xdefault, and @r08—hunters whose reports stood out both for what they found and for how they engaged with the broader community.


The Takeaway

Last Catch closed out the summer the way it opened—with a straightforward bet that channeling researcher attention toward real production systems does more for Web3 security than any single audit could. Over a month, seven programs across infrastructure, trading, data, and consumer apps underwent a real stress test. Participants received bounties, tokens, and merch, and HackenProof added another data point on what structured, incentive-driven community testing can surface at scale.

HackenProof has signaled this won't be a one-off—more seasonal events are planned, with future campaigns expected to build on the same formula of open programs, tiered rewards, and community recognition.

Share article:
More topics:

Read more on HackenProof Blog