Islamic Finance Principles Assessment
Riba — Does Immunefi involve interest?
Immunefi's core business is fee-for-service (bug bounty hosting, audit competitions, Magnus subscriptions), not lending or interest. Researchers keep 100% of bounty payouts, and no evidence points to interest-bearing treasury holdings, though treasury composition is undisclosed. For Muslim investors, riba exposure at the protocol level appears low, though staking reward mechanics remain unclear enough to warrant caution.
Assessment: Moderate Riba
Score: 65/100
Our methodology examines 10 criteria to evaluate how well Immunefi avoids interest-based mechanisms.
Immunefi generates revenue by charging protocols for bug-bounty listings, audit competitions, and access to its Magnus monitoring product — a service-fee model rather than interest extraction from deposits or loans. Researchers retain the full value of bounties they earn. The sources disclose a 10% "Reserve" allocation intended for emergencies and growth, but its composition (cash, treasury bonds, interest-bearing instruments, or crypto) is not specified. Without visibility into how this reserve is held or invested, a residual riba concern exists at the treasury level, though nothing in the available documentation indicates conventional interest income is a designed feature of Immunefi's business model.
IMU staking allows protocols and researchers to lock tokens for deeper Magnus access, fee discounts, and boosted bounty payouts. Rewards are drawn from a fixed 47.5% Ecosystem & Community allocation rather than an ongoing interest-bearing pool, and payouts are described as scaling with activity and impact — a variable, performance-linked structure closer to profit-sharing than to guaranteed interest. However, the sources do not specify whether returns carry any fixed minimum, whether principal is at risk, or whether lock-up periods and slashing apply. This absence of concrete terms is a gharar issue more than a riba one, but it prevents a fully confident permissibility finding on the staking product as launched.
Gharar — How much uncertainty does Immunefi involve?
Immunefi carries moderate uncertainty: the operating business and leadership are well-documented, but the token's launch mechanics, staking terms, and treasury composition are not. What reduces gharar is a named team and years of verifiable platform operation; what increases it is thin token-specific disclosure. On balance, informed investors face real but not extreme uncertainty.
Assessment: Moderate Gharar (Material Uncertainty)
Score: 50.1/100
Our methodology examines 15 criteria including team transparency, audit quality, and governance.
Immunefi is led by publicly identifiable individuals — CEO Mitchell Amador, VP of Engineering Simone Marx, Foundation director David Acutt, and named growth/marketing leads — all traceable via LinkedIn and public profiles. The underlying platform has operated since 2020 with claims of securing 650+ protocols and over $180B in user funds. This is a strong anti-anonymity signal rare among newer tokens. However, governance is described only in marketing language ("governance and utility token") without disclosed voting mechanics, and one smart-contract repository (the Vaults System) was noted as private at audit time, leaving open-source status for that component unconfirmed.
Dedaub conducted named, dated audits of Immunefi's protocol contracts: 16 July 2021 covering BugReportNotary, Escrow, token, vesting and distributor modules, and 7 February 2024 covering the Arbitration and Vaults systems. This is a genuine, verifiable audit trail for the core protocol. Critically, however, no audit specific to the IMU token itself or its 2025 staking contract appears in available sources. Given the token only launched in November 2025, this is an unaudited-component gap that should be named plainly as a gharar concern — investors are relying on older protocol-level audits, not confirmation that the token and staking mechanics as deployed are equally vetted.
Maysir — Does Immunefi involve gambling or speculation?
Immunefi is not designed as a gambling or speculative instrument; it is a functioning security marketplace connecting researchers, protocols, and bounty payouts. The main speculative element sits in secondary-market trading of IMU itself, as with most listed tokens. Overall, the protocol's own design leans toward productive utility rather than maysir.
Assessment: Moderate Maysir (High Risk)
Score: 61.5/100
Our methodology examines 11 criteria to determine whether Immunefi is a gambling instrument or a genuine economic tool.
Immunefi coordinates a real, ongoing service: matching security researchers with protocols that need vulnerability testing, running audit competitions, and operating the Magnus monitoring product. Payouts are earned through demonstrated work — finding and reporting genuine bugs — rather than chance-based outcomes. The claimed $100M+ in bounties paid and $25B in prevented hacks reflect tangible security value delivered to the broader DeFi ecosystem. This fee-for-service, effort-rewarded structure is fundamentally different from wagering on unpredictable outcomes, and supports treating the base protocol as a legitimate productive enterprise rather than a speculative vehicle.
Against this genuine utility must be weighed the token's market behavior: IMU launched via CoinList with only 3.74% of supply in the public sale, fully unlocked at TGE, while insiders hold roughly 68.8% of supply under vesting. This structure creates conditions for early-holder profit-taking and volatility once vested tranches unlock, independent of platform usage. Such trading-driven speculation is common across the token market generally and is not unique to Immunefi's design, but combined with a very short listed trading history since November 2025, it means near-term price action is likely to be driven more by speculative positioning than by underlying platform adoption.
The Full 27-Point Screening
1. Legitimacy (4 criteria)
| Criterion | Score | Analysis |
|---|
| Team Transparency | 88/100 | CEO, VP Engineering, and Foundation director are all named and independently verifiable via LinkedIn and personal sites. |
| Fraud & Scam Risk | 78/100 | No fraud, hack, or rug-pull allegations against Immunefi itself appear in sources; it is instead cited as a source cataloguing others' scams. |
| Use Case Legitimacy | 88/100 | Sources describe a clear, long-running real-world utility as a bug-bounty and security-coordination platform protecting billions in assets. |
| Ethical Practices | 88/100 | The platform's own business is security services, not a haram sector; any third-party client lending activity is not attributable to Immunefi's own design. |
Summary: Immunefi is led by named, traceable individuals with a multi-year operating track record and no fraud indicators found against the project itself.
2. Project Operations (9 criteria)
| Criterion | Score | Analysis |
|---|
| Core Protocol Business | 88/100 | Core business is security coordination/bug bounties, a service sector with no prohibited activity described. |
| Transaction Fees | 78/100 | Revenue is generated via service fees charged to protocols, with researchers keeping 100% of bounty payouts, not interest-based extraction. |
| Treasury Assets | 45/100 (low evidence) | Sources mention only a 10% reserve pool for emergencies with no disclosure of what assets the treasury actually holds. |
| Revenue Model | 80/100 | Revenue model is explicitly service-fee based (bounty hosting, audits, Magnus access), not lending or interest income. |
| Transparency | 45/100 | Documentation and disclosure whitepapers exist, but one audited repository was explicitly noted as private, so full open-source status is unclear. |
| Governance | 32/100 | Token is labeled "governance" but no voting mechanics are described, and insiders reportedly control the large majority of supply at launch. |
| Launch Fairness | 28/100 | Public sale received only 3.74% of supply with 100% TGE unlock, while team/backers/reserve retained the vast majority under vesting. |
| Token Distribution | 35/100 | Team and early allocations leave insiders controlling roughly two-thirds of circulating supply at launch per disclosed figures. |
| Speculation/Utility Ratio | 55/100 | Token has documented utility (fee payment, staking tiers, rewards) but is also actively traded with disclosed FDV, indicating mixed speculative and utility demand. |
Summary: The base protocol is a legitimate fee-for-service security platform, but token launch distribution is insider-heavy and governance mechanics are undisclosed.
3. Financial Health (4 criteria)
| Criterion | Score | Analysis |
|---|
| Protocol Revenue | 82/100 | Revenue is service-fee based rather than derived from interest or lending activity. |
| Financial Status | 52/100 | The underlying platform has an established multi-year track record, but the token itself is very new with no disclosed financial statements. |
| Interest Assessment | 82/100 | The base Immunefi protocol does not itself lend, borrow, or charge interest; it is a fee-for-service security platform. |
| Audit Quality | 58/100 | Named-firm dated audits (Dedaub, 2021 and 2024) exist for Immunefi's protocol contracts, but no audit specific to the IMU token or its 2025 staking mechanism was found. |
Summary: Revenue is fee-based rather than interest-based, some platform contracts have named third-party audits, but no audit specific to the IMU token or its staking mechanism was found.
4. Token Economics (5 criteria)
| Criterion | Score | Analysis |
|---|
| Token Purpose | 72/100 | Sources describe concrete utility uses for IMU: fee payment, feature access, staking tiers, and researcher rewards. |
| Governance Rights | 38/100 | Token is described as a "governance" asset but no specific voting rights or governance process is detailed in the sources. |
| Rewards Distribution | 55/100 | Rewards are tied to activity (bounty size, staking tier) but funded from a fixed pre-allocated pool rather than a clear profit-share mechanism. |
| Speculation Controls | 48/100 | Team/investor vesting cliffs exist as anti-dump measures, but the public tranche unlocked fully at TGE and the token trades speculatively. |
| Asset Backing | 52/100 | Value is tied to platform utility and adoption rather than any disclosed hard-asset backing. |
Summary: IMU has documented utility uses but combines fixed-supply reward pools, heavy insider allocation, and open market tradability that together create meaningful speculative exposure.
5. Staking Mechanism (5 criteria)
| Criterion | Score | Analysis |
|---|
| Mechanism Type | 48/100 | A staking mechanism exists for feature/tier access, but custodial status, lock-up, and mechanics are not detailed in the sources. |
| Islamic Contract Classification | 30/100 (low evidence) | Sources give no information classifying the staking arrangement under any specific Islamic contract structure. |
| Rewards Structure | 58/100 | Rewards are described as scaling with activity and impact rather than being a fixed guaranteed return, but detail is limited. |
| Documentation | 38/100 | General platform documentation exists, but specific staking risk disclosures, lock-up terms, or slashing rules are not found in the sources. |
| Shariah Alignment | 40/100 | Without clarity on contract structure or risk-sharing mechanics, a core Shariah classification question remains unresolved based on available sources. |
Summary: A staking mechanism exists for feature access and reward boosts, but its custodial nature, lock-up terms, and Islamic contract classification are not established in the sources.
Overall Assessment: Immunefi presents as a genuine, non-meme security-infrastructure project with a transparent team and service-based revenue, but token distribution concentration, unclear governance, and undocumented staking mechanics leave several Shariah-relevant questions unresolved from the available sources.