Futures
Access hundreds of perpetual contracts
CFD
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
CFD
U.S. stock CFD derivatives
US Stocks
Access real US stocks and ETFs
HK Stocks
Trade quality Hong Kong-listed stocks
Korean Stocks
SK Hynix
Real Korean stocks and top assets
Stock Futures
High leverage, 24/7 trading
Tokenized Stocks
Backed by real stock assets
IPO Access
Unlock full access to global stock IPOs
GUSD
Mint GUSD for Treasury RWA yields
Stocks Activities
Trade Popular Stocks and Unlock Generous Airdrops
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
IPO Access
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Promotions
AI
Gate AI
Your all-in-one conversational AI partner
Gate AI Bot
Use Gate AI directly in your social App
GateClaw
Gate Blue Lobster, ready to go
Gate for AI Agent
AI infrastructure, Gate MCP, Skills, and CLI
Gate Skills Hub
10K+ Skills
From office tasks to trading, the all-in-one skill hub makes AI even more useful.
The easiest way to erase a security researcher’s work is five words: “We already knew about it.”
Without a timestamp, that isn’t a defense. It’s a rewrite.
@TermMaxFi closes that loophole through Known Issue Assurance in its Immunefi bounty. A known bug must have been disclosed publicly or logged privately through a self-reported submission before the researcher files it.
If the project cannot prove the issue was already known, then a valid report remains in scope and is due a reward. The burden of proof works both ways: researchers bring a PoC; the project brings receipts.
Immunefi handles triage, arbitration is enabled, and neither side gets to retcon the timeline after the fact. That turns a bug bounty from “the project has the final word” into an evidence-based process.
This does not mean every duplicate report gets paid. Unfixed issues already disclosed in public audits are excluded, and there is no public evidence that TermMax has had to invoke this clause in an actual dispute.
The point is preventative: the rules are written before money, reputation, and incentives collide.
Mature Web3 security is not just bigger bounty numbers. It is due process when someone says, “Trust us, we knew.”
Should “no receipts, no known-issue defense” become the default rule for every serious crypto bug bounty?