Skip to content
GetProfitable
Search
Dictionary

Bug bounty

A standing offer to pay researchers for responsibly disclosed vulnerabilities, often scaled to the funds a bug could have taken.

Large programs pay up to seven figures for critical findings, which is rational: a bounty of $1m against $100m at risk is cheap insurance, and it gives a researcher who could otherwise exploit the bug a legal, profitable alternative.

A funded, long-running bounty says more about a team's security posture than a one-off smart-contract-audit, because it is continuous and it prices the risk honestly. Check that the scope covers the deployed contracts and that past payouts were actually made.

Disclosure must stay private. Broadcasting a fix or a proof-of-concept publicly invites front-running-onchain of the patch, and researchers who exploit first and negotiate afterwards have faced prosecution in several jurisdictions regardless of returning the funds.

Related: smart-contract-audit, front-running-onchain, admin-key-risk, flash-loan-attack

Educational only, not advice. Spotted an error? Post in Site Feedback.