Skip to main content

Bug Bounty

A program that rewards researchers for responsibly reporting valid security vulnerabilities.

Definition

A program that rewards researchers for responsibly reporting valid security vulnerabilities.

Why it matters

Security concepts help users and developers recognize common blockchain attack surfaces and defenses.

How it works

A project lists their smart contract or website on a platform, defining the scope and reward amounts based on bug severity. Researchers submit reports detailing the vulnerability and the reproduction steps. If confirmed, the project pays the researcher and patches the issue while maintaining confidentiality until the fix is deployed.

Real-world example

Immunefi is the leading platform for Web3 bug bounties, where protocols like MakerDAO have paid millions for critical vulnerability disclosures.

Advantages

  • Access to global security talent
  • Cost-effective vulnerability management
  • Proactive threat mitigation

Limitations

  • Risk of researchers leaking findings
  • Requires significant capital for rewards
  • Competitive landscape for top talent

Common misconceptions

  • Bug bounties are not just for developers; many security researchers are skilled auditors who do not write protocol code.
  • Some assume all projects have fair bounty programs, but terms of service can vary wildly between platforms.

Canonical knowledge ID: glossary:bug-bounty