Skip to content
Glossary

Bug bounty

A standing offer to pay researchers who report vulnerabilities through a defined disclosure process.

Why it matters

It changes the economics at the margin: a researcher who finds a flaw has a lawful, paid route that competes with the alternative. It also gives a project something an audit cannot — continuous coverage of code as it changes, rather than a snapshot of one commit.

What you can check

A bounty is meaningful in proportion to its terms: the maximum payout against the value actually at risk, whether the scope covers deployed contracts or only the repository, and whether there is a published safe-harbour commitment not to pursue good-faith researchers.

Not advice. Definitions are for understanding, not instruction. Nothing here is financial, legal, tax or security advice.