Crypto glossary

Bug Bounty

A bug bounty is a program in which a project pays security researchers, often called white-hat hackers, for privately reporting vulnerabilities so they can be fixed before criminals exploit them.

Auf Deutsch lesen

How a bounty program works

The project publishes rules: which code is in scope, which kinds of bugs count, how to report them privately, and how much each severity level pays. A researcher who finds a flaw submits a report with proof, the team verifies and fixes it, and the researcher gets paid. In crypto, top rewards for critical bugs can be very large, because a single smart-contract flaw can put the funds of every user at risk.

Many projects run their programs through platforms such as Immunefi or HackerOne, which handle submissions and help resolve disputes. Rewards are often scaled to the funds that were at risk, with a cap.

Why it matters in crypto

Smart contracts are public, often hold large sums and usually cannot be patched instantly once deployed. Anyone in the world can study the code. A bounty gives skilled people a legal, paid alternative to exploiting what they find, which is the main idea: make honest disclosure more attractive than theft.

Bounties complement audits rather than replace them. An audit is a time-limited review by a hired firm before launch; a bounty keeps many independent eyes on the code for as long as it runs.

Bounties after a hack

You will also hear of post-exploit bounties, where a hacked project offers the attacker a share, often around ten percent, to return the rest. These negotiations have recovered funds in some well-documented cases, but they are a damage-control step, not a substitute for a real program.

What a bounty does not tell you

A large advertised bounty signals that a team takes security seriously, but it is not proof that the code is safe. Check whether the bounty covers the contracts that actually hold funds, whether it has a history of paying out, and whether the team also had independent audits. Some projects advertise bounties with vague terms that are rarely honored.

Ask Coach about it

Coach is the AI on AtenaCrypto. It explains crypto with live market data, in plain words.

What should I check about a DeFi protocol's audits and bug bounty before depositing?Ask Coach →

Frequently asked questions

Is a bug bounty the same as an audit?

No. An audit is a paid, time-boxed review before or after launch, while a bounty pays anyone who finds a bug for as long as the program runs.

Is it legal to hunt for bugs in a bounty program?

Generally yes, within the program's published rules. Testing on live funds or going outside the scope can still create legal trouble.

Does a big bounty mean a protocol is safe?

No. It shows a security commitment and creates incentives, but bugs can remain undiscovered, and other risks like oracles or admin keys are not covered.

Related terms

AuditExploitSmart Contract RiskSmart ContractDeFi (Decentralized Finance)Due Diligence

Learn it step by step

AC Learning explains these ideas in interactive lessons — the first eight sections are free.

Open AC Learning → Create a free account

All glossary terms · Educational reference only — not investment, legal, tax or financial advice.