B

What is Bug Bounty?

Crypto Glossary Definition

A reward offered to those who help find and fix vulnerabilities in computer software. This often applies specifically to security-related bugs.

Why Bug Bounty Matters

A bug bounty pays independent security researchers to find and responsibly disclose vulnerabilities in a protocol's code before malicious actors do — it's one of the standard ways serious DeFi projects try to reduce the risk of a smart-contract exploit.

Bug Bounty in Practice

A mid-sized lending protocol preparing to launch a new collateral type decides to run a bug bounty through a platform like Immunefi before going live. The team sets tiered rewards - a modest payout for a low-severity front-end bug, and a much larger sum, scaled to a percentage of funds potentially at risk, for a critical vulnerability that could drain the protocol's liquidity pools. A security researcher spends a week studying the smart contract code, eventually finding a subtle rounding error in how the protocol calculates liquidation thresholds; under a specific sequence of price moves, a position could be liquidated for less collateral than it should require. Rather than exploiting the bug or selling the information, the researcher submits a detailed writeup through the bounty platform's private disclosure channel, including a proof-of-concept transaction on a testnet. The protocol's developers confirm the issue within a day, pause the affected market, patch the contract, and pay out the agreed bounty once the fix is verified. The whole exchange happens without any funds ever being at real risk, and the protocol publishes a short post-mortem crediting the researcher by handle. For the protocol, the payout is far cheaper than the reputational and financial damage an actual exploit would have caused, which is exactly the incentive a bug bounty program is designed to create.

Still have questions about Bug Bounty?

Ask ARIA, our free AI crypto intelligence agent, for a deeper explanation.

Ask ARIA →