What is a Bug Bounty?
A bug bounty program offers financial rewards to security researchers who discover and responsibly report vulnerabilities in a protocol's smart contracts or infrastructure. These programs incentivize ethical hackers to find bugs before malicious actors exploit them, creating a cost-effective security layer that complements formal audits.
How it Works
Bug bounty programs establish scope, rules, and reward tiers for vulnerability reports. Researchers examine code within the defined scope and submit findings through designated channels. Programs evaluate submissions, verify vulnerabilities, and pay rewards based on severity.
Typical bug bounty structure includes:
- Scope Definition: Specific contracts, systems, and vulnerability types covered
- Severity Tiers: Critical, high, medium, low classifications
- Reward Ranges: Payments based on impact, often $500 to $1M+
- Submission Process: Secure channels for responsible disclosure
- Response Timeline: Expected time for review and payment
- Safe Harbor: Protection for researchers acting in good faith
Immunefi is the dominant bug bounty platform in DeFi, hosting programs for most major protocols.
Practical Example
Polygon paid a $2 million bounty in 2021 after a researcher discovered a vulnerability that could have compromised $850 million. MakerDAO's Immunefi program offers up to $10 million for critical vulnerabilities, the highest in DeFi. These investments in security research are far cheaper than the potential losses from exploits.
Why it Matters
Active bug bounty programs signal security commitment and provide ongoing protection beyond point-in-time audits. Users should consider bounty size, scope comprehensiveness, and historical payout record when evaluating protocol security. Protocols without bounty programs may have undiscovered vulnerabilities that responsible researchers have no incentive to report.
Fensory displays bug bounty program information for DeFi protocols, helping users identify projects with active security reward programs and assess their commitment to vulnerability discovery.