What is Bug bounty?

Definition

A bug bounty pays independent researchers for responsibly disclosing vulnerabilities, with rewards scaled to severity. It turns an ongoing security budget into continuous review.

In practice

Unlike a fixed-window audit, a bounty runs for as long as the code is live, which suits contracts that hold growing balances. A credible programme states scope, severity tiers, payout ranges, and a disclosure process. For researchers it is also a public, checkable track record.

Bug bounty on Dapping

Related terms