Glossary

Bug Bounty

Easy

A reward offered for the identification of vulnerabilities in software.

What Is a Bug Bounty?

Bug bounties are offered in the hope that security vulnerabilities will be identified and reported to the owner of software before they can be exploited by a nefarious actor. In crypto, bug bounties are often offered by cryptocurrency businesses such as protocols, exchanges, and wallet operators.Bounty schemes can be thought of as competitions between friendly hackers. The schemes are opened publicly — and the company offering the bug bounty is (theoretically) able to patch any identified vulnerabilities before they become known to bad actors.In most cases, bug bounties are valued according to the severity of the vulnerability identified. According to HackerOne, almost $900,000 in bug bounties were paid out in 2018 alone. The value of individual bounties can be very low — and it is common for companies to pay about $100 as a bounty for the identification of a low-severity vulnerability. However, critical vulnerabilities can sometimes attract bounties of $10,000 or more.Some hackers make significant sums of money identifying bugs. Guido Vranken, a Dutch researcher, identified 12 bugs in the space of a week — and was paid $120,000 by EOS in return.From a software owner’s perspective, bug bounties are considered to be a supplementary security activity, used in addition to other proactive measures. 

The most important priority for developers is building secure code and minimizing vulnerabilities before shipping a product. However, even the most careful developers will inevitably miss bugs, and some of these may pose security risks. Bug bounties therefore act as an important second line of defence protecting software owners and users from bad actors.

Related Articles

Easy
CMC Crypto News
Jury Convicts Uranium Finance Hacker in $50M-Plus DeFi Exchange Theft
A Manhattan jury convicted Jonathan Spalletta of computer fraud and money laundering for draining over $50M from DeFi exchange Uranium Finance in 2021.
By Motoko Kusanagi
19 hours ago
3m
Easy
CMC Crypto News
Blockstream Refuses Ransom for Bitcoin Stolen From Liquid Network
Blockstream rejected a 15% bug bounty demand from the Liquid Network attackers, leaving 598.5 BTC, worth about $47M, outstanding as the sidechain recovers.
By Frank Armitage
3 weeks ago
3m
Easy
NFTs
OpenSea Pays $200,000 to Ethical Hackers Who Uncovered Critical Security Flaws
One of the hackers says the bug that he discovered could have been used by malicious actors to steal assets.
4 years ago
2m
Easy
Ethereum
Ethereum Reveals Date for Long-Awaited Merge — and Offers $1M Bug Bounty if Critical Flaws Found
This means that the historic switch from a Proof-of-Work to a Proof-of-Stake blockchain could take place a few days earlier than previously advertised.
4 years ago
1m
Easy
Crypto News
Just 18 Out of 1,500 Major Cryptocurrencies Are Fully Secured, Shocking New Research Reveals
It's also emerged that 20% of projects have failed to fix critical security bugs after they have been identified through an audit — potentially putting their users in danger.
4 years ago
3m
Easy
Trading
Coinbase Fixes 'Potentially Market-Nuking' Flaw
Tree of Alpha describes how he alerted the exchange to a vulnerability that could have caused a "potential crisis" — but critics say his bug bounty should have been much higher.
4 years ago
3m