Bug Bounty
A program that rewards researchers for responsibly reporting valid security vulnerabilities.
Explain Like I'm 12
A program that rewards researchers for responsibly reporting valid security vulnerabilities.
Why It Matters
Security concepts help users and developers recognize common blockchain attack surfaces and defenses.
How It Works
A project lists their smart contract or website on a platform, defining the scope and reward amounts based on bug severity. Researchers submit reports detailing the vulnerability and the reproduction steps. If confirmed, the project pays the researcher and patches the issue while maintaining confidentiality until the fix is deployed.
Real-World Example
Immunefi is the leading platform for Web3 bug bounties, where protocols like MakerDAO have paid millions for critical vulnerability disclosures.
Advantages
- Access to global security talent
- Cost-effective vulnerability management
- Proactive threat mitigation
Limitations
- Risk of researchers leaking findings
- Requires significant capital for rewards
- Competitive landscape for top talent
Common Misconceptions
- Bug bounties are not just for developers; many security researchers are skilled auditors who do not write protocol code.
- Some assume all projects have fair bounty programs, but terms of service can vary wildly between platforms.
Knowledge Explorer
Explore This Concept in the Knowledge Graph
See how Bug Bounty connects to other concepts, books, research, and developer resources.
Related Terms
Phishing
Phishing is a social engineering attack where malicious actors impersonate legitimate platforms, services, or individuals to deceive users into disclosing sensitive information, such as private keys, seed phrases, or login credentials. In the crypto sector, phishing is highly sophisticated; attackers often create fake websites, send fraudulent emails, or use social media bots to trick users into signing malicious transactions that drain their wallets.
Private Key
A private key is a secret, mathematically generated string of characters that grants the owner complete control over an associated cryptocurrency address. It acts as a digital signature tool, allowing users to authorize transactions and prove ownership of funds. In a decentralized network, the private key is the ultimate proof of authority; whoever possesses the private key effectively owns the assets associated with the corresponding address. It is never meant to be shared with anyone.
Smart Contract Audit
A structured review of smart-contract code and system design intended to identify vulnerabilities, logic errors, and security risks.
Sybil Attack
A Sybil attack is a security threat in decentralized networks where an attacker creates a large number of pseudonymous identities to gain a disproportionate influence over the system. By controlling the majority of nodes or participating addresses, the attacker can disrupt network consensus, censor transactions, or manipulate voting processes in governance mechanisms, thereby subverting the decentralization and integrity of the blockchain.
51% Attack
An attack where one entity or coalition controls enough consensus power to reorganize blocks, censor transactions, or attempt double spending.
Address Poisoning
A scam where attackers create lookalike address activity so victims may accidentally send funds to the wrong address.