Advertise on KripZen — put your brand in front of a global crypto audience.Get in touch →

Glossary entry

Bug Bounty Programme

Wallets & Security

How to read an exchange or protocol bug bounty: scope, safe harbour and payout history matter far more than the headline maximum reward.

Definition

A bug bounty programme is a standing offer to pay outside researchers for privately reporting vulnerabilities, tiered by severity and governed by a published policy that defines what is in scope, how to report, and what the researcher is permitted to do while testing. In crypto it fills a gap that audits cannot: an audit is a fixed engagement against a fixed snapshot of code, while a bounty runs continuously against the deployed system, including the parts that changed after the audit finished. The headline number is the least informative part of it. Read the scope first — a programme that covers only a marketing website while the bridge contracts and the withdrawal signing path sit outside it is not protecting the thing that can lose your money. Then read the safe harbour clause, which is the promise not to pursue legal action against a researcher who stayed within the rules; without it, the researchers most capable of finding the serious bugs have every reason to stay away. Then look for evidence the programme actually pays: published payout totals, resolved report counts, or a listing on a platform that records disclosures. A large maximum reward with a narrow scope, no safe harbour and no payment record is a marketing line. A modest maximum with broad scope, clear rules and a visible history is a functioning control.

Next

Related terms

More in Wallets & Security