Overview
A bug bounty is a program that rewards security researchers for responsibly disclosing vulnerabilities. It harnesses the community to find bugs. Many protocols run ongoing bounty programs.
How It Works
Researchers find and report vulnerabilities to the program, which validates and rewards them based on severity. Responsible disclosure gives teams time to fix issues before public release. Bounties complement audits.
Why It Matters
Bug bounties extend security coverage beyond audits and incentivize continuous scrutiny. They have prevented many exploits. They are a key part of protocol security and community engagement.
Related Concepts
Bug Bounties relate to Smart Contract Audits and Security research. They are part of the broader Security ecosystem.