Library · Crypto, word by word · Infrastructure and development

What is a bug bounty?

A bug bounty is a reward a project offers to people who find and responsibly report security flaws in its code instead of exploiting them. For smart contracts, bounties are often scaled to the amount of money a flaw could put at risk.

What it means for you

A bug bounty means a project pays outsiders to look for flaws in the contracts holding your funds; it does not mean all flaws have been found. Check the bounty's scope: if the contracts you deposit into are outside it, or the reward is small next to the funds at risk, an attacker can gain more by exploiting a bug than by reporting it.

How it works

A bug bounty is a financial reward given to individuals, usually whitehat hackers, who discover vulnerabilities in an application. Because a smart contract can hold user funds directly, a flaw can be exploited for immediate profit; the scaling bug bounty approach ties the payout to the amount of funds at stake, to make disclosure more attractive than exploitation. Bounties complement audits rather than replace them: an audit is an additional round of review at one point in development and will not catch every bug, while a bounty keeps paying for discoveries after launch.

Source: ethereum.org: Smart contract security · checked 4 October 2026

Often confused with

Bug bounty vs Smart contract audit

Related words

Smart contract auditSmart contractReentrancy attackOpen source

Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.