Bug Bounty

Last Updated Sep 24, 2026

In One Sentence

A bug bounty is a program that offers rewards for eligible vulnerability reports submitted under defined testing and disclosure rules.

Definition

A bug bounty encourages security researchers to report weaknesses to the organization responsible for a system. Programs specify which assets and vulnerability types are in scope, how testing may be conducted, and what information a report should contain. Rewards may depend on demonstrated impact, report quality, novelty, and compliance with the program’s terms; discovering an issue does not automatically guarantee payment.

How It Works

A researcher investigates within the authorized scope and privately submits a clear description of the weakness and its impact. The program evaluates the report, checks whether it is a duplicate, and coordinates remediation and any reward. Safe demonstrations should use permitted environments and avoid exposing users’ data or moving real funds without explicit authorization. Publication is normally coordinated according to the stated disclosure policy.

Key Considerations

A bounty program complements audits and internal testing by inviting additional perspectives over time. It is not proof that a product is secure, nor blanket permission to test every related service. Scope can exclude interfaces, third-party dependencies, or operational activities that users assume are covered. Before participating, read the current rules and use the official reporting channel. For users assessing a project, look beyond the maximum advertised reward to the actual scope and response process; an attractive headline does not ensure that every valid report will receive that amount.