Skip to main content

Bug Bounty

security · development

A program offering rewards to security researchers who responsibly disclose vulnerabilities.

1.definition

A bug bounty defines which systems and vulnerabilities are in scope, how researchers should test and report safely, and how eligible findings are assessed. Reward size can depend on severity, exploitability, impact, report quality, and the program's rules.

2.limits

A bounty is not proof that a system is secure and does not replace audits, testing, monitoring, or incident response. Researchers should read authorization and safe-harbor terms before testing; activity outside the stated scope may not be protected or rewarded.

Related terms

All terms and definitions may update as the Cryptionary improves.