Trust Protocols Entry #0883 Classified Declassified

The reason a bug bounty is advertised before it ever pays out

A large bug bounty is promoted as proof of security, but the promise of a reward for finding flaws is displayed long before, and often instead of, any flaw being found.

No visual record attached The written record below is complete.
Plate 783 — The million-dollar bounty whose zero payouts were sold as a clean record

Intuition test — answer before you read on

Why does an advertised bug bounty prove less about security than it suggests?

A protocol advertised a one-million-dollar bug bounty prominently on its homepage as evidence of its commitment to security. The bounty had never paid out. That fact was presented as a strength — no bugs found — when it equally described a programme that no serious researcher had engaged with, on terms that quietly excluded the most severe categories. The advertisement of scrutiny was doing the reassuring, while the scrutiny itself remained a promise rather than a record.

What everyone sees

A user sees a large bounty figure and reads two reassuring messages at once: the team is confident enough to invite attacks, and anything wrong would already have been found and fixed. The size of the reward signals seriousness. The user infers a well-tested system from the existence of the invitation, without distinguishing between a bounty that has attracted rigorous review and one that merely exists as a banner.

What is actually happening

Security researchers note that a bounty programme’s value lies in its results and terms, not its headline number: scope exclusions, low historical payouts, unresponsive triage and unrealistic conditions all hollow out the promise. Many advertised bounties are never meaningfully engaged. A programme that has paid nothing tells you little about security and much about participation. The advertisement substitutes the intention to be reviewed for the fact of having been reviewed under real adversarial pressure.

Why it stays hidden

The hidden mechanism is the display of a future-tense safeguard as a present-tense achievement. A bounty is a standing offer, not a completed test; advertising it converts an open invitation into perceived security. By foregrounding the reward and omitting the record — payouts, scope, engagement — the protocol lets the promise of scrutiny stand in for scrutiny, and no-bugs-found reads as safety when it may mean no-one-looked.

A bounty is an invitation, not a result. Advertised before it pays, it sells the promise of scrutiny in place of the scrutiny.

A bounty is an invitation, not a result. Advertised before it pays, it sells the promise of scrutiny in place of the scrutiny.

The hidden part — entry #0883

Collect this card

A bounty is an invitation, not a result. Advertised before it pays, it sells the promise of scrutiny in place of the scrutiny.

0 / 10,000 collected

Sources & further reading 2
  1. Atzei, Bartoletti & Cimoli — A Survey of Attacks on Ethereum Smart Contracts (2017)
  2. Maillart et al. — Given Enough Eyeballs, All Bugs Are Shallow? (2017)

Circulate this file

Annotations are reserved for archive members.

Sign in to annotate