Encyclopedia DeFi · Entry 368
Bug bounties and audits: different security evidence and incentives
In this article
At a glance
Key facts
| Fact | Detail | Source |
|---|---|---|
| Audit limit | OpenZeppelin explicitly says audits do not ensure the absence of bugs. | [1] |
| Bounty scope | The cited Aave program defines eligible systems, impacts and researchers. | [2] |
| Evidence requirement | That program requires a proof of concept for smart-contract reports. | [2] |
An old report does not cover every later change
Imagine an audit examined version A, then an upgrade added version B’s withdrawal logic. The version-A report is useful evidence about its own scope, not proof that the new path was examined. Match the report’s commit or scope to the deployed implementation and check how findings were resolved.
Source-code verification answers whether published code matches deployment; it is a different question from whether the code is safe.
A headline reward omits important terms
The Aave program specifies eligible assets and impacts, proof requirements and exclusions. A researcher finding a real issue outside those rules might not qualify for payment. The maximum advertised reward is not a reserve automatically paid to users after a loss.
Look for layered evidence
Testing, review, formal verification, monitoring and bounties address different failure paths. Morpho’s risk documentation describes several such practices while still acknowledging contract and oracle risk. A missing known incident is not evidence that every future interaction is safe.
Direct answers
Questions people ask
Does audited mean insured against loss?
No. An audit is security work, not a reimbursement promise. Any cover arrangement has separate terms.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
An audit is a planned examination of a defined codebase or system. A bug bounty offers rewards for qualifying vulnerability reports under published rules. They can complement each other, but neither proves that a protocol has no bugs. A useful assessment checks what was examined, what is deployed now and which reports the bounty actually accepts.
Scope: DeFi · data through 2026-10-02. Verification: verified · 2026-10-02T19:18:00.092Z.
Link to this claimAudit limit: OpenZeppelin explicitly says audits do not ensure the absence of bugs.
Scope: DeFi · data through 2026-10-02. Verification: verified · 2026-10-02T19:18:00.092Z.
Link to this claimBounty scope: The cited Aave program defines eligible systems, impacts and researchers.
Scope: DeFi · data through 2026-10-02. Verification: verified · 2026-10-02T19:18:00.092Z.
Link to this claimEvidence requirement: That program requires a proof of concept for smart-contract reports.
Scope: DeFi · data through 2026-10-02. Verification: verified · 2026-10-02T19:18:00.092Z.
Link to this claimRevision history
- — First publication after primary-source research and separate automated verification.
Source register
Sources and references
Retrieval dates and locators are recorded individually.- Preparing for mainnetOpenZeppelin
Audits are scoped security work, not a guarantee.
Locator: Auditing and security; Admin accounts; Upgrades admin · Version / scope: Primary page retrieved 2026-10-02; hash recorded · Retrieved: 2026-10-02T19:10:47.728ZOpen source - AAVE Bug BountyImmunefi / Aave DAO
Program terms illustrate limitations; no guarantee of absence of bugs.
Locator: Program overview; scope; eligibility; prohibited activities · Version / scope: Primary page retrieved 2026-10-02; hash recorded · Retrieved: 2026-10-02T19:10:47.211ZOpen source - Risk and Security DocumentationMorpho
Distinguishes types of protocol risk.
Locator: Smart contract; Oracle; Counterparty; Bad debt; Liquidity risks · Version / scope: Documentation retrieved for the 2026-10-02 editorial scope; content hash recorded · Retrieved: 2026-10-02T18:53:22.330ZOpen source - Cover ProductsNexus Mutual
Scope, period and discretionary assessment, without calling it guaranteed compensation.
Locator: Product wording; discretionary cover; claims · Version / scope: Documentation retrieved for the 2026-10-02 editorial scope; content hash recorded · Retrieved: 2026-10-02T18:53:23.174ZOpen source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Bug bounties and audits: different security evidence and incentives.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bug-bounties-vs-audits/