Skip to article
Degrees of SatoshiFollow the connections.
Degrees of Satoshi/ Encyclopedia

Encyclopedia DeFi · Entry 368

Bug bounties and audits: different security evidence and incentives

Theme
DeFi
Sources
4 cited records
Reading time
About 3 minutes
Automated verification
Substantive update
In this article

At a glance

Key facts

Key facts for Bug bounties and audits: different security evidence and incentives
FactDetailSource
Audit limitOpenZeppelin explicitly says audits do not ensure the absence of bugs.[1]
Bounty scopeThe cited Aave program defines eligible systems, impacts and researchers.[2]
Evidence requirementThat program requires a proof of concept for smart-contract reports.[2]
01

An old report does not cover every later change

Imagine an audit examined version A, then an upgrade added version B’s withdrawal logic. The version-A report is useful evidence about its own scope, not proof that the new path was examined. Match the report’s commit or scope to the deployed implementation and check how findings were resolved.

Source-code verification answers whether published code matches deployment; it is a different question from whether the code is safe.

02

A headline reward omits important terms

The Aave program specifies eligible assets and impacts, proof requirements and exclusions. A researcher finding a real issue outside those rules might not qualify for payment. The maximum advertised reward is not a reserve automatically paid to users after a loss.

03

Look for layered evidence

Testing, review, formal verification, monitoring and bounties address different failure paths. Morpho’s risk documentation describes several such practices while still acknowledging contract and oracle risk. A missing known incident is not evidence that every future interaction is safe.

Direct answers

Questions people ask

Does audited mean insured against loss?

No. An audit is security work, not a reimbursement promise. Any cover arrangement has separate terms.

Inspect the evidence

The answer and key facts have stable claim links. These records retain the scope and qualification when reused.

An audit is a planned examination of a defined codebase or system. A bug bounty offers rewards for qualifying vulnerability reports under published rules. They can complement each other, but neither proves that a protocol has no bugs. A useful assessment checks what was examined, what is deployed now and which reports the bounty actually accepts.

Scope: DeFi · data through 2026-10-02. Verification: verified · 2026-10-02T19:18:00.092Z.

Link to this claim
Audit limit: OpenZeppelin explicitly says audits do not ensure the absence of bugs.

Scope: DeFi · data through 2026-10-02. Verification: verified · 2026-10-02T19:18:00.092Z.

Link to this claim
Bounty scope: The cited Aave program defines eligible systems, impacts and researchers.

Scope: DeFi · data through 2026-10-02. Verification: verified · 2026-10-02T19:18:00.092Z.

Link to this claim
Evidence requirement: That program requires a proof of concept for smart-contract reports.

Scope: DeFi · data through 2026-10-02. Verification: verified · 2026-10-02T19:18:00.092Z.

Link to this claim
Revision history
  1. — First publication after primary-source research and separate automated verification.

Source register

Sources and references

Retrieval dates and locators are recorded individually.
  1. Preparing for mainnetOpenZeppelin

    Audits are scoped security work, not a guarantee.

    Locator: Auditing and security; Admin accounts; Upgrades admin · Version / scope: Primary page retrieved 2026-10-02; hash recorded · Retrieved: 2026-10-02T19:10:47.728ZOpen source
  2. AAVE Bug BountyImmunefi / Aave DAO

    Program terms illustrate limitations; no guarantee of absence of bugs.

    Locator: Program overview; scope; eligibility; prohibited activities · Version / scope: Primary page retrieved 2026-10-02; hash recorded · Retrieved: 2026-10-02T19:10:47.211ZOpen source
  3. Risk and Security DocumentationMorpho

    Distinguishes types of protocol risk.

    Locator: Smart contract; Oracle; Counterparty; Bad debt; Liquidity risks · Version / scope: Documentation retrieved for the 2026-10-02 editorial scope; content hash recorded · Retrieved: 2026-10-02T18:53:22.330ZOpen source
  4. Cover ProductsNexus Mutual

    Scope, period and discretionary assessment, without calling it guaranteed compensation.

    Locator: Product wording; discretionary cover; claims · Version / scope: Documentation retrieved for the 2026-10-02 editorial scope; content hash recorded · Retrieved: 2026-10-02T18:53:23.174ZOpen source
How this article was made

Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.

Editorial method and corrections

Degrees of Satoshi editorial project. “Bug bounties and audits: different security evidence and incentives.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bug-bounties-vs-audits/