{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "bug-bounties-vs-audits",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/bug-bounties-vs-audits/",
  "collection": "defi",
  "title": "Bug bounties and audits: different security evidence and incentives",
  "description": "Read a security audit and a bounty program as different forms of evidence, each with a scope and limitations.",
  "aliases": [
    "bug bounty vs smart contract audit",
    "does a bug bounty mean a protocol is safe"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T19:18:00.092Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "An audit is a planned examination of a defined codebase or system. A bug bounty offers rewards for qualifying vulnerability reports under published rules. They can complement each other, but neither proves that a protocol has no bugs. A useful assessment checks what was examined, what is deployed now and which reports the bounty actually accepts.",
    "claimId": "bug-bounties-vs-audits-quick-answer",
    "sourceIds": [
      "x425-defi-oz-mainnet",
      "x425-defi-aave-bounty"
    ]
  },
  "keyFacts": [
    {
      "label": "Audit limit",
      "value": "OpenZeppelin explicitly says audits do not ensure the absence of bugs.",
      "sourceIds": [
        "x425-defi-oz-mainnet"
      ],
      "id": "audit-limit",
      "claimId": "bug-bounties-vs-audits-fact-audit-limit"
    },
    {
      "label": "Bounty scope",
      "value": "The cited Aave program defines eligible systems, impacts and researchers.",
      "sourceIds": [
        "x425-defi-aave-bounty"
      ],
      "id": "bounty-scope",
      "claimId": "bug-bounties-vs-audits-fact-bounty-scope"
    },
    {
      "label": "Evidence requirement",
      "value": "That program requires a proof of concept for smart-contract reports.",
      "sourceIds": [
        "x425-defi-aave-bounty"
      ],
      "id": "evidence-requirement",
      "claimId": "bug-bounties-vs-audits-fact-evidence-requirement"
    }
  ],
  "prerequisites": [
    "smart-contract-audits"
  ],
  "sections": [
    {
      "id": "example",
      "heading": "An old report does not cover every later change",
      "sourceIds": [
        "x425-defi-oz-mainnet",
        "x425-defi-aave-bounty"
      ],
      "paragraphs": [
        "Imagine an audit examined version A, then an upgrade added version B’s withdrawal logic. The version-A report is useful evidence about its own scope, not proof that the new path was examined. Match the report’s commit or scope to the deployed implementation and check how findings were resolved.",
        "Source-code verification answers whether published code matches deployment; it is a different question from whether the code is safe."
      ]
    },
    {
      "id": "program",
      "heading": "A headline reward omits important terms",
      "sourceIds": [
        "x425-defi-aave-bounty"
      ],
      "paragraphs": [
        "The Aave program specifies eligible assets and impacts, proof requirements and exclusions. A researcher finding a real issue outside those rules might not qualify for payment. The maximum advertised reward is not a reserve automatically paid to users after a loss."
      ]
    },
    {
      "id": "interpret",
      "heading": "Look for layered evidence",
      "sourceIds": [
        "x425-defi-morpho-risk",
        "x425-defi-oz-mainnet"
      ],
      "paragraphs": [
        "Testing, review, formal verification, monitoring and bounties address different failure paths. Morpho’s risk documentation describes several such practices while still acknowledging contract and oracle risk. A missing known incident is not evidence that every future interaction is safe."
      ]
    }
  ],
  "faq": [
    {
      "question": "Does audited mean insured against loss?",
      "answer": "No. An audit is security work, not a reimbursement promise. Any cover arrangement has separate terms.",
      "sourceIds": [
        "x425-defi-oz-mainnet",
        "x425-defi-nexus-cover"
      ]
    }
  ],
  "claims": [
    {
      "id": "bug-bounties-vs-audits-quick-answer",
      "articleSlug": "bug-bounties-vs-audits",
      "statement": "An audit is a planned examination of a defined codebase or system. A bug bounty offers rewards for qualifying vulnerability reports under published rules. They can complement each other, but neither proves that a protocol has no bugs. A useful assessment checks what was examined, what is deployed now and which reports the bounty actually accepts.",
      "sourceIds": [
        "source-51752d973dc3abdc",
        "source-56c47d2d3baa981e"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-51752d973dc3abdc",
          "locator": "Auditing and security; Admin accounts; Upgrades admin"
        },
        {
          "sourceId": "source-56c47d2d3baa981e",
          "locator": "Program overview; scope; eligibility; prohibited activities"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:18:00.092Z",
        "reviewer": "Independent automated verification — Codex root, separate from the DeFi drafting agent",
        "notes": [
          "Checked OpenZeppelin absence-of-bugs caveat and source verification versus safety; current Immunefi Aave scope, proof-of-concept and eligibility requirements. Audit not reimbursement."
        ]
      }
    },
    {
      "id": "bug-bounties-vs-audits-fact-audit-limit",
      "articleSlug": "bug-bounties-vs-audits",
      "statement": "Audit limit: OpenZeppelin explicitly says audits do not ensure the absence of bugs.",
      "sourceIds": [
        "source-51752d973dc3abdc"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-51752d973dc3abdc",
          "locator": "Auditing and security; Admin accounts; Upgrades admin"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:18:00.092Z",
        "reviewer": "Independent automated verification — Codex root, separate from the DeFi drafting agent",
        "notes": [
          "Checked OpenZeppelin absence-of-bugs caveat and source verification versus safety; current Immunefi Aave scope, proof-of-concept and eligibility requirements. Audit not reimbursement."
        ]
      }
    },
    {
      "id": "bug-bounties-vs-audits-fact-bounty-scope",
      "articleSlug": "bug-bounties-vs-audits",
      "statement": "Bounty scope: The cited Aave program defines eligible systems, impacts and researchers.",
      "sourceIds": [
        "source-56c47d2d3baa981e"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-56c47d2d3baa981e",
          "locator": "Program overview; scope; eligibility; prohibited activities"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:18:00.092Z",
        "reviewer": "Independent automated verification — Codex root, separate from the DeFi drafting agent",
        "notes": [
          "Checked OpenZeppelin absence-of-bugs caveat and source verification versus safety; current Immunefi Aave scope, proof-of-concept and eligibility requirements. Audit not reimbursement."
        ]
      }
    },
    {
      "id": "bug-bounties-vs-audits-fact-evidence-requirement",
      "articleSlug": "bug-bounties-vs-audits",
      "statement": "Evidence requirement: That program requires a proof of concept for smart-contract reports.",
      "sourceIds": [
        "source-56c47d2d3baa981e"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-56c47d2d3baa981e",
          "locator": "Program overview; scope; eligibility; prohibited activities"
        }
      ],
      "scope": {
        "collection": "defi",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:18:00.092Z",
        "reviewer": "Independent automated verification — Codex root, separate from the DeFi drafting agent",
        "notes": [
          "Checked OpenZeppelin absence-of-bugs caveat and source verification versus safety; current Immunefi Aave scope, proof-of-concept and eligibility requirements. Audit not reimbursement."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "x425-defi-oz-mainnet",
      "label": "Preparing for mainnet",
      "publisher": "OpenZeppelin",
      "url": "https://docs.openzeppelin.com/contracts/5.x/learn/preparing-for-mainnet",
      "locator": "Auditing and security; Admin accounts; Upgrades admin",
      "note": "Audits are scoped security work, not a guarantee.",
      "version": "Primary page retrieved 2026-10-02; hash recorded",
      "checkedAt": "2026-10-02T19:10:47.728Z",
      "contentSha256": "fcc42714a13cadcdc2be1db3c72e63f47865f426b94a3baebb02459111d08a27",
      "recordId": "source-51752d973dc3abdc"
    },
    {
      "id": "x425-defi-aave-bounty",
      "label": "AAVE Bug Bounty",
      "publisher": "Immunefi / Aave DAO",
      "url": "https://immunefi.com/bug-bounty/aave/information/",
      "locator": "Program overview; scope; eligibility; prohibited activities",
      "note": "Program terms illustrate limitations; no guarantee of absence of bugs.",
      "version": "Primary page retrieved 2026-10-02; hash recorded",
      "checkedAt": "2026-10-02T19:10:47.211Z",
      "contentSha256": "bd6fcacfec7ed6e1e823bd62e65e5d6f25298b87a420f8702d8dc0bc4dc0eecc",
      "recordId": "source-56c47d2d3baa981e"
    },
    {
      "id": "x425-defi-morpho-risk",
      "label": "Risk and Security Documentation",
      "publisher": "Morpho",
      "url": "https://docs.morpho.org/learn/resources/risks/",
      "locator": "Smart contract; Oracle; Counterparty; Bad debt; Liquidity risks",
      "note": "Distinguishes types of protocol risk.",
      "version": "Documentation retrieved for the 2026-10-02 editorial scope; content hash recorded",
      "checkedAt": "2026-10-02T18:53:22.330Z",
      "contentSha256": "2f336c66ab4873723d5314f6ba5ec56e3e61b5d10213d62ce96b467e2e46d414",
      "recordId": "source-2c6118fd53915127"
    },
    {
      "id": "x425-defi-nexus-cover",
      "label": "Cover Products",
      "publisher": "Nexus Mutual",
      "url": "https://docs.nexusmutual.io/overview/cover-products/",
      "locator": "Product wording; discretionary cover; claims",
      "note": "Scope, period and discretionary assessment, without calling it guaranteed compensation.",
      "version": "Documentation retrieved for the 2026-10-02 editorial scope; content hash recorded",
      "checkedAt": "2026-10-02T18:53:23.174Z",
      "contentSha256": "8b38c100b57b9be9f06d1ffada0ecc579ba6a9b756c77b4b0c95d843e5b7900e",
      "recordId": "source-a8ad9738787ae4b2"
    }
  ],
  "related": {
    "articles": [
      "defi-cover-claims",
      "protocol-upgrades-and-admin-powers",
      "documented-defi-exploits",
      "protocol-pause-vs-freeze",
      "governance-quorum-thresholds"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and separate automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Bug bounties and audits: different security evidence and incentives.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bug-bounties-vs-audits/"
}
