# Bug bounties and audits: different security evidence and incentives

An audit is a planned examination of a defined codebase or system. A bug bounty offers rewards for qualifying vulnerability reports under published rules. They can complement each other, but neither proves that a protocol has no bugs. A useful assessment checks what was examined, what is deployed now and which reports the bounty actually accepts.

Evidence: [Preparing for mainnet](https://docs.openzeppelin.com/contracts/5.x/learn/preparing-for-mainnet); [AAVE Bug Bounty](https://immunefi.com/bug-bounty/aave/information/)

Canonical: https://degreesofsatoshi.com/encyclopedia/bug-bounties-vs-audits/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T19:18:00.092Z
Data current through: 2026-10-02

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Audit limit:** OpenZeppelin explicitly says audits do not ensure the absence of bugs. ([Preparing for mainnet](https://docs.openzeppelin.com/contracts/5.x/learn/preparing-for-mainnet))
- **Bounty scope:** The cited Aave program defines eligible systems, impacts and researchers. ([AAVE Bug Bounty](https://immunefi.com/bug-bounty/aave/information/))
- **Evidence requirement:** That program requires a proof of concept for smart-contract reports. ([AAVE Bug Bounty](https://immunefi.com/bug-bounty/aave/information/))

## An old report does not cover every later change

Imagine an audit examined version A, then an upgrade added version B’s withdrawal logic. The version-A report is useful evidence about its own scope, not proof that the new path was examined. Match the report’s commit or scope to the deployed implementation and check how findings were resolved.

Source-code verification answers whether published code matches deployment; it is a different question from whether the code is safe.

Evidence: [Preparing for mainnet](https://docs.openzeppelin.com/contracts/5.x/learn/preparing-for-mainnet); [AAVE Bug Bounty](https://immunefi.com/bug-bounty/aave/information/)

## A headline reward omits important terms

The Aave program specifies eligible assets and impacts, proof requirements and exclusions. A researcher finding a real issue outside those rules might not qualify for payment. The maximum advertised reward is not a reserve automatically paid to users after a loss.

Evidence: [AAVE Bug Bounty](https://immunefi.com/bug-bounty/aave/information/)

## Look for layered evidence

Testing, review, formal verification, monitoring and bounties address different failure paths. Morpho’s risk documentation describes several such practices while still acknowledging contract and oracle risk. A missing known incident is not evidence that every future interaction is safe.

Evidence: [Risk and Security Documentation](https://docs.morpho.org/learn/resources/risks/); [Preparing for mainnet](https://docs.openzeppelin.com/contracts/5.x/learn/preparing-for-mainnet)

## Questions

### Does audited mean insured against loss?

No. An audit is security work, not a reimbursement promise. Any cover arrangement has separate terms.

Evidence: [Preparing for mainnet](https://docs.openzeppelin.com/contracts/5.x/learn/preparing-for-mainnet); [Cover Products](https://docs.nexusmutual.io/overview/cover-products/)

## Claims and scope

### bug-bounties-vs-audits-quick-answer

An audit is a planned examination of a defined codebase or system. A bug bounty offers rewards for qualifying vulnerability reports under published rules. They can complement each other, but neither proves that a protocol has no bugs. A useful assessment checks what was examined, what is deployed now and which reports the bounty actually accepts.

Scope: {"collection":"defi","dataAsOf":"2026-10-02","blockHeight":null}

### bug-bounties-vs-audits-fact-audit-limit

Audit limit: OpenZeppelin explicitly says audits do not ensure the absence of bugs.

Scope: {"collection":"defi","dataAsOf":"2026-10-02","blockHeight":null}

### bug-bounties-vs-audits-fact-bounty-scope

Bounty scope: The cited Aave program defines eligible systems, impacts and researchers.

Scope: {"collection":"defi","dataAsOf":"2026-10-02","blockHeight":null}

### bug-bounties-vs-audits-fact-evidence-requirement

Evidence requirement: That program requires a proof of concept for smart-contract reports.

Scope: {"collection":"defi","dataAsOf":"2026-10-02","blockHeight":null}

## Sources

- [Preparing for mainnet](https://docs.openzeppelin.com/contracts/5.x/learn/preparing-for-mainnet) — OpenZeppelin. Audits are scoped security work, not a guarantee. Locator: Auditing and security; Admin accounts; Upgrades admin. Retrieved: 2026-10-02T19:10:47.728Z.
- [AAVE Bug Bounty](https://immunefi.com/bug-bounty/aave/information/) — Immunefi / Aave DAO. Program terms illustrate limitations; no guarantee of absence of bugs. Locator: Program overview; scope; eligibility; prohibited activities. Retrieved: 2026-10-02T19:10:47.211Z.
- [Risk and Security Documentation](https://docs.morpho.org/learn/resources/risks/) — Morpho. Distinguishes types of protocol risk. Locator: Smart contract; Oracle; Counterparty; Bad debt; Liquidity risks. Retrieved: 2026-10-02T18:53:22.330Z.
- [Cover Products](https://docs.nexusmutual.io/overview/cover-products/) — Nexus Mutual. Scope, period and discretionary assessment, without calling it guaranteed compensation. Locator: Product wording; discretionary cover; claims. Retrieved: 2026-10-02T18:53:23.174Z.

## Revision history

- 2026-10-02: First publication after primary-source research and separate automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Bug bounties and audits: different security evidence and incentives.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bug-bounties-vs-audits/
