h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

Recovery Bounties in 2026: The Payout After the Hack

Most bug bounties pay to prevent a hack. A second kind, the recovery bounty, pays hackers or the hunters chasing them to bring stolen crypto home, and in 2026 it went routine.

On the morning of August 31, a Solana automated market maker called Aquifer watched roughly $2.5 million drain out of its system. Within hours the team was not filing a police report or drafting a post-mortem. It was making an offer. Keep twenty percent, the message to the attacker said in effect, return the other eighty, and do it before 14:00 UTC on September 3. That deadline is today. According to crypto.news, the team even published the attacker’s Solana and Ethereum addresses alongside the ultimatum. Whether the money comes back or not, the episode captures a shift in how crypto handles theft: the most consequential bounty a protocol pays is often the one that comes after the break-in, not before it.

This is not the bug bounty most readers picture. The bounty that fills headlines is preventive: a security researcher finds a flaw, reports it privately, and collects a reward sized to the disaster that was avoided. The recovery bounty is its darker twin. The funds are already gone, sitting in a wallet the protocol does not control, and the payout is an inducement to give them back. In 2026 that second instrument stopped being an emergency improvisation and became a standard line in the crypto incident-response playbook, complete with its own pricing norm, its own legal scaffolding, and its own hard limits. This piece is about that payout.

A bounty with a countdown clock

Start with what happened to Aquifer, because it is textbook 2026. The protocol lost about $2.5 million. Notably, crypto.news reported that available information had not established that Aquifer’s smart contracts were exploited at all, leaving compromised wallet access as the leading theory. That detail matters, because a large and growing share of crypto theft is no longer clever math against a contract but old-fashioned key compromise, the failure mode that our guide to multisig best practices exists to prevent. When the loss is a stolen key rather than a broken invariant, there is nothing to patch and nobody to credit for finding a bug. There is only the money, sitting on-chain, and a team trying to talk it home.

So Aquifer did what dozens of teams have now done before it. It sent a message to the thief’s address, named a percentage the attacker could keep, and set a clock. The clock is the tell. A recovery bounty is not a job posting; it is a negotiation conducted in public on a ledger everyone can read, under time pressure, with the leverage tilted toward whoever holds the coins. The protocol is asking a criminal to behave like a contractor, and it is dangling money to make the ask easier to accept than a life of laundering.

Two payouts that share a word

To see why recovery bounties are their own category, put them next to the preventive kind. The advertised ceilings on preventive programs are enormous. The stablecoin issuer Usual set the record with a $16 million maximum on Sherlock, the largest bug bounty in software history at the time, as The Block reported. Yet those numbers are sticker prices, not receipts. Immunefi’s own research across hundreds of long-running programs found that the median critical payout is about $20,000, with a mean near $114,000. Preventive bounties are priced off a hypothetical: the loss that did not happen.

Recovery bounties are priced off a fact: the loss that did. The reward is a slice of real money already stolen, which flips the economics. A 10% recovery bounty on a $24 million theft is worth more than the largest preventive payout most researchers will ever see, and it is paid to whoever holds the coins, who is usually the person who took them. The table below lays out how differently the two instruments behave.

DimensionPreventive bountyRecovery bounty
When it paysBefore any loss, on private disclosureAfter the theft, funds already moved
What triggers itA valid, unexploited vulnerabilityA live or completed exploit
How it is sizedSeverity and funds at risk (a ceiling)Percentage of funds actually recovered
Typical rateMedian critical near $20,000Roughly 10% of what comes back
Who receives itAn ethical researcher who chose to reportThe attacker, or third parties who trace and freeze
Legal footingClear: authorized testing, paid disclosureMurky: a payment to someone who broke in

The last row is the one that keeps lawyers awake. A preventive bounty rewards someone the protocol invited to look. A recovery bounty rewards someone who was not invited at all, which is why the whole practice sits in a legal gray zone we will get to.

How a recovery bounty is actually made

The mechanics have converged on a script. Step one is a public on-chain message, usually an Ethereum or Solana transaction with a note in the input data, addressed to the wallet holding the stolen funds. Step two is a headline number, the percentage the attacker may keep, framed as a bounty rather than a ransom. Step three is a deadline, often twenty-four to seventy-two hours, after which the offer supposedly hardens into something worse: a larger reward for information leading to an arrest, cooperation with exchanges to freeze deposits, and coordination with law enforcement. Step four, if it works, is a return transaction to an address the team controls.

The subtext of every one of these messages is the same calculation. Stealing crypto is easy; keeping it is hard. Modern chain analytics, exchange know-your-customer walls, and stablecoin issuers who can freeze addresses mean a nine-figure haul is often unspendable. A recovery bounty offers the attacker a clean, legal-looking exit with a real number attached, and it lets the team tell its users it did everything possible. Both sides are trading certainty for time. The number that has emerged as the anchor for that trade is ten percent.

Where the ten percent came from

The convention traces to Nomad, the cross-chain bridge drained of $190.7 million on August 1, 2022. The Nomad exploit was unusual because it was a free-for-all: a single flawed contract upgrade let hundreds of copycat wallets replay the same transaction and scoop out funds, so the thieves were not one sophisticated crew but a crowd. With no single party to negotiate with, Nomad broadcast a blanket offer, a 10% bounty for anyone who returned at least 90% of what they took, and framed it as a way for opportunists to become white hats after the fact. As CryptoSlate documented, roughly $22 million came back in the first days.

Nomad chief executive Pranay Mohan gave the practice its mission statement. “The most important thing in crypto is community, and our number one goal is restoring bridged user funds,” he said, pledging to treat anyone who returned 90% as a white hat and to pursue the rest with law enforcement. That single sentence encodes the whole logic of the recovery bounty: the protocol cares more about making users whole than about punishing the thief, and it will pay for the privilege. The 10% figure stuck because it was large enough to tempt and small enough to defend to a burned community. Nearly every recovery offer since has orbited that number.

The textbook round trip: Euler’s $240 million

If Nomad set the price, Euler Finance set the template for a negotiated return. On March 13, 2023, an attacker used a flaw in the lending protocol’s liquidation logic to drain roughly $197 million in a matter of minutes. Euler is exactly the kind of borrowing-and-lending market whose mechanics our explainer on how DeFi interest rates work unpacks, and the exploit turned its own liquidation machinery into a weapon. What followed, chronicled in Euler’s own after-action account, became the reference case for how these things can end well.

Euler opened with pressure, posting a $1 million reward for information leading to the attacker’s arrest and warning that the offer would escalate if 90% of the funds were not returned quickly. Then it pivoted to a doorway. Over the next three weeks the two sides exchanged on-chain messages, and the tone changed. “No intention of keeping what is not ours,” the attacker wrote in one reply. In a later message the thief turned openly contrite, describing the damage done to other people’s money and jobs and lives and apologizing for it. By early April, about twenty-one days after the theft, essentially all of the money was back, and because Ether had appreciated during the standoff, the recovered total came to roughly $240 million, more than was taken. It remains the largest voluntary return in crypto history and the proof that patience plus a credible off-ramp can beat a manhunt.

The refusal: Poly Network’s Mr White Hat

Not every return is bought. The strangest and most instructive case predates the 10% norm entirely. In August 2021 an attacker exploited Poly Network, a cross-chain protocol, for more than $610 million, at the time the largest crypto theft ever. The team offered a $500,000 bounty and, remarkably, a job as chief security advisor. The hacker, whom Poly Network took to calling Mr White Hat, returned nearly everything, including handing over a final private key, and refused the bounty, claiming the whole exercise had been to expose the vulnerability rather than to profit.

Poly Network is the reminder that money is not the only lever. Reputation, fear of prosecution, the sheer difficulty of laundering a sum that large, and in some cases a genuine desire to prove a point all bear on whether stolen funds come home. A recovery bounty is the formalized, repeatable version of the same appeal, engineered so that a protocol does not have to hope its attacker turns out to be a principled eccentric. It buys the outcome Poly Network got lucky enough to receive for free.

2026: the year recovery bounties went routine

What separates 2026 from the Nomad and Euler era is frequency. Recovery offers are no longer once-a-year set pieces; they are a near-reflex response to mid-sized exploits, and they increasingly work. In May, the Arbitrum-based dark pool Renegade was drained of about $209,000 through a faulty function, offered a 10% bounty, and had more than 90% of the money back within forty-five minutes, per crypto.news. Speed like that is only possible because both sides now understand the script.

The bigger cases followed the same pattern with higher stakes. In July, the Arbitrum-based trading platform AFX lost about $24.15 million in USDC after its bridge keys were compromised, and offered the attacker a keep-30% deal to return the remaining 70%, as CoinDesk reported. Also in 2026, the privacy protocol Foom Cash was drained of $2.26 million after a misconfigured cryptographic verifier let an attacker submit forged proofs; a white hat working with the security firm Decurity front-ran the exploiter and clawed back $1.84 million, about 81%, across Base and Ethereum. Foom Cash then paid the white hat a $320,000 bounty and Decurity a $100,000 fee, according to Cointelegraph. Note the twist there: the recovery was performed not by the thief but by a defender racing the thief, a variant that is becoming its own discipline.

CaseWhenFunds at riskBounty framingOutcome
Poly NetworkAug 2021$610M+$500K plus job offerNearly all returned; bounty refused
Nomad BridgeAug 2022$190.7M10% for returning 90%+Partial; ~$22M back in days
Euler FinanceMar 2023~$197M$1M info reward, then talks~$240M returned over 21 days
BybitFeb 2025$1.5BBounty to tracers, not thief~$2.18M paid to hunters
RenegadeMay 2026~$209K10% offer90%+ back in 45 minutes
Foom Cash2026$2.26MWhite hat plus firm fee$1.84M (81%) recovered
AFXJul 2026~$24.15MKeep 30%, return 70%Negotiation over bridge-key theft
AquiferAug 2026~$2.5M20% offer, Sep 3 deadlinePending as of publication

Read the table and a norm jumps out, along with its exceptions. Ten percent is the gravity well, but smaller protocols with less leverage sometimes offer more (Aquifer’s 20%, AFX’s 30%) because a bigger cut of something beats a full share of nothing once the coins are frozen. The percentage a team can afford to withhold is, in the end, a measure of how confident it is that the thief cannot cash out.

Two species: pay the thief, or pay the hunters

Here is the distinction that reorganizes the entire subject. There are two kinds of recovery bounty, and they are not variations on a theme, they are different instruments for different enemies. The first, everything above, is pay the thief: offer the attacker a cut to hand the money back. The second is pay the hunters: offer a reward to third parties who trace, tag, and help freeze the stolen funds, on the assumption the thief will never cooperate.

The reason the second species exists is written into the biggest theft in history. When Bybit lost about $1.5 billion in Ether in February 2025, investigators quickly attributed the attack to the Lazarus Group, the North Korean state hacking operation. That attribution is not trivia; it is a legal wall. You cannot lawfully pay a bounty to a sanctioned North Korean entity, because the payment itself would be a sanctions violation. So Bybit inverted the model. Rather than offering the thief a cut it could never legally deliver, it stood up a bounty program worth roughly $2.18 million in stablecoins for the outside researchers and analysts who helped trace and freeze the funds, as CCN detailed. The exchange rebuilt its reserves through loans and deposits, not by buying its coins back from Pyongyang.

That is not an edge case. According to Immunefi’s tally of the first half of 2026, crypto lost about $972 million across a record 207 incidents, and roughly two-thirds of the stolen value, about $643 million, went to DPRK-linked groups. Sit with that number. For most of the money stolen from crypto this year, the pay-the-thief model is simply illegal, because the thief is a nation-state you are barred from transacting with. The routine, negotiable, 10%-and-a-deadline recovery bounty works on the opportunist who drained a $2 million AMM. It does nothing for the systemic threat, where the only lawful path is to pay the hunters and hope the exchanges freeze fast enough. As the attack surface shifts toward stolen keys and compromised operators, the kind of failure our look at smart-account wallets examines, that gap between the two species is widening, not closing.

SEAL, Safe Harbor and the million-dollar ceiling

The improvisation of the Nomad years is slowly being replaced by standing infrastructure. The Security Alliance, or SEAL, founded by the Paradigm researcher known as samczsun, runs a 24/7 emergency hotline and, more importantly for this topic, publishes the Whitehat Safe Harbor Agreement, a legal framework protocols can adopt in advance so a rescuer knows the rules before an exploit is underway. Its terms, listed on the Security Alliance site, read like a standardized recovery bounty.

Safe Harbor termProvision
Return windowRescued funds returned within 72 hours
Bounty rate10% of recovered assets
Bounty cap$1 million maximum
When it appliesPre-authorized action during an active exploit
Legal backingSecurity Research Legal Defense Fund covers fees
Adoption33 protocol adopters, $60B+ assets protected

The framework solves a real problem. In a live hack, an honest researcher who spots the drain in progress often faces a choice between doing nothing and counter-exploiting the protocol to move funds somewhere safe, an act that looks identical to theft until it is over. samczsun has been candid that this ambiguity paralyzes defenders: as he told Cointelegraph Magazine, a white hat who could intervene in a live exploit may hold back because the legal liability of doing so is unclear. Safe Harbor pre-authorizes that intervention and promises to cover legal costs, converting a moment of paralysis into a defined procedure.

But look again at the cap. Safe Harbor pays 10% of recovered assets up to $1 million, full stop. For a $2 million exploit that is a healthy $200,000. For a $200 million exploit, a researcher who single-handedly rescues the entire treasury is entitled to $1 million, one half of one percent, and not a dollar more. The instrument is calibrated for the mid-sized incident and quietly under-rewards the catastrophe, which is precisely the situation where you would want the strongest possible incentive for someone to intervene. The million-dollar ceiling is defensible as a way to stop rescues from becoming a payday, but it also means the framework is weakest exactly where the money is largest.

Bounty or extortion?

The politest version of a recovery bounty and the ugliest version of extortion can look identical on-chain: a message, a number, a deadline. The difference is who is holding the gun. When a protocol offers a thief a cut to return stolen funds, the protocol is the one making the offer from a position of loss. When an attacker who has found a bug demands payment under threat of exploiting it, the roles invert, and the security industry has a word for that.

Kraken lived the distinction in 2024. After researchers found a flaw that let them credit fake balances and withdrew nearly $3 million as a demonstration, they refused to return it until Kraken agreed to a payout the exchange considered coercive. “This is not white-hat hacking, it is extortion,” Kraken chief security officer Nick Percoco said at the time, in comments reported by CoinDesk. The line he drew is the one that separates a legitimate recovery bounty from a shakedown: who initiated the terms, whether the amount followed an accepted norm or was demanded under threat, and whether funds were held hostage to force the price up. A recovery bounty is the victim offering a reward; extortion is the attacker naming a ransom. That the two can be indistinguishable in a block explorer is exactly why the practice is legally fraught.

The gray zone: what US law actually says

No single US agency owns the recovery-bounty question, which is part of why it stays murky. The Securities and Exchange Commission is the loudest crypto enforcer and polices securities fraud, but whether you can lawfully pay a hacker is not really an SEC matter. It is a Department of Justice question under the Computer Fraud and Abuse Act, which criminalizes unauthorized access regardless of what the intruder does next, and a Treasury question under the sanctions administered by the Office of Foreign Assets Control. Those two bodies, not the markets regulator, set the real boundaries of what a protocol may do after a hack, a jurisdictional tangle that fits the broader theme of our regulatory countdown coverage.

Two hard rules fall out of that. First, exploiting a contract to move funds, even with the intent to give them back, is not automatically legal; it can still be unauthorized access, and a recovery bounty does not grant immunity from prosecution. The much-discussed overturning of the Mango Markets exploiter’s convictions in May 2025 turned on narrow questions of venue and misrepresentation, not on any broad blessing of code-is-law self-help, and courts have not endorsed the idea that draining a protocol is fine so long as you negotiate afterward. Second, and more concretely, paying a bounty to a sanctioned party is itself a violation. If your attacker is on an OFAC list, the pay-the-thief option is off the table no matter how badly you want your users made whole. That single constraint is why Bybit, facing a Lazarus attribution, could only ever pay the hunters. For any US-touching team, the compliance reflex before sending a recovery offer is to ask not merely whether the thief will take the deal, but whether accepting it would be legal to fulfill.

The tax bill on a rescue

Suppose the happy ending: a white hat rescues funds, or a repentant attacker returns them and keeps the agreed cut, and a legitimate bounty is paid. That payout is income, and the tax treatment is unforgiving. In the United States a bug bounty, preventive or recovery, is generally ordinary income, typically reported on a 1099-NEC and taxed as self-employment earnings on Schedule C, the same category that trips up so many crypto earners in our walkthrough of crypto income and Schedule C. The recipient owes income tax and self-employment tax on the reward, and owes it in the year the payment is received.

Because these bounties are usually paid in crypto, valuation adds a second trap. The income is measured at the token’s fair market value on the day it lands, and if the recipient holds a volatile governance token that then falls, the tax bill does not fall with it. A researcher who accepts a $320,000 bounty in a token that halves before April can owe tax on the full $320,000 while holding assets worth far less. The receipt, in other words, can hurt almost as much as the hack, which is one more reason the professional end of this market prefers stablecoins.

The moral hazard nobody has solved

Every recovery bounty carries an uncomfortable implication: it pays a criminal for committing a crime, even if only a fraction, and even if the alternative is worse. Critics argue that a reliable 10% return normalizes theft, turning exploits into a high-yield strategy with a socially acceptable exit. If a hacker knows that draining a protocol will, in the likely case, end with the team offering a tenth of the loot and no serious pursuit, the expected value of attacking goes up, not down.

Defenders counter that the math still favors paying. A partial return beats a total loss, users get made whole faster than any lawsuit could manage, and the alternative, a full loss plus a multi-year manhunt, helps nobody. There is also a darker adjacency the industry rarely says out loud: when preventive bounties underpay, they push talent toward the other side. A researcher who could collect a $20,000 median for a responsible disclosure, or drain the same bug and negotiate a seven-figure recovery cut, faces an incentive gradient that points the wrong way. The whitehat-to-blackhat pipeline is real, and every recovery bounty that pays out generously is, at the margin, an advertisement for it. This is the unresolved tension at the center of the instrument: it is simultaneously the humane response to a theft and a subsidy for the next one.

After the deadline: what to watch

By the time most readers see this, Aquifer’s 14:00 UTC deadline will have passed, and its outcome will be a small data point in a much larger trend. Three things are worth tracking from here. First, standardization: Safe Harbor adoption is climbing past thirty protocols, and the more teams that pre-agree to terms, the less each recovery has to be improvised under fire, though the million-dollar cap will keep drawing criticism on the largest hacks. Second, the sanctions squeeze: with roughly two-thirds of stolen value flowing to DPRK-linked groups, the pay-the-thief model is legally shut out of most of the actual losses, and the growth area is the pay-the-hunters bounty and the freezing infrastructure that makes it work. Third, the incentive debate, which is not going away; expect more argument over whether a 10% norm is harm reduction or a standing bribe.

The through-line is that crypto has quietly built a second security market on top of the first. The preventive bug bounty tries to make sure the money never leaves. The recovery bounty is the admission that, often enough, it will, and that when it does, the fastest way to get it back is not a subpoena but an offer. In 2026 that offer got a standard price, a legal wrapper, and a place in the playbook. It also inherited every awkward question about paying people who steal, none of which has an answer yet.

Frequently Asked Questions

What is a recovery bounty in crypto?

A recovery bounty is a reward a protocol offers after a hack to get stolen funds returned. It usually takes one of two forms: an offer to the attacker to keep a percentage (commonly 10%) in exchange for sending the rest back, or a reward to third-party researchers who trace and help freeze the funds. It differs from a preventive bug bounty, which pays an ethical researcher who reports a flaw before any money is lost.

Why is 10% the standard recovery bounty?

The 10% convention crystallized after the 2022 Nomad Bridge hack, when the team offered a 10% bounty to anyone returning at least 90% of what they took. The figure is large enough to tempt an attacker who cannot easily launder the funds and small enough for a protocol to justify to burned users. SEAL’s Whitehat Safe Harbor Agreement codified the same 10% rate, though it caps the payout at $1 million regardless of how much is recovered.

Is paying a hacker a recovery bounty legal?

It depends heavily on who the attacker is. Paying a bounty to a sanctioned party, such as North Korea’s Lazarus Group, is itself a sanctions violation under US OFAC rules, so it is not an option even when the team wants the funds back. Even with a non-sanctioned attacker, exploiting a contract remains potentially chargeable under the Computer Fraud and Abuse Act, and a bounty does not grant legal immunity. Frameworks like Safe Harbor try to reduce this risk by pre-authorizing defensive action.

How is a recovery bounty different from extortion?

The two can look identical on-chain, so the difference is about who sets the terms. In a recovery bounty, the victim protocol makes the offer from a position of loss and the amount follows an accepted norm. In extortion, the attacker holds funds hostage and demands payment under threat, as Kraken alleged in 2024 when its security chief called a disputed payout extortion rather than white-hat hacking. Speed, initiative, and whether the amount was demanded or offered are the practical dividing lines.

Do recovery bounties actually work?

Often, for the right kind of attack. Euler Finance recovered roughly $240 million over 21 days in 2023, and 2026 saw fast returns like Renegade getting more than 90% back within 45 minutes and Foom Cash recovering 81% with help from a white hat and a security firm. They work best against opportunistic attackers who cannot cash out. They fail against nation-state groups, who are barred from receiving payment and rarely cooperate, which is why roughly two-thirds of 2026’s stolen value has stayed gone.

By Anneke de Vries, security desk, HOGE Wire.

Share 𝕏 Post Telegram