h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

Bug Bounty Payouts in 2026: The Sticker Price and the Receipt

Crypto's largest bug bounty advertises $16 million, but the median critical payout is $20,000. Here is how whitehat rewards are really priced, and why the sticker rarely matches the receipt.

In April 2025, the yield-bearing stablecoin protocol Usual and the security marketplace Sherlock posted a number the industry had never seen: $16 million for a single critical bug, described at launch as the largest bug bounty prize in tech history. More than a year later, it still sits at the top of the leaderboard. Yet according to Immunefi’s own study of 593 long-running programs, the median reward for a confirmed critical vulnerability is $20,000. Two numbers, roughly three orders of magnitude apart, describe the same market.

That gap is not an accounting quirk. It is the design. A bug bounty ceiling is a sticker price: an advertised offer of what a protocol will pay in the rarest, worst case. The receipt, the amount that actually reaches a researcher’s wallet, is set by an entirely different mechanism: how much money the hunter can prove was at risk, whether they can produce a working proof of concept, and how badly the project wants to protect its reputation. The headline and the payout live in different worlds, and confusing the two is the most common mistake readers make about this corner of crypto security.

The stakes are not abstract. Thieves pulled more than $970 million out of crypto in the first half of 2026, across a record number of incidents. Bounties are the market’s attempt to buy the bug before the criminal does. But the price of a bug turns out to be one of the least standardized figures in the industry, and following that number from the sign on the door to the money in the wallet explains more about how crypto secures itself than any single hack ever could.

How a Bug Bounty Payout Is Actually Priced

Start with the rule that governs almost every serious program: a payout is not a flat fee, it is a function of severity and funds at risk. On Immunefi, the largest platform, a critical smart-contract vulnerability is typically rewarded at up to 10 percent of the funds a researcher can demonstrate are directly exposed, not a fixed sum chosen in advance. A flaw that threatens $100 million pays roughly $10 million. A flaw that threatens $2 million pays roughly $200,000, even when the program advertises a ceiling of $16 million. The ceiling is only reached when a single bug genuinely puts nine figures on the line.

Immunefi calls this the primacy of impact: the reward scales to the damage a researcher can prove, capped at the program maximum. It is why every large number in the industry is prefixed with the words up to. Usual’s record program spells the mechanic out plainly, sizing a critical at 10 percent of at-risk funds to a maximum of $16 million, so a demonstrated $100 million exposure would pay $10 million and the $16 million line is reserved for a genuine catastrophe.

This single design choice explains the whole distribution. Because payouts track provable exposure, most confirmed bugs, which threaten modest sums or get caught before they can be shown to endanger an entire treasury, settle far below the marquee figure. The size of a bounty therefore depends less on the cleverness of the bug than on the size and composability of the money behind it, which is why the same class of flaw is worth more in a deep lending market than in a small one. Readers weighing where the real exposure sits in decentralized finance will find the mechanics familiar from our 2026 risk map for on-chain credit: the funds at risk that set a bounty are the same funds a lending protocol has to defend.

The 2026 Ceiling Leaderboard

The top of the market is a menu, not a ledger. As of early 2026, live programs across the major platforms advertised more than $162 million in available rewards, and the biggest ceilings clustered among the protocols with the most to lose. Usual’s $16 million on Sherlock leads, having surpassed Uniswap v4’s $15.5 million and LayerZero’s $15 million, with a long tail of eight- and seven-figure programs behind them.

Read the list by category and it maps almost perfectly onto where the money sits. Cross-chain bridges and messaging layers like Wormhole and LayerZero, which hold or authorize enormous sums in transit, anchor the top alongside the deepest decentralized-finance protocols. That is the primacy-of-impact rule showing through the leaderboard: a program’s ceiling is roughly the value a single catastrophic bug could reach, so the biggest numbers cluster on the infrastructure with the most concentrated exposure rather than on the flashiest applications.

ProgramAdvertised maximumPlatform
Usual$16,000,000Sherlock
Uniswap v4$15,500,000Immunefi
LayerZero$15,000,000Immunefi
Sky (MakerDAO)$10,000,000Immunefi
Wormhole$10,000,000Immunefi
GMX$5,000,000Immunefi
Coinbase / Base$5,000,000Cantina
Olympus DAO$3,333,333Immunefi
Chainlink$3,000,000Immunefi
Morpho$2,500,000Cantina
Arbitrum$2,000,000Immunefi
Optimism$2,000,042Immunefi
Kamino$1,500,000Immunefi
Largest active crypto bug bounty ceilings in 2026. These are advertised maximums, not amounts paid. Source: Sherlock.

Every figure in that table is an offer, not a receipt. A leaderboard of ceilings tells you which protocols are most afraid of a catastrophic bug and how much treasury they are willing to signal against it. It tells you almost nothing about what researchers actually took home, which is a different table entirely, and a far less flattering one.

What Actually Gets Paid

Turn the leaderboard over and the realized numbers are humbling. Across those 593 long-running programs, the median critical payout is $20,000 and the mean is $114,355, a spread that only makes sense once you see the shape of the distribution: a long tail of small rewards with a handful of monsters at the far end dragging the average up. All-time, Immunefi has paid roughly $107.3 million specifically in critical-severity awards, and only about one in five confirmed reports rates as critical at all.

The flow data tells the same story. In the first half of 2026, Immunefi paid out about $13.45 million across 837 valid bug reports, an average near $16,000 per accepted report and a world away from the $16 million on the sign. The payouts are real and they compound into serious money over time, but the typical one is a five-figure check, not a fortune.

Hold the two worlds side by side: an advertised ceiling measured in tens of millions, a median receipt measured in tens of thousands. The mean sits awkwardly in between because the market is governed by power laws, where the rare Wormhole-scale payout does the statistical heavy lifting and everything else is ordinary work for ordinary money. That is not a flaw in the system; it is what a healthy market for bugs looks like when most bugs are small.

The Arbitrum Lesson: When the Receipt Does Not Match the Sign

The clearest illustration of the gap is not a huge payout but a disputed one. On 19 September 2022, a whitehat known as Riptide reported a flaw in the inbox sequencer of Arbitrum Nitro that could have let an attacker steal every incoming ETH deposit bound for the Ethereum-to-Arbitrum bridge, with an estimated $470 million at risk. Arbitrum’s advertised maximum bounty was $2 million. Riptide was paid 400 ETH, worth roughly $540,000 to $560,000 at the time.

Riptide said so publicly, and the complaint has become a reference point for the whole reward-versus-ceiling debate. “If you post a $2mm bounty, be prepared to pay it when it’s justified,” he wrote. “Otherwise just say the max bounty is 400 ETH and be done with it.” He went further, warning that the market has a memory: “Hackers watch which projects pay out and which do not,” and that underpaying a legitimate rescue could “incentivize a whitehat to go blackhat.”

CaseAdvertised maximumActually paidFunds at risk
Wormhole (satya0x, 2022)$10,000,000$10,000,000Bridge takeover
Aurora (pwning.eth, 2022)$6,000,000$6,000,000Around $330 million
Optimism (saurik, 2022)Over $2,000,000$2,000,042Unlimited mint
Polygon (Wagner, 2021)Program maximum$2,200,000Double-spend
Arbitrum (Riptide, 2022)$2,000,000Around $550,000 (400 ETH)Around $470 million
Advertised ceiling versus the reward actually paid. Sources: Immunefi, The Block, CryptoPotato.

The pattern is uneven on purpose. Sometimes the receipt matches the sign to the dollar, as with Wormhole and Aurora. Sometimes it lands at a fraction, as with Arbitrum. The deciding variable is rarely the raw severity of the bug; it is the negotiation over how much was provably at risk, how the platform graded the report, and whether the project treated the ceiling as a promise or a marketing figure. When those diverge visibly, as Riptide made sure they did, the reputational cost lands on the protocol, not the researcher.

Wormhole: The One Time the Ceiling Nearly Held

The largest bug bounty ever paid remains the exception that proves the rule. On 24 February 2022, a researcher using the handle satya0x disclosed a vulnerability in Wormhole’s contract-upgrade machinery that could have handed an attacker control of the bridge’s core contracts. Immunefi confirmed and paid a $10 million reward, still the biggest single bounty in the industry’s history.

The context matters. Only weeks earlier, on 2 February, a different bug in Wormhole’s signature verification had let a thief mint 120,000 wrapped ETH and drain roughly $323 million, one of the largest exploits of that era, with Jump Crypto stepping in to replenish the funds. The bounty program was scaled up in the aftermath, and satya0x’s find was the program working as designed: a genuine path to seizing the whole bridge, caught and paid before a single user lost money. Immunefi framed the payout as a signal to the field, saying Wormhole was telling “the best, most talented whitehats on the planet that if they responsibly disclose security vulnerabilities to Wormhole, they’ll be well taken care of.”

This is the one scenario where the 10-percent math actually reaches the ceiling, because the bug threatened the entire bridge rather than a slice of it. It also lays bare the brutal economics that justify the whole apparatus: a $10 million reward set against a $323 million loss suffered a few weeks prior is not generosity, it is the cheapest insurance a protocol will ever buy. The number only looks extravagant until you price the alternative.

Unbridled Optimism: The Payout as a Choice

A few weeks after the Wormhole rescue, the security researcher Jay Freeman, better known by the handle saurik, found a flaw in the Optimism Layer 2 that let him effectively print unlimited ETH. He named the writeup Unbridled Optimism and chose to disclose it rather than use it. Optimism paid its $2 million maximum, and Boba Network, which shared the affected code, added its own $100,000 top tier, bringing the total to a now-famous $2,000,042. Freeman noted at the time that the combined reward “might actually set a new record.”

The Optimism case reframes what a payout is buying. On the open market, a working infinite-mint exploit is worth an unbounded sum; against that, $2 million is a rounding error. The bounty was never really the price of the bug. It was the price of a researcher’s honesty and their willingness to shoulder legal risk, weighed against the temptation of a fortune with no receipt. Every large bounty sits on that same knife edge, which is why the headline figure functions less as compensation and more as a thumb on the scale, nudging the person who finds the catastrophe toward the disclosure form instead of the exit.

That calculus is not sentimental, it is economic. A blackhat who drains a bridge has to launder the proceeds through mixers and hostile jurisdictions, accept a steep discount to cash out, and live with the permanent risk of a Federal Bureau of Investigation indictment or an on-chain freeze; the realizable value of a stolen $300 million is a fraction of the headline, and it comes with a lifetime of exposure. A whitehat who reports the same bug takes a clean, taxable seven-figure check and a reputation that compounds into more work. Framed that way, a $2 million bounty does not have to match the black-market price of a bug; it only has to beat the risk-adjusted, laundered, look-over-your-shoulder value of stealing it. Most of the time, for most researchers, it does.

Severity Ladders and the Proof-of-Concept Gate

Between the sign and the receipt sits a grading process, and it is where most of the money is decided. Programs sort findings into severity tiers, commonly Critical, High, Medium and Low, and only the top two reach the headline range. Since roughly one in five confirmed reports is judged critical, the big money is gated twice over: first by whether a bug is severe, then by whether the researcher can prove it.

Proof is the hard gate. You are not paid for a plausible theory; you are paid for a reproducible proof of concept that demonstrates funds at risk. This is the single largest reason realized rewards fall below advertised ceilings. A researcher may be certain a design is unsafe, yet if they can only show $3 million of provable exposure rather than the whole treasury, the 10-percent rule prices the finding at a few hundred thousand dollars, not the marquee figure. Severity can also be argued down after the fact: a report initially logged as critical, then reclassified as high, can lose an order of magnitude of value in a single email, which is exactly the downgrade dynamic that fuels the underpayment complaints researchers like Riptide have aired publicly.

The attack surface that this ladder has to cover keeps growing, too. As wallets themselves become programmable, the taxonomy of what counts as a critical bug expands with them; our explainer on smart-account wallets and account abstraction lays out why features like session keys and batched transactions create severity classes that did not exist when the first bounty ladders were written. Grading a bug is not a clerical task; it is the moment the payout is really set.

Ceilings That Almost Never Pay: The Usual Case

If a payout tracks provable risk, why post $16 million at all? Because a ceiling is also a confidence signal, and Usual’s program is the purest example. By the time the bounty went live, the codebase had already passed 20 audits, including a Sherlock audit contest with a $209,000 prize pool that turned up no valid medium-severity finding or higher. The $16 million is priced against code that specialists have repeatedly failed to break.

That inverts how the number reads. A ceiling set atop heavily audited code carries a low expected cost to the protocol and a high signaling value to depositors: it says the team is so confident the code holds that it will pay a fortune to anyone who proves otherwise. Sherlock structures the promise with insurance-style coverage behind it, so the eye-watering figure is partly underwritten rather than simply pledged. It is a flex dressed as a liability.

Sherlock’s co-founder and chief executive, Jack Sanford, has argued that this is precisely the role a bounty should play alongside a fixed audit. “Point-in-time audits are indispensable,” he said, “but they were never meant to carry the entire burden of security.” A one-off audit is a snapshot; a standing bounty is the always-on layer that keeps paying attention after the auditors have moved on. Read that way, a giant ceiling on already-audited code is not a contradiction. It is the point.

Contests Versus Continuous Bounties: Two Ways to Price the Same Bug

The same protocol will often price the same bug in two different ways, and the choice reshapes the receipt. Uniswap v4 is the clean example. Before launch, it ran a competitive audit competition with a prize pool of roughly $2.35 million, split among hundreds of researchers by the severity of what they surfaced. After launch, it carries a $15.5 million continuous bounty that pays a single hunter who finds a live critical. Same code, two entirely different payout logics.

The contest model, run by platforms like Cantina, Spearbit and Sherlock, and pioneered by the now-wound-down Code4rena, fixes total spend in advance and distributes it across many participants, so a strong finding might earn a warden a few thousand to a few tens of thousands of dollars. The continuous model concentrates the reward: one live critical, one large check. Neither is strictly better; a contest buys broad pre-launch scrutiny at a capped cost, while a standing bounty buys open-ended vigilance with an uncapped tail risk. But they produce very different receipts for the same class of vulnerability, which is another reason a single advertised number can never describe what a researcher will actually earn.

The two models also select for different researchers. A contest rewards breadth and speed, favoring wardens who can sweep a fresh codebase in a fixed window and file many graded findings before the clock runs out. A continuous bounty rewards patience and obsession, favoring the specialist who returns to the same live protocol for months until a single critical falls out. Neither pool is interchangeable, which is why serious protocols increasingly run both: a competition to harden the code before launch, then a standing bounty to watch it forever. The reward a researcher earns depends not only on the bug they find but on which of those two doors they walked through to find it.

Does the Math Actually Work?

Strip away the headline figures and the case for bounties rests on expected value, not ceilings. Immunefi’s study of 593 programs found that 61.4 percent surfaced a paid critical within a year of going live, rising to 87.2 percent by year three and 93.9 percent by year five. In other words, a long-running program will almost certainly contain a critical bug; the only open question is whether a whitehat or a thief reaches it first.

Weigh that against the cost of losing the race. The same research puts the average successful exploit at about $24.5 million in direct theft, with the median hacked token falling 61 percent within six months and 84 percent never recovering their pre-hack value. Set a median $20,000 bounty, or even a rare $10 million one, against a typical eight-figure loss and a permanent hit to the token, and the reward looks less like a prize and more like the cheapest line item in a security budget.

The catch is that a bounty only pays if the finder chooses to file it, which means the number has to beat both the black-market bid and the temptation to stay silent. This is where the giant ceiling earns its keep even though it rarely pays: it tells the most capable researchers that the upside of honesty is real and large. The effectiveness of a bounty program is not measured by the size of any one check; it is measured by the share of catastrophes that quietly never happen.

When a Payout Becomes a Ransom

There is a version of the payout that starts from the wrong side of the exploit. A researcher who has already moved the funds and then offers to return them for a reward is negotiating from a position no program intended to create. The norm that emerged to handle this is blunt: return the money, keep 10 percent. The Security Alliance’s Safe Harbor framework tries to codify it, setting a reward at a fixed share of rescued funds up to a capped maximum and a short return window, so that a good-faith rescue does not curdle into a hostage situation.

The framework holds until the numbers stop agreeing. In 2024, researchers at the auditor CertiK withdrew about $3 million from Kraken while testing a deposit bug and, the exchange says, would not return it without first negotiating a reward. Kraken’s chief security officer, Nick Percoco, was unequivocal: “This is not white-hat hacking, it is extortion.” The number is the fault line. Pay below the norm and researchers cry underpayment, as Riptide did; demand above it and projects cry extortion, as Kraken did. The acceptable payout is a narrow band, and nothing enforces it but reputation.

The legal backdrop offers little more certainty. In the United States there is no federal statute granting whitehats immunity; the Computer Fraud and Abuse Act still applies to unauthorized access, and while the SEC under chair Paul Atkins has softened its posture on token classification, the Justice Department has kept hacking enforcement a priority. Safe Harbor is a private contract, not a legal shield. The picture differs abroad, where Europe’s MiCA rulebook governs service providers without directly addressing whitehat conduct, and the same cross-border murk shapes where stolen funds ultimately flow, a problem we mapped through the lens of FATF’s Travel Rule and VASP guidance. A payout, in the end, is one of the few tools that works the same in every jurisdiction: pay the finder before someone else outbids you.

What Moves the Number Next

Three forces are already bending the payout curve. The first is that the most expensive bugs are moving off-chain. The largest losses of 2026 have come not from Solidity flaws but from stolen keys, compromised multisigs and the social engineering of privileged accounts, the kind of operational failure that dominates recent incident data. Bounties priced to catch a code bug do nothing about a stolen admin key, which means the industry’s biggest ceilings may increasingly be guarding the wrong door.

The second force is artificial intelligence, which cuts both ways. AI tooling helps researchers surface real bugs faster, but it also floods programs with low-quality, machine-generated reports that raise the cost of finding the signal, squeezing the economics of who actually gets paid. AI agents that hold wallets are also a new kind of privileged key holder, a fresh bug class no ceiling is priced for yet; as autonomous software starts moving money, the questions we raised about how AI agents pay on-chain become security questions as much as payment ones.

The third force is simple inflation of the ceiling itself. In 2022, a $10 million reward set the record; by 2025 the bar had moved to $16 million, and the 10-percent-of-at-risk math guarantees it will keep climbing as treasuries and total value locked grow. Meanwhile the median payout has barely budged. The sticker price and the receipt are drifting further apart, not closer, and that widening gap is the real state of the bug bounty market in 2026: a promise about the worst possible day, printed in large type, sitting above a receipt for an ordinary one. Read both, and never mistake one for the other.

Frequently Asked Questions

What is the largest bug bounty payout in crypto history?

The record single payout is $10 million, paid by the cross-chain bridge Wormhole in February 2022 to a researcher using the handle satya0x, who disclosed a bug that could have handed an attacker control of the bridge’s core contracts. It was facilitated by Immunefi and remains the biggest single bug bounty ever paid.

Why is the advertised bug bounty so much bigger than what usually gets paid?

Advertised figures are up-to ceilings tied to the funds a researcher can prove are at risk, usually up to 10 percent for a critical bug. Most confirmed bugs threaten only part of a protocol’s funds or are caught early, so the median critical payout is around $20,000 even when a program advertises $16 million. The ceiling is reserved for a bug that endangers an entire treasury.

How are crypto bug bounty payouts calculated?

Payouts are set by severity and demonstrated impact. Programs grade a finding as Critical, High, Medium or Low, then size a critical reward at a percentage, commonly up to 10 percent, of the funds the researcher can prove are directly at risk, capped at the program maximum. Crucially, the reward requires a working proof of concept, not just a theory.

What is the biggest active crypto bug bounty in 2026?

The largest standing program is Usual’s $16 million bounty hosted on Sherlock, announced in April 2025 and billed as the largest bug bounty prize in tech history. It sits ahead of Uniswap v4’s $15.5 million and LayerZero’s $15 million programs on Immunefi.

Do crypto whitehats get legal protection, and are payouts taxable?

In the United States there is no federal statute granting bug bounty hunters immunity; the Computer Fraud and Abuse Act still governs unauthorized access, and voluntary frameworks like Safe Harbor are private contracts rather than legal shields. Bounty rewards are treated as taxable income, so a whitehat generally owes tax on the fair market value of whatever they receive.

Anneke de Vries covers security and exploits for HOGE Wire.

Share 𝕏 Post Telegram