Bug Bounty
Bug Bounty
A program that pays a reward to anyone who finds a security vulnerability in a system.
In Simple Terms
A bug bounty is a system where companies invite outside people to hunt for security holes in their web services or apps, then pay a reward to whoever reports one. Companies use it as a way to keep their own systems secure. IT companies and all sorts of organizations worldwide rely on it to strengthen their security.
Behind the Name
The term comes from combining "bug" — a flaw or glitch in a program — with "bounty," a reward offered for accomplishing something specific, like the reward in "bounty hunter." Put them together, and you get a program that pays out rewards for hunting down bugs. It's also known more formally as a "Bug Bounty Program."
Take a Closer Look!
A bug bounty is a program that pays a cash reward to anyone who finds and reports a security flaw hiding in a system or app.
Companies set them up to catch dangerous issues early with help from outside technologists — the kind of blind spots an in-house development team alone might miss.
Put simply, it's like a prize race for hunting down holes in a system, digital-world style.
The reward amount scales with how serious the flaw is, and someone who finds a truly critical issue can walk away with a hefty payout.
Because it lets companies fix dangerous holes before malicious attackers can exploit them, it's used worldwide as a security-hardening technique.
Participating researchers investigate safely within the program's rules and report whatever they find straight to the company.
The company then verifies whether the report is genuinely a real risk, and once it's confirmed to be legitimate, pays out the reward.
Since this brings in far more eyes than in-house testing alone could, it plays a real role in building safer services.