Bounty Calculator
Calculate rewards for bug bounties and task programs
Bug Bounty Tiers
Total Value Locked in protocol
Bounty Analysis
Configure bounties to see analysis
Bug Severity Definitions
Common Task Bounty Ranges
When to Use Bounty Calculator
Launch Bug Bounty
Launching a DeFi protocol with $50M TVL? Set critical at $100K (0.2% of TVL), high at $25K. Competitive enough to attract researchers, sustainable for treasury.
Task Campaign
Need 10 tutorials, 5 integrations, 3 videos? Plan budget: $3K tutorials, $5K integrations, $2K videos = $10K total. Know exactly what you can afford.
Competitive Analysis
Competitor pays $50K for critical bugs. Are you competitive? Use calculator to benchmark. Underpaying = no submissions. Overpaying = treasury drain.
TVL Growth Adjustment
TVL grew from $10M to $100M? Time to increase bounties. What was $10K critical should be $50K+. Scale rewards with risk exposure.
Quarterly Planning
$50K monthly for bounties. How to split? 60% bug ($30K), 40% tasks ($20K). Covers ~1 high bug or 60 small tasks. Clear allocation.
Payout Verification
Researcher claims critical bug. Is $100K fair? Check calculator against TVL and severity. Document reasoning for governance transparency.
Frequently Asked Questions
Someone found a critical bug - do we have to pay the full bounty?
If it meets your critical criteria (funds at risk, PoC provided, responsibly disclosed), yes. Reputation matters - word spreads fast if you lowball. Exception: if impact is less than claimed, negotiate down with clear reasoning. Use platforms like Immunefi for mediation if disputed.
What if we can't afford the bounty we advertised?
Don't advertise bounties you can't pay. If caught off-guard: 1) Pay in installments (get researcher agreement), 2) Emergency governance vote for funds, 3) Negotiate partial payment + tokens. Never ghost or refuse payment - that's how you get publicly exploited instead of privately disclosed.
How to handle duplicate bug submissions?
First valid submission wins full bounty. Later duplicates get nothing (or small thank-you if detailed). Timestamp everything. If submitted within hours of each other, consider splitting. Clear policy upfront prevents disputes.
Should we cap total bounty payouts?
Yes, for treasury safety. Common: max 5-10% of TVL total exposure. If you have $100M TVL, cap total bug bounty liability at $5-10M. This prevents one researcher bankrupting you with 20 critical bugs. Platforms like Immunefi handle this automatically.
How fast should we pay bounties?
Bug bounties: 7-14 days after verification and fix. Task bounties: 3-7 days after delivery acceptance. Faster = better reputation = more submissions. Set up multisig with pre-approved bounty budget to avoid governance delays for each payout.
What if someone exploits instead of reporting?
That's why you have bug bounties - make reporting more profitable than exploiting. If exploited anyway: 1) Pause protocol, 2) Offer bounty to return funds (white hat negotiation), 3) Pursue legally if possible. Post-mortem publicly to maintain trust. Increase bounties if they weren't competitive enough.
No comments yet. Be the first to share your thoughts!