What is a bug disclosure policy?
- Author
- CRYPTO PORT Editorial
- Published
- Updated
- Reading time
- 4 min
In short
A disclosure policy sets out when a discovered bug is reported, to whom, and when it is made public. On a blockchain where funds move directly, publishing too early invites attacks and publishing too late leaves users defenceless. Whether a policy exists, and how the project has handled fixes and announcements in the past, says a lot about its operational maturity.
Key points
- Defines the reporting channel and the timing of publication
- Publishing before fixes propagate invites attacks
- Usually paired with a bounty programme
- Past post-incident reports show how mature the process is
Definition
A published policy describing how someone who finds a vulnerability reports it, and how the fix and public announcement proceed, often including protections and rewards for the reporter.
Because blockchain software is public, details of a vulnerability are effectively an attack recipe. Most projects therefore define a sequence: take the report through a private channel, prepare a fix, wait until node operators have largely upgraded, and only then publish.
From a reporter's perspective, a policy is also an assurance that reporting will not be treated as intrusion. Without one, a good-faith finder risks being treated as an attacker, and the predictable result is vulnerabilities that go unreported or are sold elsewhere.
What a user can check is whether a reporting channel is published, whether the scope and size of any bounty is stated, and whether post-incident write-ups followed past events. A report explaining what happened, how it was fixed and how far the impact reached is concrete evidence of operational quality.
Watch out for
- · Posting vulnerability details publicly first can trigger the attack
- · Messages claiming to have found a bug and asking for keys or a connection are fraud
- · Check whether important areas are carved out of the bounty scope