# kaal:claim:4734750-004

**Claim.** Bug bounty programs fail at their own premise because the hackers they pay to demonstrate exploitability frequently sell or exploit the bugs they find instead of disclosing them.

**Type.** failure  **Support.** argued

**Holds when.**

- community audit and bug bounty programs for smart contracts

**Source quote.**

> Alas, hackers often sell the bug or exploit them when they discover them.

**From.** Wulf A. Kaal, *Code Review DAO* (2024), Community Audits, page 9

**Cite as.** Wulf A. Kaal, Code Review DAO (2024). SSRN: https://ssrn.com/abstract=4734750

**Verify.** sha256 of source PDF `60eadf91c0913468505afc664c8d8d1e1673d6c5326d031ca7060addb8ab2eda` at https://raw.githubusercontent.com/wulfkaal/Academic-Papers/main/papers/pdf/Kaal%20-%202024%20-%20Code%20Review%20DAO.pdf

**Failure mode.** Bounty hunter defection  (family: fraud-and-misconduct)

**Topics.** compliance, ai-and-agents, risk-and-incentives, smart-contracts, consensus-and-security

**Keywords.** bug-bounties, community-audit, incentive-misalignment, smart-contract-security

**Canonical form.** This markdown file is the canonical hashed representation of the claim. Its sha256 is the content hash used for attestation.
