# Bug bounties

`kaal:entity:bug-bounties`

**Status.** derived

This node is assembled mechanically from the 2 claims that carry the concept tag `bug-bounties`. It is a roster of what the corpus says under this term. It is **not** an adjudicated definition: no single statement here has been ruled canonical, and no first-appearance call has been made. Read the claims and judge for yourself.

## Every claim under this term

2 claims across 1 works, 2024 to 2024.

**2024**

- [4734750-004](https://wulfkaal.github.io/claims/4734750-004) [failure/argued] *(failure mode)* -- Bug bounty programs fail at their own premise because the hackers they pay to demonstrate exploitability frequently sell or exploit the bugs they find instead of disclosing them.
  > Alas, hackers often sell the bug or exploit them when they discover them.
  Wulf A. Kaal, Code Review DAO (2024). SSRN: https://ssrn.com/abstract=4734750
- [4734750-005](https://wulfkaal.github.io/claims/4734750-005) [failure/argued] *(failure mode)* -- Bug bounty programs are structurally compromised by their reliance on a trusted intermediary that extracts high commission fees and may hold interests that conflict with the software vendor.
  > they use a trusted intermediary that charges hefty commission fees and may have a conflict of interest with the software vendor
  Wulf A. Kaal, Code Review DAO (2024). SSRN: https://ssrn.com/abstract=4734750

## Verify

Every claim above resolves to a record carrying a verbatim source quote, the sha256 of the source PDF, and a preformatted citation. Nothing here asks to be taken on trust.

    curl -s https://wulfkaal.github.io/entities/bug-bounties.md | sha256sum

**Canonical form.** This markdown file is the canonical hashed representation of this entity node. Its sha256 is the content hash.
