Rhino.fi reduced critical bug bounty rewards by 80%, cutting minimum payout from $100K to $20K across three tiers.
Tech & Launches ·
Rhino.fi reduced its critical bug bounty reward floor from $100,000 to $20,000, representing an 80% decrease across three severity tiers totaling $98,000 in cuts. The stablecoin liquidity platform, which operates a solver and pre-funded network across 35+ chains, now sets its minimum payout for critical smart contract vulnerabilities at the lower tier. The updated bounty structure maintains a 10% calculation of affected funds up to a $2 million maximum but adjusts the threshold that incentivizes researchers to report issues rather than withhold them.
The revision reflects a broader pattern of projects recalibrating security incentives as market conditions or risk assessments evolve. Critical bug reports continue to require proof-of-concept submissions, and Rhino.fi's internal team retains discretion in determining final payouts for high and medium severity findings based on exploitability and likelihood factors. Payouts remain denominated in USD and distributed in USDT or USDC at the team's discretion, with no KYC requirement for recipients.
The rationale behind the reduction—whether driven by lower total value at risk, competing budget priorities, or changing threat models—has not been publicly disclosed. Researchers should note that the lower minimum may still apply to the same classes of vulnerabilities, potentially affecting the perceived value proposition of participating in the program.