Research
Why findings don't get paid.
Articles live on Paragraph and are indexed here at build time. Each one publishes one number, and the repository it comes from.
7 22 3 73.2%
Seven gates to run before you write a single line of PoC
The checklist I would run first, and what it cost me not to.
7 gates to run before the PoC
22 ways your audit report gets rejected (and the greps that catch them first)
Published alongside viability-gate GitHub repo
22 anti-patterns, each with a grep
The payout floor is the only number that matters
Published alongside bounty-economics GitHub repo
3 valid findings that paid $0
I logged 97 rejected bug-bounty submissions. 73% were preventable before I read a line of code.
Published alongside rejection-taxonomy GitHub repo.
73.2% catchable before reading code
Every number above is in a public repository: rejection-taxonomy · viability-gate · bounty-economics