Merchants of vulnerabilities: How bug bounty programs benefit software vendors
成果类型:
Article; Early Access
署名作者:
Gal-Or, Esther; Hydari, Muhammad Zia; Telang, Rahul
署名单位:
Pennsylvania Commonwealth System of Higher Education (PCSHE); University of Pittsburgh
刊物名称:
PRODUCTION AND OPERATIONS MANAGEMENT
ISSN/ISSBN:
1059-1478
DOI:
10.1177/10591478261448668
发表日期:
2026
关键词:
PATCH RELEASE
security
IMPACT
POLICY
摘要:
We study how bug bounty programs (BBPs) shape software vendors' security and release choices. Vendors invest in internal assurance before release to reduce residual vulnerabilities, and after launch they must manage vulnerability discovery, disclosure, and remediation. We develop a game-theoretic model in which a vendor chooses release timing and severity-contingent bounties, anticipating effort by ethical and malicious hackers in a winner-take-all discovery race. The model highlights two linked mechanisms: an incentive channel that shifts first discovery of severe vulnerabilities away from malicious exploitation and toward ethical reporting, and a governance channel in which coordinated disclosure changes how vulnerability information is managed while remediation is underway. We derive closed-form optimal bounties and characterize a feasibility region that sustains positive bounties and interior success probabilities. Within this region, a BBP strictly increases the vendor's expected profit by reallocating first-discovery probability on severe vulnerabilities from malicious to ethical hackers and by converting part of severe-loss exposure into bounded, pay-for-results expenditures. For private programs, we also solve for the optimal invited set of ethical hackers and show that this optimal set is strictly smaller than the expected number of malicious attackers. Higher bounties raise ethical hackers' effort and first-discovery probabilities but also increase program cost, and they interact with reputational (non-monetary) incentives. Finally, in the baseline model, BBP adoption conditionally reduces the marginal value of additional pre-release delay and therefore conditionally implies earlier release relative to the no-BBP benchmark. This timing result is a within-model conditional implication; its practical relevance depends on operational readiness, triage throughput, and the vendor's ability to validate and safely deploy fixes once a valid report arrives. Managerially, BBPs should be viewed as a post-release governance layer that complements strong internal assurance rather than as a substitute for it. Policymakers can support responsible use of BBPs by encouraging timely remediation, transparent post-patch disclosure, and reporting standards that reduce information asymmetry and triage frictions.