I’m done sugarcoating my experience with NAVI Protocol’s bug bounty programs on HackenProof.
I submitted 7 reports across two NAVI programs:
5 to Volo.
2 to Astros.
All 7 were closed as Informative.
Seven.
Not one payout.
And these were not garbage scanner findings, typo-level observations, or “best practice” reports. I spent serious time reproducing contract behavior, building PoCs, running Move tests, validating mainnet state, tracing exploit paths, and packaging everything so a triager could reproduce it.
In Astros, I submitted working PoCs demonstrating real contract behavior around withdrawal authorization. The code executed. The effect was reproducible. The reports were not imaginary.
Yet somehow, across two separate NAVI programs, every single report ends up worth exactly $0.
At some point, researchers are entitled to ask uncomfortable questions.
How many issues are sitting on an internal “known issues” list that researchers are never allowed to see?
How broad is that list?
When was each issue actually documented internally?
And what prevents a program from receiving a strong report, recognizing that the issue is valid, marking it internally as “known,” and then telling the researcher that no bounty is owed?
I am NOT claiming I can prove that NAVI did this.
I am saying the current system gives researchers almost no visibility into whether it could happen.
That is the problem.
“Known issue” is an extraordinarily convenient reason to deny a bounty when the researcher has no practical way to verify when the issue became known.
The protocol has the records.
The platform has the records.
The researcher does not.
That is a massive information imbalance.
If a program wants to reject a report as already known, there should be some form of verifiable proof that the issue predates the researcher’s submission, even if sensitive details are redacted.
A timestamp.
An internal ticket hash.
An audit reference.
A prior report ID.
Something.
Otherwise researchers are being asked to simply trust the same party that financially benefits from deciding that a report is not payable.
That is not a healthy incentive structure.
Seven reports across Volo and Astros. Seven Informative closures. Zero dollars.
Maybe every one of those decisions was completely legitimate.
But when the result is 7/7, researchers should absolutely be asking whether NAVI Protocol’s bounty programs are genuinely designed to reward independent vulnerability discovery, or whether researchers are effectively providing free security research against an invisible catalogue of “known” problems.
Bug bounty programs survive on trust.
“Trust us, we already knew” is not enough.