sparrowwallet / sparrow

Desktop Bitcoin Wallet focused on security and privacy. Free and open source.
https://sparrowwallet.com/
Apache License 2.0
1.22k stars 174 forks source link

Bug bounty program #332

Open jooray opened 2 years ago

jooray commented 2 years ago

I am recommending Sparrow Wallet for a customer and one of the criteria they are considering is an active bug bounty program. I know Sparrow is free and open-source, so maybe a crowdfunding campaign for some BTC?

I co-founded a bug bounty platform as well (Hacktrophy.com), we have worked with Bitcoin projects in the past. Of course there can be any other bug bounty provider or even a self-hosted bug bounty. Let's get people who rely on Sparrow's security put money where they mouth is and allow them to contribute to the bug bounty program. And let's attract ethical hackers to find security bugs.

BTCPayServer has a nice crowdfunding module and it could be used for funding the project development (people contributing to specific features for example).

tzatko commented 2 years ago

+1

elkimek commented 2 years ago

+1

craigraw commented 2 years ago

I like this idea, but I'm concerned about the implementation - specifically, I'm not sure that a crowdfunding campaign would create a meaningful bounty. Setting it up and managing it are also considerations. That said, something to consider in future.