Note
Moving from audits to bug bounties
A common mistake people make when they transition from audits/competitions to bug bounties is bringing the comforting mental model with them:
rigid scope + the expectation that every valid bug in scope gets paid
That kind of certainty is something audits and competitions often provide. It is not the default in bug bounties.
Bug bounties work much more like a market. Scope matters, but so do usage, impact, exploitability, and whether anyone actually cares. You need to understand what the team values, where, and under what conditions, before you spend 40 hours on it.
Otherwise you end up finding vulnerabilities in contracts no one uses or bugs in paths no one can reach.