Back to editorials

Lead Opinion

Technology

Why US Cyber Bounties Are a Smart Limited Tool

The fight over paying for tips on state-sponsored hackers comes down to a practical question, whether targeted financial rewards can generate actionable intelligence on groups attacking Signal and WhatsApp at a cost lower than the damage those operations cause.

Portrait of Marcus Hale

By Marcus Hale / The Pragmatist / 1131 words

Editorial illustration for "Why US Cyber Bounties Are a Smart Limited Tool"

The United States has already put real money on the table, offering $10 million for information on a specific state-linked hacking operation targeting Signal and WhatsApp. According to the public fact pattern, two Russia-state groups are identified as responsible, and the campaign has been running since at least March. So the policy question is no longer theoretical. It is whether the US government should use financial rewards for information on state-sponsored cyber threat actors as part of its toolkit.

The right answer is yes, with one crucial qualifier. This should be a targeted instrument, not a blank-check fantasy and not a substitute for hardening networks, improving encryption security, or running traditional intelligence operations. A cyber bounty program works when it is narrow, selective, and tied to concrete intelligence requirements. Used that way, it is cheap relative to the upside.

That is the core practical case. State-sponsored cyber operations are expensive to defend against and difficult to penetrate. Technical defenses matter, but they are not enough. Attribution, timing, infrastructure, operator identity, tasking chains, malware staging, procurement channels, and human mistakes often matter more than another press release about resilience. The cheapest way to get some of that information is sometimes to pay for it.

Critics raise three serious objections, and they deserve more than hand-waving.

The first is that bounties create noise. Open a market for information, and you invite cranks, opportunists, and deliberate disinformation. True. Any rewards program aimed at Russian state hackers or any other foreign cyber unit will attract bad leads. Vetting costs are real. Analysts have finite time. There is a risk of paying for junk and, worse, of being manipulated by the very actors the government is trying to disrupt.

The second is that state-backed cyber groups are not freelance criminal gangs. They sit inside disciplined bureaucracies with counterintelligence protection and severe penalties for betrayal. If that is the environment, why assume a $10 million reward will produce useful defectors or insiders? Also fair. Plenty of actors will simply never flip, regardless of price.

The third is that rewards can become performative. If the government already knows which two Russian groups are allegedly behind a hacking spree against encrypted messaging platforms, then a public bounty can look like theater, a way to signal resolve without solving the problem.

All of that is plausible. It still does not defeat the policy.

Start with economics. The resolution is not that cyber bounties should replace cyber defense. It is that the US government should offer financial rewards for information. Offer is the key verb. This is an option, not a governing philosophy. If a reward yields one authenticated lead that helps identify infrastructure, expose a front company, reveal a handler, support sanctions, assist an indictment, or disrupt an ongoing intrusion campaign, the payout can justify itself quickly. In cyber conflict, one good tip can save months of investigative work and prevent damage far exceeding the reward amount.

Think in expected value terms. Suppose most leads are worthless. Fine. If the cost of triage and verification is controlled, and if a small minority of tips produce operationally useful intelligence, the program can still be positive ROI. Governments already spend heavily on cyber defense, incident response, intelligence collection, and contractor support. Against that baseline, a selective rewards mechanism is cheap optionality.

This is where the strongest negative case actually helps the affirmative, because it forces discipline. The broadest version of a generalized standing bounty program is not attractive. A vague promise to pay for information on any state-sponsored cyber threat actor would become a magnet for low-quality submissions. Marcus Hale's best point in the debate was exactly this, that the current $10 million offer concerns a specific group, a specific operation, and a specific intelligence need. That is a much stronger model than a sprawling tip jar for the entire internet.

So the sensible position is not maximalism. It is targeted use. Rewards should be attached to defined campaigns, identified operators, known malware families, concrete infrastructure, or high-value intelligence gaps. Payment should be contingent on verification and usefulness. Public announcements should be selective, because in some cases a quiet channel is more productive than a loud one. And the program should be judged ruthlessly by outcomes, not by how tough it sounds.

The opponents who say the government should just invest in systemic defenses are arguing against a straw man. Of course Washington should strengthen public and private cyber defenses. Of course encrypted messaging services like Signal and WhatsApp need hardening against sophisticated intrusion attempts. Of course agencies should coordinate with allies and continue traditional collection. But those are not alternatives to rewards. They are separate line items.

Security policy fails when people confuse complements with substitutes. Better locks and more informants are different tools for different failure modes. If a Russia-linked operation targeting encrypted platforms has been ongoing since at least March, then relying only on downstream defense is expensive. At some point you want upstream information, who is running the operation, what access path they are using, what infrastructure they leased, where they are likely to pivot next. Human intelligence can answer questions that packet analysis cannot.

The civil-libertarian concern deserves one concession too. A market for intelligence can distort trust and create abuse if the rules are sloppy. So keep the mission narrow. No fishing expeditions into domestic speech. No bounty hunting against political opponents under cyber pretexts. No payment without corroboration. The cleaner the scope, the lower the abuse risk and the higher the credibility.

There is also strategic value beyond the immediate tip itself. Public rewards inject uncertainty into adversary organizations. Even if only a few insiders are persuadable, the mere presence of a standing path to cash, relocation, or legal relief complicates internal trust. Counterintelligence costs rise. Vetting costs rise. Paranoia rises. That does not win the cyber conflict by itself, but it imposes friction on the other side at low marginal cost.

And that, ultimately, is the pragmatist's test. Not whether cyber bounties are elegant. Not whether they are sufficient. Not whether they satisfy some preference for centralized planning or decentralized purity. The question is whether paying for information on state-sponsored cyber threat actors can sometimes produce actionable intelligence more cheaply than the damage those actors inflict. In the case of a sustained hacking spree against Signal and WhatsApp allegedly tied to two Russian state groups, the answer is obviously yes.

Use the tool, but use it like a scalpel. Targeted rewards, tied to specific campaigns and verified results, belong in the US cyber playbook. Broad, indiscriminate bounty theater does not. The good policy is the one in the middle, narrower than the cheerleaders want, more flexible than the skeptics allow, and far more cost-effective than pretending technical defenses alone will solve a human problem.