Skip to content

Kelly criterion for bug hunting?

A half-formed hunch: allocating research time across targets is a bankroll problem, and Kelly might be the right lens.

planted April 22, 2026 · last tended June 30, 2026

A captured spark. Unverified, unpolished, possibly wrong.


A seed, planted fast before it blew away. Possibly nonsense.

The Kelly criterion sizes bets to maximize long-run growth of a bankroll given your edge and odds. Security research has the same shape: my bankroll is attention, each target is a bet with some probability of a finding and some payout (bounty, knowledge, write-up), and I can size positions by the hours I spend.

Things Kelly would predict, if the analogy holds:

  • Never go all-in on one target, even a juicy one (ruin risk = burnout + zero findings).
  • Edge matters more than payout. A boring target where I have deep prior knowledge beats a glamorous one where I’m a tourist.
  • Fractional Kelly (betting less than the formula says) is wise when your edge estimate is noisy, and my edge estimates are very noisy.

Suspicious wrinkle: research payoffs aren’t independent bets. Knowledge compounds across targets, which Kelly doesn’t model. Maybe that’s the interesting part.

Related muscle memory from web CTFs: rotating hypotheses on a timer is basically fractional Kelly for a single afternoon.

The compounding wrinkle is where this stops being a cute analogy and starts being useful. Kelly assumes each bet is independent and the bankroll only moves in dollars. Research breaks both. A week sunk into a losing target, no bounty, still pays out in edge: a new sink I will recognize next time, a tool sharpened, a clearer mental model of how that vendor thinks. So the real bankroll isn’t hours, it’s compounding skill, and a negative-EV bet on a brutal target can be positive-EV once you price in what it teaches. That is the opposite of gambling ruin. The same move that loses you money makes you harder to beat. quant-is-edge-and-survival is the same idea wearing a suit.

Which means the ruin condition has to be redrawn. In a real bankroll, ruin is zero dollars and it absorbs you: you cannot bet your way back from nothing. In research the absorbing state isn’t an empty wallet, it’s a fried one. Burnout, tilt, the afternoon you keep forcing the same dead hypothesis because you are too sunk to fold. Fractional Kelly protects the wallet; here it protects attention. Bet small enough on any one target that a goose egg doesn’t make you quit the game. That fold-on-tilt instinct is the same systems reflex behind the-attackers-mindset-is-systems-thinking: watch the loop you are in, not just the move in front of you.

Next action: re-read the Kelly chapter of Fortune’s Formula, then log a season for real. Per session: target, hours, prior confidence (a number, set before I start, no cheating), and the outcome in two currencies, bounty and learning. A season of that and my edge estimates stop being a hand-wave and become a distribution I can actually bet against. If the data is fun, this sprouts.

Paths that lead here

Where this note points

More from these beds