It's also complying with tax and employment laws in the country the hacker is in, to the satisfaction of your legal and finance teams.
Sure, in western-style legal systems you can call them a contractor and they can pay their own tax. Just don't employ them full time for long enough to trigger 'sham contract' rules that would make them employees.
But your corporate legal team doesn't have anyone trained and licensed to give advice on Tajikistan tax and employment law, so they can't approve this proposed contract without hiring an outside legal expert. And of course all suppliers, regardless of country, must agree to our anti-slave-labour policy which permits audits of...
One might say "skip that nonsense, just send the money" - but the larger the company, the more their in-house infosec becomes a load of uptight squares who love compliance and audit. And the kind of companies that can pay out five-figure bounties tend to be pretty large.
Less about that. More about “not accidentally funding terrorism” (or, more realistically, not giving money to sanctioned countries which can have significant consequences).
CISO: "We're going to invite random strangers from all around the globe to hack us, and pay them for their findings"
CEO: "I'm not sure I like the idea of us inviting people to hack us - or paying a 'bounty' to hackers holding a knife to our throat. Will they at least agree to a binding NDA and terms of engagement, in advance?"
CISO: "No, they won't."
CEO: "Well, at least if the hackers are in poor countries, a $500 payout for a critical bug will be plenty, right?"
CISO: "No, critical issues will be 10-100x that"
CEO: "Well will the average quality of these reports better than those we get from our hired pentesters?"
CISO: "On average these will be the lowest quality reports you've ever seen. But 0.1% might be gold. Oh, and I need to hire 3 more guys to sift through these terrible reports. Also our sifters might miss the gold."
CEO: "Oh. Well at least we won't be breaking the law though, right?"
IIRC all cryptocurrency that's money is money (so bitcoin, ethereum, etc but not necessarily project-specific tokens) and if you happen to make or lose money on a currency conversion it doesn't have tax implications.
Italy has progressive taxes on salary, with marginal rates from 23% to 43%. The latter on income above €50k
And if you've got taxes like that on earned income - shouldn't people with unearned income pay just as much? If your tax on investment gains is too small, you end up with an economy where the salaried worker renting a house pays more tax than their landlord, who owns ten houses.
I think America’s tax policy and redistribution scheme have made it the country where private individuals have the most money in the world - and that saying the landlord should pay just as much tax disincentivizes wealth concentration!
I don't know. It used to be 26%, like capital gains from shares, securities, etc. but since 1st January 2026 crypto is taxed at 33% unless it's euro stablecoins (still 26%).
At this point, I think most crypto investors in Italy will just evade taxes altogether.
Buying stable coins is a mild pain because so many banks think crypto is radioactive. Then you have to wait for your deposited funds to completely settle before you can withdraw the crypto from your account and send it elsewhere. Doable, sure. Easy & convenient, not so much. I wouldn't call it a solved problem in the same way you can hand someone cash, tap to pay with your phone, or pay by scanning a QR Code.
Revolut does not have a banking license in the US. At the moment they are a front for another bank. Don't be gullible and believe blindly what the marketing departments tell you.
> You can gamble with it, but it doesn't let you own or send it.
You can deposit (receive) and withdraw (send) cryptocurrencies there.
"Owning" is a matter at the private key level which of course you use a self-hosted wallet for "true" ownership. But no argument was made on ownership.
My point still stands that Revolut is a bank that allows cryptocurrencies.
You got downvoted, but sadly we have 2026 and it's still not easy to send money to any bank in the world. You can say a lot of bad things about the crypto world, but thats a problem Bitcoin solved two decades ago.
That was not my point. Money with bancs also not, if it would be so easy, there would be no problems with nigerian oncles and so on. Good look get your grandmas scammed money back.
In Canada, every bank has Interac e-Transfer, essentially we can easily email or text either other money. It's really wicked, and I'm always amazed other places like America don't have it built into their bank accounts and have to use 3rd-party apps to handle sending money to each other.
But anyway, the point is that it tells you every single time you send a transfer that way to be careful, because you can't undo a transfer after it's been sent. I'm assuming it's the same for most methods of bank transfer? I mean, debit transactions are surely a different beast.
Banks can always try to undo a transaction - it's just not guaranteed to work. AFAIK, credit/debit card reversals are always reversible because if the merchant doesn't have the money, it becomes their bank's problem to get the money or eat the loss. This works because the merchant is easily identifiable, well known, and has a reputation to uphold (at least to their bank). Other methods of transfer don't come with such contractual protection, but can still have best-effort.
They can. Maybe in some jurisdictions they don't have to so they try to avoid it. But if there is crime involved for example, they can be required to do what's inconvenient
The method of “reversal” was sending the money back, because it was a transfer between banks. The actual method of transfer or underlying currency is of no import in such circumstance.
The entire point is that the bank can send the money back and transaction is always between banks. Whereas in cryptocurrency world transaction is direct. Like with cash, except you can accidentally a million dollars