Help harden the protocol before genesis. Report vulnerabilities through GitHub and earn up to 10,000 XE per finding — paid out in native XE at mainnet launch.
Severity assigned by the XE core team based on impact, exploitability, and report quality. Amounts are targeted ceilings — exceptional findings may exceed them.
Catastrophic protocol breaks. Unauthorised mint, double-spend, key recovery, or lattice compromise.
Network-wide degradation, censorship, escrow bypass, signature forgery. Exploitable and damaging at scale.
Targeted DoS, race conditions, replay attacks, privilege escalation in relay services.
Validation gaps, fee mismatch, non-sensitive disclosure, inconsistent API responses.
UI bugs, typos, broken explorer views, misleading log messages, documentation errors.
Illustrative examples per tier. If you find something impactful that doesn't fit below, report it anyway.
Ranked by total XE awarded. Updates as reports are triaged.
Rebuilds nightly from bounty-paid labels on xeprotocol/core.
All reports go through GitHub Issues on xeprotocol/core. Public-by-default for transparency.
Verify on test.network. Capture tx hashes, block heights, exact reproduction steps.
Apply bug-bounty label. Suggest a severity tier.
Minimal reproduction script or test case. Impact analysis: who's affected, worst case.
Critical/Severe issues risking funds — email security@xe.network with PGP-encrypted summary first.
Core team confirms, assigns severity, labels bounty-accepted. After fix: bounty-paid.
All bounties pay in native XE at mainnet launch. Provide a testnet-format address in the issue.
In Scope
Out of Scope
Spin up an account on testnet, hammer the network, and tell us what falls over.