Bug Bounty

Find a bug. Earn XE.

Help harden the protocol before genesis. One standing programme, the whole system in scope, open now. We have set aside 2% of the XE supply — for it, and we want two things: novel, serious attacks on the ledger, consensus, leasing and networking, and sustained volume that shows where the network degrades. Report on GitHub and earn up to 50,000 XE per finding, paid in native XE at mainnet launch. Rewards are discretionary and contingent on launch; amounts are provisional until the pool is finalized, and XE carries no guaranteed monetary value.

2%Of Supply Allocated
50,000Top Reward (XE)
5Severity Tiers
GitHubSubmission Channel
GenesisPayout Date
What We Want

This is a standing programme, not an event, and nothing is held back for later. It pays for two kinds of work, judged on the same tiers: findings that break the protocol, and findings that show what sustained volume does to it. Heavy, honest use is part of the job — the network is meant to be hammered.

Track 1 — Security findings
  • Ledger: double spends, balance inflation, unauthorized mint or burn, micro-unit overflow
  • Consensus: conflicting blocks finalized, vote weight forged or misapplied, finality reversed
  • Leasing: escrow taken without service, settlement or force-settle abused, attestations forged, VM access with the wrong key
  • Cryptography and keys: forgery, key recovery, address or identity confusion
  • Nodes: crashes or corruption from crafted input, unsafe defaults, admin surfaces reachable
  • Governance and chat: unsigned state-chain changes, keyset rotation abuse, message spoofing
Track 2 — Volume & resilience
  • Sustained transaction volume that drops blocks, stalls finality or evicts peers
  • Spam and rate-limit abuse that degrades service for other clients
  • Load that exhausts a node's memory, disk or file handles
  • Chat, SSE and API starvation under many concurrent clients
  • Provider and lease churn that breaks settlement or accounting
  • Reproducible measurements: what you sent, at what rate, and what the network did

Volume findings are rewarded by their impact on the same tiers — a finality stall you can reproduce is Severe, a measurable slowdown is Medium. Sustained heavy users are recognised on mainnet alongside the top researchers.

Scope

Everything that ships with the XE node, everything the public testnet runs, and everything on this site. If it is documented here and it can be broken, it is in scope.

In Scope
  • Block lattice and every block type — send, receive, burn, mint, the lease family, multisig
  • Consensus, finality and representative voting
  • XE and XUSD accounting in micro-units, emission and settlement maths
  • Compute leasing end to end: escrow, timekeeper attestation, renewal, cancellation, force-settle, provider VMs and the SSH gateway
  • P2P networking, peer discovery and sync
  • Node lifecycle — config, storage, restart and recovery — and crash resistance against crafted input
  • State chain and multisig governance
  • Signed chat, SSE streams and the account directory
  • Wallet, CLI, web wallet and SDK key handling — keygen, signing, addresses, storage
  • The HTTP API, its rate limits and the test.network proxy
  • The explorer, the web wallet, this website and the docs (including header, XSS and content issues)
  • Third-party dependencies where the weakness is reachable through XE
  • Spam, rate-limit and load abuse — see Track 2
Out of Scope
  • Volumetric DDoS against the hosting layer — nginx, DNS, the website or faucet service — rather than the protocol
  • Social engineering of XE staff or users
  • Physical attacks on hardware
Reward Tiers

Five tiers, one programme. Severity is assigned by the XE core team based on impact, exploitability and report quality. Critical findings earn up to 50,000 XE. Amounts are targeted ceilings — exceptional findings may exceed them — and are provisional until the bounty pool is finalized ahead of mainnet launch.

Critical
50,000XE

Catastrophic protocol breaks. Unauthorized mint, double-spend, escrow theft, key recovery, consensus that finalizes conflicting histories, or lattice compromise.

Severe
25,000XE

Serious breaks short of catastrophe. Signature forgery, validation bypass, node compromise, finality that stalls network-wide under load — exploitable and damaging at scale.

High
10,000XE

Targeted DoS, race conditions, replay attacks, privilege escalation, sustained degradation a single client can cause.

Medium
2,500XE

Validation gaps, accounting mismatches, non-sensitive disclosure, inconsistent API responses, measurable slowdowns under volume.

Minor
650XE

UI bugs, typos, broken explorer views, misleading log messages, documentation errors.

Bug Classes

Illustrative examples per tier across the whole system. If you find something impactful that doesn't fit below, report it anyway.

SeverityClassExamplesReward
CriticalSupply & ledger integrityunauthorized mint · double spend · balance inflation · micro-unit overflow · escrow drained without service50,000 XE
CriticalCryptographic & consensus compromisekey recovery · signature forgery · identity hijack · conflicting blocks both finalized · vote weight forged50,000 XE
SevereValidation bypassmalformed block accepted · send/receive/burn/lease rule bypass · unsigned state-chain change · attestation forged25,000 XE
SevereNode compromise, ledger loss & network stallscrash from crafted input · storage corruption · unrecoverable restart · finality stalled network-wide by load25,000 XE
HighRaces, replays & state transitionsrace condition · replay attack · state inconsistency · TOCTOU · lease renewed or settled out of order10,000 XE
HighKeys, access & privilegekey material exposure · unsafe file permissions · admin endpoint reachable · VM access with the wrong key10,000 XE
HighDegradation one client can causedropped blocks under sustained volume · peer eviction · chat or SSE starvation · node OOM from a single source10,000 XE
MediumValidation, accounting & load edge casesaccounting mismatch · validation gap · API inconsistency · rounding · measurable slowdown under volume2,500 XE
MediumInformation disclosuremetadata leak · verbose error · debug exposure · missing security headers with impact2,500 XE
MinorUI/UX, docs & cosmeticlayout · responsive · a11y · typo · broken link · log noise · self-XSS650 XE
Leaderboard

Ranked by total XE awarded across the programme. Updated when the site is redeployed after reports are triaged.

RankResearcherReportsXE Earned
No reports accepted yet.

File a finding to claim the top spot.

Updated manually when the site is redeployed as reports are accepted and paid.

How to Report

Reports are filed as public issues on github.com/xeprotocol/xe. Critical/Severe findings go privately by email first — we coordinate disclosure and open the public issue once a patch has shipped.

  1. 01
    Reproduce against testnet

    Verify on test.network. Capture tx hashes, block heights, exact reproduction steps. For volume findings, capture the rate you sent, for how long, from how many sources, and what the network did.

  2. 02
    File a GitHub issue

    Open an issue at github.com/xeprotocol/xe/issues/new with a suggested severity tier and the area it lands in. Public by default — for Critical/Severe findings, see step 4 instead.

  3. 03
    Include a clear PoC

    Minimal reproduction script or test case. Impact analysis: who's affected, worst case. For load, the script that generates it.

  4. 04
    Critical/Severe: email first

    Findings that risk funds or the network go privately to security@xe.network— not a public issue. Ask for an encryption key first; we'll reply with one before you send details, then with a tracking ID. A public issue goes up once a patch ships.

  5. 05
    Triage & acceptance

    Core team confirms, assigns severity, and replies on the issue (or by email with a tracking ID for Critical/Severe) — we apply tracking labels ourselves on triage.

  6. 06
    Payout at genesis

    Accepted bounties pay in native XE at mainnet launch, if and when it happens. Provide an XE address (or a designated mainnet address) in your report.

Rules

Ready to break things?

Spin up accounts on testnet, hammer the ledger, the network and the compute market — with clever attacks or with sheer volume — and tell us what falls over.