Help harden the protocol before genesis. One standing programme, the whole system in scope, open now. We have set aside 2% of the XE supply — for it, and we want two things: novel, serious attacks on the ledger, consensus, leasing and networking, and sustained volume that shows where the network degrades. Report on GitHub and earn up to 50,000 XE per finding, paid in native XE at mainnet launch. Rewards are discretionary and contingent on launch; amounts are provisional until the pool is finalized, and XE carries no guaranteed monetary value.
This is a standing programme, not an event, and nothing is held back for later. It pays for two kinds of work, judged on the same tiers: findings that break the protocol, and findings that show what sustained volume does to it. Heavy, honest use is part of the job — the network is meant to be hammered.
Everything that ships with the XE node, everything the public testnet runs, and everything on this site. If it is documented here and it can be broken, it is in scope.
Five tiers, one programme. Severity is assigned by the XE core team based on impact, exploitability and report quality. Critical findings earn up to 50,000 XE. Amounts are targeted ceilings — exceptional findings may exceed them — and are provisional until the bounty pool is finalized ahead of mainnet launch.
Catastrophic protocol breaks. Unauthorized mint, double-spend, escrow theft, key recovery, consensus that finalizes conflicting histories, or lattice compromise.
Serious breaks short of catastrophe. Signature forgery, validation bypass, node compromise, finality that stalls network-wide under load — exploitable and damaging at scale.
Targeted DoS, race conditions, replay attacks, privilege escalation, sustained degradation a single client can cause.
Validation gaps, accounting mismatches, non-sensitive disclosure, inconsistent API responses, measurable slowdowns under volume.
UI bugs, typos, broken explorer views, misleading log messages, documentation errors.
Illustrative examples per tier across the whole system. If you find something impactful that doesn't fit below, report it anyway.
Ranked by total XE awarded across the programme. Updated when the site is redeployed after reports are triaged.
File a finding to claim the top spot.
Reports are filed as public issues on github.com/xeprotocol/xe. Critical/Severe findings go privately by email first — we coordinate disclosure and open the public issue once a patch has shipped.
Verify on test.network. Capture tx hashes, block heights, exact reproduction steps. For volume findings, capture the rate you sent, for how long, from how many sources, and what the network did.
Open an issue at github.com/xeprotocol/xe/issues/new with a suggested severity tier and the area it lands in. Public by default — for Critical/Severe findings, see step 4 instead.
Minimal reproduction script or test case. Impact analysis: who's affected, worst case. For load, the script that generates it.
Findings that risk funds or the network go privately to security@xe.network— not a public issue. Ask for an encryption key first; we'll reply with one before you send details, then with a tracking ID. A public issue goes up once a patch ships.
Core team confirms, assigns severity, and replies on the issue (or by email with a tracking ID for Critical/Severe) — we apply tracking labels ourselves on triage.
Accepted bounties pay in native XE at mainnet launch, if and when it happens. Provide an XE address (or a designated mainnet address) in your report.
Spin up accounts on testnet, hammer the ledger, the network and the compute market — with clever attacks or with sheer volume — and tell us what falls over.