VexScan
Testnet

Bug Bounty Program

This programme is not open yet

The Vexidus bug bounty has not launched. There is no active programme, no reward values have been set, and nothing on this page is an offer of payment. We are not currently soliciting submissions.

Everything below describes the intended shape of the programme when it does launch, published for transparency. It is not a commitment. If you have already sent us a report, it has been logged and will be looked at — but we cannot promise a reward, a timeline, or a reply.

We still want to know about genuine security problems in the Vexidus network, and we would rather hear about them privately than read about them anywhere else. Please treat the disclosure guidance below as live even though the rewards are not.

Scope

In Scope

  • Vexidus node binary (consensus, P2P, state machine)
  • RPC server (vex_* and eth_* endpoints)
  • VexScan explorer (vexscan.io)
  • VexForge Studio (vexforge.xyz)
  • VexSpark Wallet (wallet.vexspark.com)
  • SDK and CLI tools
  • VSC token standards (VSC-7, VSC-21, VSC-55)
  • Staking, VexBridge, and IntentVM logic

Out of Scope

  • Third-party services (Discord, Telegram, hosting providers)
  • Social engineering or phishing attacks
  • Denial of service via brute-force traffic volume
  • Issues already reported or publicly known
  • Bugs in testnet-only bypass code (documented in codebase)
  • Cosmetic UI issues with no security impact

Severity Tiers

Intended classification only. No amounts are attached to these tiers today.

Critical

Not set — programme not open
  • Consensus bypass — forge valid blocks without stake
  • Double-spend or state corruption across validators
  • Private key extraction from public data
  • Remote code execution on validator nodes

High

Not set — programme not open
  • Unauthorized fund transfers or balance manipulation
  • Denial of service causing network halt
  • Signature verification bypass
  • P2P protocol attacks causing chain splits

Medium

Not set — programme not open
  • RPC endpoint vulnerabilities (injection, auth bypass)
  • Mempool flooding or transaction censoring
  • Explorer data manipulation or XSS
  • Token standard logic errors causing incorrect balances

Low

Not set — programme not open
  • Information disclosure (non-sensitive)
  • UI/UX bugs affecting data accuracy
  • Documentation errors causing misconfigurations
  • Rate limiting bypass on public endpoints

Reward values will be published here if and when the programme opens. Until then no amount is owed or implied for any finding, including findings made before launch.

Rules

  • Responsible disclosure: Report to us first. Do not publicly disclose until we confirm a fix is deployed.
  • No disruption: Do not degrade the testnet experience for other users. Test on a local node when possible.
  • One report per issue: Duplicate reports receive credit only for the first submission.
  • Proof required: Include steps to reproduce, affected code paths, and potential impact.
  • Good faith: Act in good faith and avoid accessing other users' data or funds beyond what is necessary to demonstrate the vulnerability.

How to Report

Email: security@vexidus.com

Discord: #bug-bounty channel

Because the programme is not open, we cannot commit to an acknowledgement time, an assessment, a reply, or any reward. Reports are logged and triaged, and genuine chain security issues do get fixed — but please send one only if you would still send it knowing it is unpaid and may go unanswered.

See our Terms of Service for additional legal information.