Bug Bounty Program
This programme is not open yet
The Vexidus bug bounty has not launched. There is no active programme, no reward values have been set, and nothing on this page is an offer of payment. We are not currently soliciting submissions.
Everything below describes the intended shape of the programme when it does launch, published for transparency. It is not a commitment. If you have already sent us a report, it has been logged and will be looked at — but we cannot promise a reward, a timeline, or a reply.
We still want to know about genuine security problems in the Vexidus network, and we would rather hear about them privately than read about them anywhere else. Please treat the disclosure guidance below as live even though the rewards are not.
Scope
In Scope
- Vexidus node binary (consensus, P2P, state machine)
- RPC server (vex_* and eth_* endpoints)
- VexScan explorer (vexscan.io)
- VexForge Studio (vexforge.xyz)
- VexSpark Wallet (wallet.vexspark.com)
- SDK and CLI tools
- VSC token standards (VSC-7, VSC-21, VSC-55)
- Staking, VexBridge, and IntentVM logic
Out of Scope
- Third-party services (Discord, Telegram, hosting providers)
- Social engineering or phishing attacks
- Denial of service via brute-force traffic volume
- Issues already reported or publicly known
- Bugs in testnet-only bypass code (documented in codebase)
- Cosmetic UI issues with no security impact
Severity Tiers
Intended classification only. No amounts are attached to these tiers today.
Critical
Not set — programme not open- Consensus bypass — forge valid blocks without stake
- Double-spend or state corruption across validators
- Private key extraction from public data
- Remote code execution on validator nodes
High
Not set — programme not open- Unauthorized fund transfers or balance manipulation
- Denial of service causing network halt
- Signature verification bypass
- P2P protocol attacks causing chain splits
Medium
Not set — programme not open- RPC endpoint vulnerabilities (injection, auth bypass)
- Mempool flooding or transaction censoring
- Explorer data manipulation or XSS
- Token standard logic errors causing incorrect balances
Low
Not set — programme not open- Information disclosure (non-sensitive)
- UI/UX bugs affecting data accuracy
- Documentation errors causing misconfigurations
- Rate limiting bypass on public endpoints
Reward values will be published here if and when the programme opens. Until then no amount is owed or implied for any finding, including findings made before launch.
Rules
- Responsible disclosure: Report to us first. Do not publicly disclose until we confirm a fix is deployed.
- No disruption: Do not degrade the testnet experience for other users. Test on a local node when possible.
- One report per issue: Duplicate reports receive credit only for the first submission.
- Proof required: Include steps to reproduce, affected code paths, and potential impact.
- Good faith: Act in good faith and avoid accessing other users' data or funds beyond what is necessary to demonstrate the vulnerability.
How to Report
Email: security@vexidus.com
Discord: #bug-bounty channel
Because the programme is not open, we cannot commit to an acknowledgement time, an assessment, a reply, or any reward. Reports are logged and triaged, and genuine chain security issues do get fixed — but please send one only if you would still send it knowing it is unpaid and may go unanswered.
See our Terms of Service for additional legal information.