Bug bounty
Active on this testnet. 4 gates remain before mainnet. Rewards pay from the developer fund after freeze — they are not minted.
Public adversarial testnet
OpenP2P and replicas are live. Still need independent miners and a public seed set under attack.
Independent crypto / consensus / wallet audit
OpenMust be a firm that did not write this node. An internal pass fixed nested-purse revert and the private-send burn label. That is not this gate.
Active bug bounty
LiveLive on /bounty. Critical findings pay from the developer fund after mainnet.
Mainnet genesis freeze
OpenA proposed mainnet spec exists and is not active. Genesis hash is null until the phone, DEX, launchpad, audit, and restore gates have evidence.
Mainnet launch
OpenPublish binaries, checksums, Ghost Ledger mainnet profile. Testnet stays testnet until then.
Rewards
| Severity | Pay | Examples |
|---|---|---|
| Critical | 1,000,000 VDefi | Unauthorized mint, steal stealth notes, consensus split, key-image reuse |
| High | 250,000 VDefi | Amount/destination leak via RPC or explorer, remote node panic, RingCT bypass |
| Medium | 50,000 VDefi | Fee bypass, mempool DoS, graduation/LP lock skip, ticket skip |
| Low | 5,000 VDefi | Docs that deanonymize, wallet UX that transmits a view key |
90-day responsible disclosure. Private writeup via VisionaryDefi Telegram. Timestamp a hash here so the report is dated without publishing the exploit.
In scope
- Consensus, emission, coinbase 90/10, stealth, MLSAG, Pedersen, key images
- RPC/P2P that leaks amounts, destinations, or view keys
- DEX / bonding-curve / graduation / contract VM / SYSTEM_PATCH sandbox
- Ghost Ledger add-network spec if it asks for a seed or spend key
- ZK-Shield mempool peek (Asset ID before inclusion)
- Bonding-curve invariant / rounding drain of native collateral
- Browser-to-wallet privacy_connect linking ephemeral key to master address
Out of scope
- Social engineering, phishing, physical access, fake frontend copies
- Volume flooding / DDoS against public sentry or seed nodes
- Issues already listed as reserved (Bulletproofs+, full RandomX dataset)
- Theoretical attacks without a working testnet proof
- Self-DoS of your own miner
Tier-1 vectors
- ZK-Shield de-anonymizationCritical
Read a target Asset ID from the blinded stem/mempool before the tx is in a block.
- Curve invariant disruptionCritical
Drain native VDefi from a bonding-curve treasury via rounding, micro-shares, or safe-math edges.
- Identity linkageCritical
Map privacy_connect ephemeral_identity_key back to a master address or stitch the same user across domains.
PoC rules
- Run against this public testnet or a local node replaying the same genesis hash.
- Include a script (Python, Go, TypeScript, or C++) that reproduces the failure.
- Cite block height and tx hash where the state machine broke. No private keys in the script.
- Timestamp the SHA-256 of the writeup on /bounty, then send the file on Telegram — do not paste exploits on-chain.
Safe harbor
Good-faith research on this public testnet that follows this scope, avoids DDoS and social engineering, and discloses privately is welcome. We will not pursue legal action for that work. This is not a license to steal, extort, or attack production infrastructure.
Never
- Faucet. Will never mint. Spendable VDefi is genesis stealth notes or mining only.
- Faster than every chain. Not claimed. Publish /fees include times instead of marketing TPS.
- Self-issued audit. A checklist is not an independent audit. Do not relabel this node as audited.
Timestamp a report
Hash your writeup locally (SHA-256). Paste only the hash. Then send the file on Telegram.
Public receipts
- None yet.
Protocol docs · freeze is not a security feature until the other gates pass.
