VisionaryDefi apps & Ecosystem

Bug bounty

Active on this testnet. 4 gates remain before mainnet. Rewards pay from the developer fund after freeze — they are not minted.

Active

Public adversarial testnet

Open

P2P and replicas are live. Still need independent miners and a public seed set under attack.

Independent crypto / consensus / wallet audit

Open

Must be a firm that did not write this node. An internal pass fixed nested-purse revert and the private-send burn label. That is not this gate.

Active bug bounty

Live

Live on /bounty. Critical findings pay from the developer fund after mainnet.

Mainnet genesis freeze

Open

A proposed mainnet spec exists and is not active. Genesis hash is null until the phone, DEX, launchpad, audit, and restore gates have evidence.

Mainnet launch

Open

Publish binaries, checksums, Ghost Ledger mainnet profile. Testnet stays testnet until then.

Rewards

SeverityPayExamples
Critical1,000,000 VDefiUnauthorized mint, steal stealth notes, consensus split, key-image reuse
High250,000 VDefiAmount/destination leak via RPC or explorer, remote node panic, RingCT bypass
Medium50,000 VDefiFee bypass, mempool DoS, graduation/LP lock skip, ticket skip
Low5,000 VDefiDocs that deanonymize, wallet UX that transmits a view key

90-day responsible disclosure. Private writeup via VisionaryDefi Telegram. Timestamp a hash here so the report is dated without publishing the exploit.

In scope

  • Consensus, emission, coinbase 90/10, stealth, MLSAG, Pedersen, key images
  • RPC/P2P that leaks amounts, destinations, or view keys
  • DEX / bonding-curve / graduation / contract VM / SYSTEM_PATCH sandbox
  • Ghost Ledger add-network spec if it asks for a seed or spend key
  • ZK-Shield mempool peek (Asset ID before inclusion)
  • Bonding-curve invariant / rounding drain of native collateral
  • Browser-to-wallet privacy_connect linking ephemeral key to master address

Out of scope

  • Social engineering, phishing, physical access, fake frontend copies
  • Volume flooding / DDoS against public sentry or seed nodes
  • Issues already listed as reserved (Bulletproofs+, full RandomX dataset)
  • Theoretical attacks without a working testnet proof
  • Self-DoS of your own miner

Tier-1 vectors

  • ZK-Shield de-anonymizationCritical

    Read a target Asset ID from the blinded stem/mempool before the tx is in a block.

  • Curve invariant disruptionCritical

    Drain native VDefi from a bonding-curve treasury via rounding, micro-shares, or safe-math edges.

  • Identity linkageCritical

    Map privacy_connect ephemeral_identity_key back to a master address or stitch the same user across domains.

PoC rules

  • Run against this public testnet or a local node replaying the same genesis hash.
  • Include a script (Python, Go, TypeScript, or C++) that reproduces the failure.
  • Cite block height and tx hash where the state machine broke. No private keys in the script.
  • Timestamp the SHA-256 of the writeup on /bounty, then send the file on Telegram — do not paste exploits on-chain.

Safe harbor

Good-faith research on this public testnet that follows this scope, avoids DDoS and social engineering, and discloses privately is welcome. We will not pursue legal action for that work. This is not a license to steal, extort, or attack production infrastructure.

Never

  • Faucet. Will never mint. Spendable VDefi is genesis stealth notes or mining only.
  • Faster than every chain. Not claimed. Publish /fees include times instead of marketing TPS.
  • Self-issued audit. A checklist is not an independent audit. Do not relabel this node as audited.

Timestamp a report

Hash your writeup locally (SHA-256). Paste only the hash. Then send the file on Telegram.

Public receipts

  • None yet.

Protocol docs · freeze is not a security feature until the other gates pass.