Passer au contenu principal

Open for submissions

Bug Bounty Program 

Earn up to 5,000 QAU per vulnerability from a capped fund of 25,000 QAU by finding protocol, node and cryptographic implementation bugs affecting the Quantaureum network.

Capped fund: 25,000 QAU

Rewards are upper bounds assessed case-by-case, paid in QAU from the capped 25,000 QAU bounty fund. Each reward draws down the fund balance; payouts stop once the fund is exhausted.

What is in scope

The bug bounty program covers the Quantaureum protocol end-to-end: consensus (QPOS, GM-QTD threshold signing), the QVM and QASM execution layers, the P2P networking stack, the post-quantum cryptography modules (Dilithium3, Kyber768), and the bridge. Report privately via security@quantaureum.com (s'ouvre dans un nouvel onglet) - never open a public issue for a vulnerability.

Specification and design bugs

The Quantaureum specifications detail the design rationale for consensus, execution, and the cryptography stack.

Types of bugs

  • Consensus and QPOS finality bugs
  • QVM / QASM execution and JIT compiler bugs
  • P2P networking and protocol handling bugs
  • Post-quantum cryptography implementation bugs

Node and protocol bugs

The Quantaureum node software, its consensus logic, and the QVM execution engine must follow the protocol specification and be secure against network-level attacks.

Bugs that break consensus, allow theft of funds, or compromise validator keys are rewarded at the highest severity.

Types of bugs

  • Consensus, QPOS or GM-QTD logic deviations that could split the network
  • Unexpected crashes, remote code execution or denial of service in the node software
  • Post-quantum signature (Dilithium3) or key encapsulation (Kyber768) implementation flaws

Tooling and SDK bugs

The official SDKs (Go, Rust, C++, Java, Python, TypeScript) and the qauctl tooling are in scope of the bug bounty program. Please include all details necessary to reproduce the vulnerability.

SDK bugs that could lead developers to construct unsafe transactions or mishandle key material are rewarded. Crashes of developer tools without security impact are tracked as normal issues.

Staking and bridge bugs

The validator staking flow (deposits, delegation, withdrawals) and the Merkle bridge specifications and source code are part of the bug bounty program.

Critical dependency bugs

Certain dependencies are crucial for the Quantaureum network to function. Bugs in the cryptographic libraries that could weaken signature or encryption guarantees are rewarded at high severity.

Helpful links

What is out of scope

Only the targets listed under in-scope are part of the Bug Bounty Program. Reports that do NOT qualify:

  • ✕Already publicly disclosed vulnerabilities*
  • ✕Issues in third-party services not maintained by Quantaureum*
  • ✕Vulnerabilities already known to the team
  • ✕Automated scanner reports without demonstrated impact
  • ✕Vulnerabilities in software not in the in-scope list
  • ✕Social engineering or phishing reports
  • ✕Missing rate limiting on public endpoints
  • ✕Denial of service requiring disproportionate resources
  • ✕Best-practice suggestions without a security impact
  • ✕Reports about testnet-only configurations

*These are not included, however, we can sometimes help reach out to affected parties

Reporting rules

The bug bounty program is a discretionary rewards program for the Quantaureum community. It supports our responsible-disclosure policy: vulnerabilities must be reported privately, fixed, and only then disclosed publicly.

  1. 1Report privately to security@quantaureum.com - never open a public GitHub issue for a vulnerability
  2. 2Include steps to reproduce if possible
  3. 3We acknowledge receipt within 48 hours and give an initial assessment within 7 days
  4. 4Please do not disclose the vulnerability publicly until a fix is released

Rewards by severity

Rewards are upper bounds assessed case-by-case, paid in QAU from the capped 25,000 QAU bounty fund. Each reward draws down the fund balance; payouts stop once the fund is exhausted.

Low - up to 200 QAU
  • Low-impact issues
  • Missing security best practices
  • Minor information disclosure
Medium - up to 1,000 QAU
  • Limited-impact vulnerabilities
  • Denial of service
  • Non-sensitive information disclosure
High - up to 2,500 QAU
  • Broad loss of funds
  • Stake or protocol integrity compromise
  • Validator key compromise
Critical - up to 5,000 QAU
  • Consensus compromise
  • Direct theft of funds
  • Remote code execution
  • Network-wide validator key compromise
  • Bridge asset theft

Submit a vulnerability report

Reward: up to 200 QAU
Reward: up to 1,000 QAU

Medium

Reward: up to 1,000 QAU

Severity: Medium

Report a medium-severity bug (s'ouvre dans un nouvel onglet)
Reward: up to 2,500 QAU

High

Reward: up to 2,500 QAU

Severity: High

Report a high-severity bug (s'ouvre dans un nouvel onglet)
Reward: up to 5,000 QAU

Critical

Reward: up to 5,000 QAU

Severity: Critical

Report a critical bug (s'ouvre dans un nouvel onglet)

Frequently asked questions

Rewards are paid in QAU from the capped 25,000 QAU bounty fund (0.125% of the total 20,000,000 QAU supply, drawn from the on-chain Ecosystem Fund). Each reward draws down the balance; payouts stop once the fund is exhausted. The fund is never drawn from user balances.

Acknowledgment: within 48 hours. Initial assessment: within 7 days. Fix or mitigation: depends on severity - Critical: 24h, High: 72h, Medium: 7d, Low: 30d.

We follow responsible disclosure and credit reporters in release notes, unless they prefer to remain anonymous.

Please do not disclose the vulnerability publicly until a fix is released. We coordinate disclosure timelines with reporters.

Issues must be previously undisclosed, reproducible, and not already known to the team.

Rewards are upper bounds, assessed case-by-case.

Email security@quantaureum.com with a description of the vulnerability and steps to reproduce. Do not open a public issue.