What is in scope
The bug bounty program covers the Quantaureum protocol end-to-end: consensus (QPOS, GM-QTD threshold signing), the QVM and QASM execution layers, the P2P networking stack, the post-quantum cryptography modules (Dilithium3, Kyber768), and the bridge. Report privately via security@quantaureum.com (inafunguka katika kichupo kipya) - never open a public issue for a vulnerability.
Rewards by severity
Rewards are upper bounds assessed case-by-case, paid in QAU from the capped 25,000 QAU bounty fund. Each reward draws down the fund balance; payouts stop once the fund is exhausted.
Submit a vulnerability report
Frequently asked questions
Issues must be previously undisclosed, reproducible, and not already known to the team.
Rewards are upper bounds, assessed case-by-case.