Help harden the protocol before genesis. The programme runs in phases — one area of functionality at a time, open across the foreseeable future of development. Phase 1 — transactions & running a node — is the active scope. Report vulnerabilities on GitHub and earn up to 10,000 XE per finding — paid in native XE at mainnet launch. Rewards are discretionary and contingent on launch; the bounty pool is still being finalized, and XE carries no guaranteed monetary value.
The bounty is a standing programme, not a one-off event: it opens one area of the system at a time and stays open as the protocol is built. Phase 1 is live now. Later phases are listed here by title only — each one's scope, examples and rules go up when that phase opens, and no phase closes the programme.
Phase 1 is the entry point to the system: everything one node and one keypair can do on their own or against themselves. That is the scope of the programme today — set your testing to it.
The same five tiers apply in every phase. Severity assigned by the XE core team based on impact, exploitability, and report quality. Amounts are targeted ceilings — exceptional findings may exceed them — and are provisional until the bounty pool is finalized ahead of mainnet launch.
Catastrophic protocol breaks. Unauthorized mint, double-spend, key recovery, or lattice compromise.
Serious breaks short of catastrophe. Signature forgery, validation bypass, node compromise — exploitable and damaging at scale.
Targeted DoS, race conditions, replay attacks, privilege escalation.
Validation gaps, fee mismatch, non-sensitive disclosure, inconsistent API responses.
UI bugs, typos, broken explorer views, misleading log messages, documentation errors.
Illustrative Phase 1 examples per tier. If you find something impactful inside the Phase 1 scope that doesn't fit below, report it anyway.
Ranked by total XE awarded across every phase. Updated when the site is redeployed after reports are triaged.
File a finding to claim the top spot.
Reports are filed as public issues on github.com/xeprotocol/xe. Critical/Severe findings go privately by email first — we coordinate disclosure and open the public issue once a patch has shipped.
Verify on test.network. Capture tx hashes, block heights, exact reproduction steps.
Open an issue at github.com/xeprotocol/xe/issues/new with a suggested severity tier and the Phase 1 area it lands in. Public by default — for Critical/Severe findings, see step 4 instead.
Minimal reproduction script or test case. Impact analysis: who's affected, worst case.
Findings that risk funds or the network go privately to security@xe.network— not a public issue. Ask for an encryption key first; we'll reply with one before you send details, then with a tracking ID. A public issue goes up once a patch ships.
Core team confirms, assigns severity, and replies on the issue (or by email with a tracking ID for Critical/Severe) — we apply tracking labels ourselves on triage.
Accepted bounties pay in native XE at mainnet launch, if and when it happens. Provide an XE address (or a designated mainnet address) in your report.
Spin up an account on testnet, hammer Phase 1 — transactions and a node of your own — and tell us what falls over.