BUG BOUNTY
Every layer of Nockchain is in scope. AI Proof-of-Work is now live on mainnet - find a critical flaw, and get paid in NOCK.
The Nockchain Bug Bounty covers the entire protocol surface: consensus, mining and reward attribution, the peer-to-peer network, and the node implementation. If a finding affects how the chain agrees, mines, or moves data, it is eligible - whichever part of the stack it lives in.
The current focus is AI Proof-of-Work, now live on mainnet: a new mining protocol that commits to the model an inference is running on, letting inference providers merge-mine their existing workloads against Nockchain. It is securing real value today, and we want it stress-tested by the people best equipped to break it.
If you find a way to take funds, mint them, or cheat the proof-of-work at low cost, we will pay you for it. Awards are denominated in NOCK and sized in blocks - the same unit the network pays miners - with the largest awards reserved for critical findings.
Rewards
Critical
Exploits that take, destroy, or create funds outside the rules of the protocol, or that let a miner cheat the proof-of-work at scale. The cap is reserved for unbounded theft or issuance and for arbitrary proof forgery demonstrated end to end.
- Theft, unauthorized movement, or destruction of funds
- Unbacked issuance - NOCK or wrapped NOCK minted outside consensus rules
- Extreme proof-of-work bypass: valid blocks at a tenth of the honest cost or less, or credit for work not performed, without majority hashrate or extreme luck
- Arbitrary proof forgery accepted on the production verification path
Invalid Proof Accepted
Production verification accepts an invalid block, proof, or proof-of-work statement. You have a working PoC, but the advantage it gives an attacker is not yet quantified.
Becomes Critical once the advantage is quantified - by you or by our review.
Funds Stuck or Destroyed
A protocol or bridge bug leaves funds permanently stranded, burns them without a matching mint, or drops a withdrawal - with no attacker taking them.
Treated as loss of funds even though nobody profits.
Other Confirmed Bugs
Real, reproducible defects that do not reach the classes above: remote denial of service, memory safety, eclipse and partition attacks, consensus divergence without fund impact, or proof-system flaws with negligible practical advantage.
Discretionary. A genuine finding is never turned away empty-handed.
Awards are sized in blocks. One block equals the current block reward of 1,638.4 NOCK, so awards track what the network itself pays for work. Within a band, the amount reflects validated impact, exploitability, reproducibility, report quality, novelty, and duplicate order. Eligibility and the final amount are determined during review by the Nockchain Community Co.
How to Submit
Every report follows the same predefined structure: a written issue description and a working proof of concept we can run to reproduce the finding. Reports that cannot be reproduced are not eligible for a reward.
Submit your finding privately through a GitHub security advisory on the Nockchain repository - never through public GitHub issues or social channels. You will hear back from us once the report has been triaged.
Submit a Finding# Summary One paragraph on what the vulnerability is and why it matters. ## Affected Component Consensus / mining / networking - with the commit hash and version you tested against. ## Impact What an attacker gains, who is affected, and your severity estimate. For proof-of-work claims: the quantified advantage. ## Proof of Concept Step-by-step reproduction on the production path: environment, configuration, scripts or commands, and expected vs. actual behavior. ## Supporting Material Logs, traces, or a suggested patch. (optional)
Review & Payout
Every submission is reviewed and classified by the Nockchain Community Co., which triages reports, confirms reproduction, assigns the final severity, and issues awards in NOCK.
Eligibility
- A working proof of concept on the production path is mandatory. Speculative reports without one are not eligible.
- Proof-of-work claims must quantify the advantage: the cost reduction per valid block, or the work credited without being performed. Unquantified claims are assessed under Invalid Proof Accepted.
- The first reproducible report of a root cause receives the award. A later report that materially narrows or extends it receives a credit share of up to 25%. One root cause never earns a second Critical award.
- Plausible but undemonstrated findings are held, not rejected. The reporter keeps first-reporter priority for 30 days to complete a production-path proof of concept.
- Findings already fixed on master remain eligible if the fix was unreleased or undisclosed when reported, scaled by the exposure window.
- One finding per report. Bundled claims are split, and one valid defect does not validate the others.
Conduct
- Never exploit a vulnerability on mainnet. Reproduce findings on a local or private network, and never target infrastructure you do not own.
- Keep findings confidential until a fix has been released and publicly announced.
- Act in good faith: no data destruction, no extortion, no social engineering.
Out of Scope
- Attacks requiring a majority of the network hashrate, or equivalent luck sustained over enough blocks to execute
- Vulnerabilities in third-party dependencies - please report these upstream
- Previously known issues and findings from published audits
- Social engineering, phishing, or attacks on infrastructure not operated by the protocol
- Automated scanner output without a developed, reproducible exploit
The Nockchain Community Co. reserves all rights to determine, at its sole and final discretion, whether a submission warrants a payout and the size of the award. Awards are drawn from a fixed program pool and do not constitute an entitlement to any share of it. Successful completion of identity verification (KYC) is required before any award is paid.