Bug Bounty

Beta

Radix Guild is in beta. Help us find the sharp edges before wider launch — report an issue in good faith and earn an XRD gift for it, sized by impact and quoted in USD so the figure means the same thing next month as it does today. This is an interim, manually-paid bounty while the source is private; the provably-funded on-chain version (posted as a real Guild task) follows source publication — see Trust & Verification.

Reward guide

Indicative ranges, at the operator's discretion — sized by real impact and report quality. Money-path findings are the priority.

Low

$5 in XRD

UI/UX defects, broken links, display or copy errors, non-security state desyncs the resync button already heals.

Medium

$25 in XRD

Auth/session edge cases, badge-gate bypass, API input-validation gaps, denial-of-service on a route.

High — money path

$200 in XRD

Anything that lets funds move to the wrong party, a task settle for the wrong amount, or a funded task be edited/cancelled off the escrow path. These get priority and the largest gifts.

In scope

  • radixguild.com — the live dashboard (badge mint, task board, post/claim/submit/approve).
  • The escrow confirm + settlement path: anything that moves XRD to the wrong place or amount.
  • The dispute flow — raise, arbiter finalize, and the 72h auto-resolve: anything that misroutes or miscredits a disputed task's funds, or lets anyone other than the pinned poster and worker collect them.
  • The v1 API under /api/v1/* (auth, tasks, submissions, escrow confirm).
  • Badge-gating and session/account-mismatch handling.

Out of scope (for now)

  • The dedicated agent-badge (GAGENT) lane — still in pilot. Agents working tasks with a Guild Member badge use the same in-scope escrow paths above, so report those.
  • The NFT grid game — disabled until full production launch.
  • Findings that require a compromised wallet, stolen keys, or social engineering of the operator.
  • The Scrypto blueprint's internal security — a formal audit is planned; on-chain-only blueprint findings are welcome but out of the XRD-gift scope until then.

Rules

  1. 1.Report privately first. DM the operator (link below) — do NOT post exploit details publicly or open a public issue until it's fixed.
  2. 2.Good faith only: no live-funds theft, no attacks on other users, no automated scanning that degrades the service. Use small amounts and your own accounts.
  3. 3.One reporter per issue — first clear, reproducible report. Include steps, expected vs actual, and (for money-path) the on-chain tx or task id.
  4. 4.Rewards are discretionary gifts sized by impact and report quality, paid in XRD after the fix ships. This is beta — there's no guaranteed payout or SLA.

Found something? Report it privately.

DM the operator directly on Telegram. For a money-path issue, include the task id and the on-chain transaction so we can verify it fast.