Bug Bounty

Beta

Radix Guild is in beta. Help us find the sharp edges before wider launch — report an issue in good faith and earn a small XRD gift for it. This is an interim, manually-paid bounty while the source is private; the provably-funded on-chain version (posted as a real Guild task) follows source publication — see Trust & Verification.

Reward guide

Indicative ranges, at the operator's discretion — sized by real impact and report quality. Money-path findings are the priority.

Low
50–100 XRD

UI/UX defects, broken links, display or copy errors, non-security state desyncs the resync button already heals.

Medium
250–500 XRD

Auth/session edge cases, badge-gate bypass, API input-validation gaps, denial-of-service on a route.

High — money path
1,000+ XRD

Anything that lets funds move to the wrong party, a task settle for the wrong amount, or a funded task be edited/cancelled off the escrow path. These get priority and the largest gifts.

In scope
  • radixguild.com — the live dashboard (badge mint, task board, post/claim/submit/approve).
  • The escrow confirm + settlement path: anything that moves XRD to the wrong place or amount.
  • The v1 API under /api/v1/* (auth, tasks, submissions, escrow confirm).
  • Badge-gating and session/account-mismatch handling.
Out of scope (for now)
  • Disputes and the auto-resolve/finalize flow — switched OFF for beta (a known hardening track); reports there are already expected.
  • The agent lane / ADK — not live yet.
  • The NFT grid game — disabled until full production launch.
  • Findings that require a compromised wallet, stolen keys, or social engineering of the operator.
  • The Scrypto blueprint's internal security — a formal audit is planned; on-chain-only blueprint findings are welcome but out of the XRD-gift scope until then.

Rules

  1. 1.Report privately first. Use the feedback form below — do NOT post exploit details publicly or open a public issue until it's fixed.
  2. 2.Good faith only: no live-funds theft, no attacks on other users, no automated scanning that degrades the service. Use small amounts and your own accounts.
  3. 3.One reporter per issue — first clear, reproducible report. Include steps, expected vs actual, and (for money-path) the on-chain tx or task id.
  4. 4.Rewards are discretionary gifts sized by impact and report quality, paid in XRD after the fix ships. This is beta — there's no guaranteed payout or SLA.

Found something? Report it privately.

The feedback form routes straight to the operator. For a money-path issue, include the task id and the on-chain transaction so we can verify it fast.