MoonBite
MoonBite
Get Wallet
Bug Bounty Hackathon · 21 Sep – 5 Oct 2026

Break it. Get paid.

MoonBite's whole pitch is "don't trust us — verify." So come verify. For two weeks, every real bug you find in the node, the wallet, the miner, or this site earns points. The five hunters with the most points split the prize pool.

Prizes are paid in MBITE from coins the founder mined himself on the live chain — MoonBite has no premine and no treasury, so there is nowhere else for them to come from. MBITE has no market value and no exchange listing; treat prizes as a stake in the network, not money. MoonBite is not an investment or a security.
The pool

5,000 MBITE across the top 5

Ranked by total points from accepted reports when the clock stops on 5 Oct 2026, 18:00 UTC.

1st — 2,000 MBITE

Top of the leaderboard.

2nd — 1,200 MBITE

3rd — 800 MBITE

4th — 600 MBITE

5th — 400 MBITE

Points per bug

Critical 500 · High 250 · Medium 100 · Low 40. First valid report of an issue gets the points; duplicates credit the first.

Scope

What counts

MoonBite Core (the big one)

Consensus bugs, chain splits, coin inflation, crashes a peer can trigger remotely. Anything that breaks the chain's rules is an automatic Critical. Test on regtest or testnet — that's what they're for.

Wallet

The web wallet at moonbite.org/wallet and the desktop wallet. Seed handling, key generation, transaction building, anything that could lose or leak a user's coins.

Miner & downloads

mine.sh, mine.ps1, the bundles, checksums, and the download pipeline. A bundle that doesn't run on a stock machine is a valid bug too.

moonbite.org

The site, its APIs, and the explorer. Injection, auth bypass, data leaks, broken logic, or plain wrong information displayed as fact.

Out of scope: traffic-flooding the live seed node or site (that's just an outage, not a finding), attacks on other users or their coins, social engineering, and anything needing physical access. Consensus attacks belong on regtest/testnet, never mainnet.
Submit

Two doors, pick the right one

Security vulnerabilities — private

Anything exploitable goes through GitHub's private vulnerability reporting, so it gets fixed before it gets famous. Public zero-days forfeit the points.

Report privately on GitHub →

Ordinary bugs — public issue

Crashes, wrong balances, broken pages, misleading copy, bundles that don't run: open a public issue titled [bounty] with steps to reproduce.

Open an issue →

Every report needs: what you found, steps to reproduce it, and what you think the impact is. Include a moon1... address — that's where prizes land. Severity is judged by the maintainer; the running leaderboard is published in a pinned GitHub discussion during the event, and final standings within 72 hours of close.