Break it. Get paid.
MoonBite's whole pitch is "don't trust us — verify." So come verify. For two weeks, every real bug you find in the node, the wallet, the miner, or this site earns points. The five hunters with the most points split the prize pool.
5,000 MBITE across the top 5
Ranked by total points from accepted reports when the clock stops on 5 Oct 2026, 18:00 UTC.
1st — 2,000 MBITE
Top of the leaderboard.
2nd — 1,200 MBITE
3rd — 800 MBITE
4th — 600 MBITE
5th — 400 MBITE
Points per bug
Critical 500 · High 250 · Medium 100 · Low 40. First valid report of an issue gets the points; duplicates credit the first.
What counts
Consensus bugs, chain splits, coin inflation, crashes a peer can trigger remotely. Anything that breaks the chain's rules is an automatic Critical. Test on regtest or testnet — that's what they're for.
The web wallet at moonbite.org/wallet and the desktop wallet. Seed handling, key generation, transaction building, anything that could lose or leak a user's coins.
mine.sh, mine.ps1, the bundles, checksums, and the download pipeline. A bundle that doesn't run on a stock machine is a valid bug too.
The site, its APIs, and the explorer. Injection, auth bypass, data leaks, broken logic, or plain wrong information displayed as fact.
Two doors, pick the right one
Anything exploitable goes through GitHub's private vulnerability reporting, so it gets fixed before it gets famous. Public zero-days forfeit the points.
Crashes, wrong balances, broken pages, misleading copy, bundles that don't run: open a public issue titled [bounty] with steps to reproduce.
Every report needs: what you found, steps to reproduce it, and what you think the impact is. Include a moon1... address — that's where prizes land. Severity is judged by the maintainer; the running leaderboard is published in a pinned GitHub discussion during the event, and final standings within 72 hours of close.