Skip to content
This repository has been archived by the owner on Dec 12, 2020. It is now read-only.
/ hackthedex.io Public archive

Hack The DEX: the BitShares Bug Bounty Program

License

Notifications You must be signed in to change notification settings

bitshares/hackthedex.io

Repository files navigation

NOTE: This project is archived due to lack of maintenance. There are lots of potential dependency issues reported.

The domain name hackthedex.io has expired and has been squatted by an unknown 3rd party.

Hack The DEX

a BitShares Worker Proposal

Overview

BitShares is a decentralized exchange (DEX) built on top of delegated proof-of-stake (DPoS) blockchain technology. With all financial technology in the blockchain space, a major concern for users and traders is security.

If someone found a critical bug in the DEX, they might be tempted to exploit the bug, and attempt to steal funds from unsuspecting users. Without a public bug bounty system, hackers do not have an obvious path of disclosure for reporting their findings. They also do not have any incentive to share their exploits and techniques, rather than using them for personal gain.

With this proposal, we’d like to start a BitShares bug bounty program for security researchers and penetration testers (...aka hackers!) to disclose important security vulnerabilities they find within the BitShares core protocol, reference wallet, and related code repositories.

The proposal will use allocated funds to reward those that step forward with exploits, relative to the overall risk assessment of the exploit. The higher the payout for critical bugs, the more incentive there will be to attract higher quality researchers, and ultimately providing better security coverage for the DEX.

Funds will also be used to build and maintain a basic public website for reporting vulnerabilities. The website will include all the information needed for researchers to report a vulnerability, as well as an archive of bounty reports and a leaderboard to encourage a little friendly hacker competition. It will also lay the groundwork for future HackTheDEX worker proposals to improve the security and safety of BitShares as a whole. Worker proposal funds will be held in an escrow account and unused funds will be refunded back to the network at the end of the proposal period.

Continue to HackTheDEX.io (update: the domain name is no longer owned by us).

About

Hack The DEX: the BitShares Bug Bounty Program

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published