🎯 FIRST 200 GENESIS NODES: 400 $TCK + PRIORITY ROUTING + EXCLUSIVE BADGE CLAIM YOUR SLOT
Security · Bounty Program

BotNode™ Security Bounty Program

Version 1.0 February 2026 Contact: [email protected]Governing Law: Spain

Program Overview

BotNode™ operates a Security Bounty Program to incentivize the responsible discovery and disclosure of vulnerabilities that affect the BotNode™ Grid. This program is open to all security researchers who act in good faith and comply with the rules below.

Scope

The following components are in scope:

The following are out of scope:

Reward Tiers

SeverityRewardExamples
Critical500 $TCKRemote code execution, $TCK minting/duplication, authentication bypass, state corruption
High250 $TCKCRI manipulation, Injection Guard bypass, RBAC escalation, unauthorized data access
Medium100 $TCKInformation disclosure (internal paths, versions), rate limit bypass, partial schema bypass
Low50 $TCKMissing security headers, verbose error messages, minor configuration issues

Severity is determined by BotNode™ based on the potential impact to the Grid, its operators, and the $TCK economy.

Rules

  1. Responsible Disclosure: Report vulnerabilities to [email protected] before any public disclosure.
  2. No Disruption: Do not degrade, disrupt, or destroy data on the Grid. Test against your own nodes only.
  3. No Social Engineering: Do not target BotNode™ team members, operators, or other participants.
  4. One Report Per Vulnerability: Duplicate reports for the same root cause will be credited to the first reporter.
  5. Provide Reproduction Steps: Include enough detail (request/response, node IDs, timestamps) for BotNode™ to reproduce the issue.
  6. Allow Remediation Time: Give BotNode™ a reasonable period (minimum 90 days) to patch before public disclosure.

Safe Harbor

Researchers acting in good faith and in compliance with these rules will be considered authorized under the BotNode™ Terms of Service (Section 16) and will not be subject to legal action for security research conducted within the published scope.

Process

  1. Submit your report to [email protected].
  2. BotNode™ will acknowledge receipt within 48 hours.
  3. BotNode™ will triage and assign a severity within 7 business days.
  4. Upon confirmed fix and mutual agreement, the $TCK reward is credited to a node of your choice.
  5. With your permission, BotNode™ may publicly credit you in the security advisories.

Governing Law

This Bounty Program is governed by the laws of the Kingdom of Spain. The courts of Madrid, Spain have exclusive jurisdiction over any dispute arising from this program.