Ecosystem Contribution & Bug Bounty Reward Framework¶
Overview¶
Trestle incentivizes global whitehat researchers and ecosystem developers to stress-test our codebase. Rewards are determined by technical impact and are paid out directly from the project treasury.
To claim rewards: Join reward.trestle.website, submit your vulnerability report, and complete verification.
Reward Tiers¶
| Severity | Target Systems & Scope | hNOBT Reward | xGov Reward | Payout Release |
|---|---|---|---|---|
| 🔴 Critical (S1) | Escrow protocol bypassing vectors, Dutch Auction pricing or clearing logic exploits, wallet-draining smart contract flaws | 100,000 hNOBT | 2,500 xGov | Instant Release (Within 48 hours of patch) |
| 🔥 High (S2) | Deadlocked contract states, transaction verification loop failures, Telegram Mini-App backend API manipulation | 50,000 hNOBT | 1,000 xGov | 7-Day Security Hold |
| âš¡ Medium (S3) | RPC node desynchronization errors, app state integration dropping inside Telegram, incorrect event emission configurations | 20,000 hNOBT | 250 xGov | 14-Day Processing Cycle |
| 🟡 Low (S4) | Text typos in documentation, layout shifting/cropping inside webviews, UI styling/cosmetic discrepancies | 2,500 hNOBT | 0 xGov | End of Testnet Phase |
All hNOBT rewards are 10× the base rate.
Payout Options¶
Join reward.trestle.website to validate and claim rewards. Two options:
| Option | Requirements | Bug Bounty Payout |
|---|---|---|
| A: Full Reward | Stage 1 (Gitcoin Passport + Accounts) + Stage 2 (Biometric) | 100% hNOBT + 100% xGov |
| B: Early Withdrawal | Stage 1 (Gitcoin Passport + Accounts) only | 50% hNOBT + 0 xGov |
Submission Format¶
To claim eligible technical rewards, submit private findings to contact@trestle.website containing:
- Vulnerability Title — Summary of the identified exploit vector
- Steps to Reproduce — Clean, step-by-step description to reconstruct the issue
- Proof of Concept (PoC) — Code script execution or an active Polygon Amoy Testnet Transaction Hash validating the exploit
Response Timeline¶
- Initial acknowledgement: 48 hours
- Triage & validation: 7 days
- Reward distribution: 14 days after validation
Scope¶
In Scope¶
- Smart contracts (staking, escrow, marketplace, RWA, governance)
- Cloudflare Workers (API, OAuth, verification logic)
- Frontend security issues
- Document verification bypasses
- API/Worker misconfigurations
Out of Scope¶
- UI/UX issues (not security)
- Missing features
- Already reported issues
- Social engineering attacks
- Third-party integrations (Lens, Farcaster, etc.)
- Private/internal code (reward-trestle is a private repository)
Sybil-Defense Rules¶
-
Proof-of-Concept Requirement: No S1, S2, or S3 bug bounty points will be logged without an accompanying active Polygon Amoy Testnet Transaction Hash or a valid, reproducible local code fork.
-
Retention Rule: Growth referrals are only counted if the incoming users pass Trestle Telegram/Discord captcha gate and stay active for at least 72 hours.
-
Multi-Account Rule: If two different profiles submit identical bugs or referral lists, the payout is split 50/50 or canceled entirely pending identity verification.
Team Allocations¶
| Role | hNOBT Allocation | xGov Allocation |
|---|---|---|
| Moderator | 1,000 hNOBT | 50 xGov/week |
| Growth Lead | 2,000 hNOBT | 100 xGov/week |
| Core Dev | 5,000 hNOBT | 500 xGov/week |
Hall of Fame¶
Contributors whose reports are accepted will be:
- Listed in the Security Contributors section
- Eligible for Security Scout NFT badge
- Considered for future Governance Token allocation
Future: Immunefi Transition¶
Upon Mainnet launch with TVL:
- Cash rewards via Immunefi or similar platform
- Higher reward tiers (\(100–\)100,000+ depending on severity)
- Public disclosure process