Skip to content

Ecosystem Contribution & Bug Bounty Reward Framework

Overview

Trestle incentivizes global whitehat researchers and ecosystem developers to stress-test our codebase. Rewards are determined by technical impact and are paid out directly from the project treasury.

To claim rewards: Join reward.trestle.website, submit your vulnerability report, and complete verification.


Reward Tiers

Severity Target Systems & Scope hNOBT Reward xGov Reward Payout Release
🔴 Critical (S1) Escrow protocol bypassing vectors, Dutch Auction pricing or clearing logic exploits, wallet-draining smart contract flaws 100,000 hNOBT 2,500 xGov Instant Release (Within 48 hours of patch)
🔥 High (S2) Deadlocked contract states, transaction verification loop failures, Telegram Mini-App backend API manipulation 50,000 hNOBT 1,000 xGov 7-Day Security Hold
âš¡ Medium (S3) RPC node desynchronization errors, app state integration dropping inside Telegram, incorrect event emission configurations 20,000 hNOBT 250 xGov 14-Day Processing Cycle
🟡 Low (S4) Text typos in documentation, layout shifting/cropping inside webviews, UI styling/cosmetic discrepancies 2,500 hNOBT 0 xGov End of Testnet Phase

All hNOBT rewards are 10× the base rate.


Payout Options

Join reward.trestle.website to validate and claim rewards. Two options:

Option Requirements Bug Bounty Payout
A: Full Reward Stage 1 (Gitcoin Passport + Accounts) + Stage 2 (Biometric) 100% hNOBT + 100% xGov
B: Early Withdrawal Stage 1 (Gitcoin Passport + Accounts) only 50% hNOBT + 0 xGov

Submission Format

To claim eligible technical rewards, submit private findings to contact@trestle.website containing:

  1. Vulnerability Title — Summary of the identified exploit vector
  2. Steps to Reproduce — Clean, step-by-step description to reconstruct the issue
  3. Proof of Concept (PoC) — Code script execution or an active Polygon Amoy Testnet Transaction Hash validating the exploit

Response Timeline

  • Initial acknowledgement: 48 hours
  • Triage & validation: 7 days
  • Reward distribution: 14 days after validation

Scope

In Scope

  • Smart contracts (staking, escrow, marketplace, RWA, governance)
  • Cloudflare Workers (API, OAuth, verification logic)
  • Frontend security issues
  • Document verification bypasses
  • API/Worker misconfigurations

Out of Scope

  • UI/UX issues (not security)
  • Missing features
  • Already reported issues
  • Social engineering attacks
  • Third-party integrations (Lens, Farcaster, etc.)
  • Private/internal code (reward-trestle is a private repository)

Sybil-Defense Rules

  1. Proof-of-Concept Requirement: No S1, S2, or S3 bug bounty points will be logged without an accompanying active Polygon Amoy Testnet Transaction Hash or a valid, reproducible local code fork.

  2. Retention Rule: Growth referrals are only counted if the incoming users pass Trestle Telegram/Discord captcha gate and stay active for at least 72 hours.

  3. Multi-Account Rule: If two different profiles submit identical bugs or referral lists, the payout is split 50/50 or canceled entirely pending identity verification.


Team Allocations

Role hNOBT Allocation xGov Allocation
Moderator 1,000 hNOBT 50 xGov/week
Growth Lead 2,000 hNOBT 100 xGov/week
Core Dev 5,000 hNOBT 500 xGov/week

Hall of Fame

Contributors whose reports are accepted will be:

  • Listed in the Security Contributors section
  • Eligible for Security Scout NFT badge
  • Considered for future Governance Token allocation

Future: Immunefi Transition

Upon Mainnet launch with TVL:

  • Cash rewards via Immunefi or similar platform
  • Higher reward tiers (\(100–\)100,000+ depending on severity)
  • Public disclosure process