Security at QoreChain
QoreChain was built for adversaries that do not exist yet. The same discipline applies to the ones that do: post-quantum cryptography at every layer, a standing bug bounty, responsible disclosure, and independent review.
Quantum-safe by construction
Full-stack post-quantum cryptography
ML-DSA-87 (Dilithium-5, FIPS 204) for signatures, ML-KEM-1024 (Kyber, FIPS 203) for key encapsulation, SHAKE-256 for hashing. Applied to consensus, transactions, bridges, and state verification, not bolted on.
NIST Category 5
QoreChain targets the highest NIST security category, equivalent to AES-256, for 128-bit post-quantum security across the protocol stack. The standards it implements were finalized by NIST in August 2024.
Wallet security by default
QoreX, the official wallet, is non-custodial: keys are generated and stored only on your device, every QOR transfer is signed with mandatory ML-DSA-87, and the apps collect no analytics and no personal data.
A 67,500,000 QOR bug bounty
Opened at mainnet launch on 7 June 2026 and active for the lifetime of the network. On 1 September 2026 it opens as a structured public programme, Break QoreChain, with a defined season, a published scope, fixed reward tiers and a settlement date.
The pool, and how to check it yourself
The bug bounty allocation is held in a dedicated on-chain escrow. You do not have to take our word for the balance.
qor1c60gmsq68jpx8yzjj0pagl7kkggs4zc8mrfkkmcurl -s https://api.qore.host/cosmos/bank/v1beta1/balances/qor1c60gmsq68jpx8yzjj0pagl7kkggs4zc8mrfkkmThe escrow holds 67,500,000 QOR and releases over 48 months under the published tokenomics. The first season of Break QoreChain, from 1 September 2026 to 28 February 2027, runs on the tranche released at listing: 10,125,000 QOR, distributed in full at settlement.
The pool is denominated in QOR and held on-chain. Every payout is made in stablecoin, converted from the pool at the time of payment. You are paid in something you can spend.
We convert QOR to stablecoin only to pay a validated report, from the address above, and we publish the transaction hash with every payout.
This pool is funded separately from the insurance fund. The insurance fund exists to make users whole and is not spent on anything else.
Rewards
| Severity | Total | First payment | Paid within | Paid on mainnet deployment of the fix |
|---|---|---|---|---|
| Critical | 5,000 USDT | 1,500 | 14 days | 3,500 |
| High | 2,000 USDT | 600 | 14 days | 1,400 |
| Medium | 750 USDT | 250 | 21 days | 500 |
| Low | 250 USDT | 100 | 21 days | 150 |
| Insight | 100 USDT | 50 | 21 days | 50 |
The clock starts the moment your report reaches our inbox, not on a date we choose. Critical and High are triaged and paid first because they are the ones that can cost users money.
Our triage is done by a named human being rather than a queue, and we would rather tell you what that means than pretend otherwise. If more than ten valid reports reach us in any rolling thirty day period, we will say so on this page, and the Medium, Low and Insight window extends to thirty days for reports received after that notice. Critical and High are never extended, and no extension is ever applied to a report already in our hands.
If the fix is not deployed to mainnet within 90 days of the triage decision, the remaining balance is paid in full regardless. Your reward does not depend on our engineering schedule.
Every valid report also earns a share of the season pool, distributed at settlement on 28 February 2027 in the proportions below. The pool is distributed in full whether or not anyone finds a critical. Categories with no findings are redistributed proportionally.
| Category | Share of the 10,125,000 QOR season pool |
|---|---|
| Critical | 40% |
| High | 25% |
| Medium | 15% |
| Low | 5% |
| Insight and hardening | 10% |
| Participation | 5% |
The participation share is split between everyone who submitted at least one valid report, including duplicates. Nobody who did real work leaves with nothing.
Severity classification
- Critical. Direct theft or permanent freezing of user funds, unauthorised minting or supply inflation, consensus halt or chain split reachable by an unprivileged actor, forgery or bypass of the post-quantum signature path.
- High. Theft or freezing of funds under preconditions the attacker does not fully control, privilege escalation to validator or module authority, permanent denial of service on a core module, key recovery or predictable key generation in a production signing path.
- Medium. Temporary denial of service, incorrect state transitions without direct financial loss, authorisation flaws limited to non-financial data, cryptographic weaknesses without a demonstrated exploitation path.
- Low. Issues requiring unusual configuration or privileged access, information disclosure of non-sensitive data, defects with clear mitigations already available to operators.
- Insight. Hardening opportunities, defence-in-depth improvements, and documented deviations between shipped behaviour and published specification.
PQC implementation issues, including side channels, carry the highest priority within their severity band.
Scope
In scope from 1 September
- Consensus and block production, including staking, slashing and distribution
- The bank module, locked-coin accounting and escrow accounts
- The ML-DSA-87 signing path and post-quantum key registration, Go implementation
- The EVM execution lane, chain 9801
- Public RPC and API infrastructure
- The QoreX wallet
Added during the season
Components under active remediation are not in scope at opening. We do not open a bounty over code we already know is being changed. Each one is added, with an announcement, as its remediation lands: the CosmWasm lane, the bridge module, the dashboard application, the C and Python bindings in qorechain-pqc, and qorechain-lightnode.
Added at the end of the season
In the final two weeks of February, after the external audit, the SVM execution lane enters scope. It is the lane that broke us on 21 August, and it is the last one we open, only after everyone has had a chance to try it.
Out of scope
Volumetric and denial of service testing against production, social engineering of the team or the community, third party dependencies without a demonstrated impact on QoreChain, any testing on mainnet that affects real users or real funds, and automated mass submissions.
Proof of concept required
Every submission, at every severity, must include a working proof of concept against a local devnet or the public testnet. No proof of concept, no reward. This is not a formality; it is what lets us pay you in fourteen days instead of arguing for a month.
Reporting and disclosure
How a report travels
- 1Report privatelyWrite to security@qore.network with a description, reproduction steps, affected commit or version, and your assessment of impact. Do not open a public GitHub issue for security reports.
- 2Acknowledgement within 48 hoursWe confirm receipt within 48 hours with a reference number, followed by a triage decision and a severity classification from a person.
- 3PaymentThe first payment reaches you within 14 days of your report for Critical and High, and within 21 days for Medium, Low and Insight. The remainder is paid on mainnet deployment of the fix, or at 90 days from the triage decision, whichever comes first.
- 4DisclosureCritical vulnerabilities are targeted for a fix within 30 days. Public disclosure follows once the fix is deployed to mainnet. Every valid report is published, with credit to the reporter, unless they prefer anonymity.
Safe harbour
Research conducted in good faith and within the scope above will not be met with legal action from the QoreChain Association, and we will not request that a third party bring one. Good faith means you did not access, modify or exfiltrate user data or funds beyond the minimum needed to demonstrate the issue, you did not test against mainnet in a way that affects real users or real funds, you reported to us privately, and you gave us the disclosure window above. If you follow those conditions and we later disagree about severity or eligibility, that is a disagreement about a payment, never a legal matter.
Separately, the Association has applied to adopt the Whitehat Safe Harbor agreement published by the Security Alliance (SEAL). That framework covers a different situation: it pre-authorises a whitehat to intervene during an active exploit in order to rescue funds. It is not a substitute for the paragraph above and it does not cover routine research. We will publish the on-chain adoption once it is registered.
Reports received before 1 September
Reports received before the programme opened are covered at full programme rates, regardless of the staged scope above.
Independent review
Third-party audit
An independent third-party security audit of the protocol is ongoing, with results to be published in the project data room when complete. The core protocol builds on the Cosmos SDK, and QoreChain's public interfaces, types, and protocol definitions are open source on GitHub.