Duglas is an open, educational blockchain project. If you find real issues — security problems, logical flaws, consensus bugs, or anything that breaks the chain — we want to hear about it. And we’ll reward you for it.
Wallet security issues, private key exposure risks, signature bypass, or any flaw that could compromise user funds in a real deployment scenario.
GitHub subscription + 3 repo starsIssues in block validation, chain replacement logic, PoW verification, or anything that could allow an invalid chain to be accepted.
GitHub subscription + 3 repo starsDouble-spend scenarios, nonce manipulation, balance validation bypasses, or fee policy circumvention in the mempool.
GitHub subscription + 3 repo starsNon-deterministic state, state corruption on replay, incorrect pending-state calculation, or history inconsistencies.
GitHub subscription + 3 repo starsChain sync bugs, peer propagation failures, eclipse attack vectors, or WebSocket handling flaws.
GitHub subscription + 3 repo starsCLI errors, API edge cases, documentation mistakes that lead to confusion, or reproducible crashes.
Shoutout + repo starsWe’re an indie project — no VC money, no token sale. What we can offer is visibility and community support:
Run Duglas locally. Explore the codebase. Try to break things intentionally.
Write clear reproduction steps. Include expected vs actual behavior. Be specific.
Open a GitHub issue or use the form below. Include your GitHub username for reward.
We verify, fix, and ship. You get credited and rewarded accordingly.
Fill this out once. Public bugs can go to GitHub Issues. Critical or private security reports can go straight to email.