Find bugs.
Get rewarded.

Duglas is an open, educational blockchain project. If you find real issues — security problems, logical flaws, consensus bugs, or anything that breaks the chain — we want to hear about it. And we’ll reward you for it.

Security Vulnerabilities

Wallet security issues, private key exposure risks, signature bypass, or any flaw that could compromise user funds in a real deployment scenario.

GitHub subscription + 3 repo stars

Consensus & Chain Bugs

Issues in block validation, chain replacement logic, PoW verification, or anything that could allow an invalid chain to be accepted.

GitHub subscription + 3 repo stars

Transaction & Mempool Flaws

Double-spend scenarios, nonce manipulation, balance validation bypasses, or fee policy circumvention in the mempool.

GitHub subscription + 3 repo stars

State Derivation Issues

Non-deterministic state, state corruption on replay, incorrect pending-state calculation, or history inconsistencies.

GitHub subscription + 3 repo stars

P2P Network Issues

Chain sync bugs, peer propagation failures, eclipse attack vectors, or WebSocket handling flaws.

GitHub subscription + 3 repo stars

General Bugs & Improvements

CLI errors, API edge cases, documentation mistakes that lead to confusion, or reproducible crashes.

Shoutout + repo stars

What you get

We’re an indie project — no VC money, no token sale. What we can offer is visibility and community support:

  • +GitHub Stars — we’ll star up to 3 repositories of your choice from our accounts.
  • +GitHub Follow — subscription or follow to your GitHub profile.
  • +Public Credit — credited in CONTRIBUTORS and release notes.
  • +Something else? — open to other fair exchanges. Reach out and let’s talk.
REWARD TIERS
Critical / SecuritySub + 3 Stars
Consensus / ChainSub + 3 Stars
Tx / MempoolSub + 2 Stars
State / P2PSub + 2 Stars
General BugsStars + Credit
1

Find an Issue

Run Duglas locally. Explore the codebase. Try to break things intentionally.

2

Document It

Write clear reproduction steps. Include expected vs actual behavior. Be specific.

3

Submit a Report

Open a GitHub issue or use the form below. Include your GitHub username for reward.

4

Get Rewarded

We verify, fix, and ship. You get credited and rewarded accordingly.

Submit a Bug Report

Fill this out once. Public bugs can go to GitHub Issues. Critical or private security reports can go straight to email.

Routing: regular bugs open a prefilled GitHub Issue. Critical / Security reports can be sent privately to dv842449@gmail.com with all fields prefilled into the email draft.