About BugChan

BugChan is a decentralized bug bounty platform for Web3. Projects launch transparent onchain bounty programs, and researchers submit reproducible reports with a small stake to reduce spam. Rewards are distributed based on outcomes, all verifiable onchain.

Security shield

Why BugChan

Onchain transparency

Budgets, reward tiers, and timelines are public and auditable.

Spam‑resistant

Stake per submission discourages spam and rewards quality.

Researcher‑friendly

Clear scope, fast feedback, fair rewards.

Programmable payouts

Composable bounties built for Web3.

Technology

BugChan provides a decentralized bug bounty platform that operates on the Sepolia testnet. The platform uses smart contracts to track submissions, stakes, and rewards while storing encrypted vulnerability reports on IPFS.

Security Model

  • On‑chain: Smart contracts record bounty details, report references, and stakes
  • Off‑chain (IPFS): Bounty documentation and vulnerability reports
  • Client‑side encryption: Ensures reports are only readable by authorized parties
  • Stake mechanism: Researchers stake ETH to submit reports, discouraging spam

Requirements

BugChan operates on the Sepolia testnet. All interactions require a connected wallet with Sepolia ETH for transaction fees.

How it works

For project owners

  1. Create bounty with detailed scope and reward treasury
  2. Review submitted vulnerability reports
  3. Accept valid reports and reject invalid submissions
  4. Close bounty to distribute rewards to approved researchers

For security researchers

  1. Browse open bounties and review scope documentation
  2. Prepare and encrypt vulnerability reports
  3. Submit findings with required stake amount
  4. Receive rewards for accepted reports when bounty closes

Rewards & Incentives

  • Projects fund a treasury that distributes rewards when the bounty closes
  • Researchers must stake ETH to submit reports, which is returned upon acceptance
  • Multiple submissions allowed with fixed stake amount per submission
  • Rejected reports result in slashed stake; pending reports are refunded when bounty closes
  • Rewards are distributed according to report quality and severity tiers
BugChan logo

Decentralized bug bounty platform securing web3, one vulnerability at a time.

Built for ETHOnline 2025