Syscoin is a full-stack, modular blockchain platform merge-mined with Bitcoin, combining the security of Proof-of-Work with advanced scalability features. Its dual-chain Layer 1 architecture consists of a native UTXO-based chain for data availability and finality, alongside NEVM (Network-Enhanced Virtual Machine), an EVM-compatible chain offering Ethereum equivalence. This hybrid design enables secure, scalable rollups while bridging the strengths of Bitcoin and Ethereum ecosystems.
Program Overview Syscoin has launched a targeted bug bounty program for version 4.4.2 of its Network Enhanced Virtual Machine (NEVM) on the Testnet, focused on the following components within the official repository: https://github.com/syscoin/syscoin/tree/master. This includes the QT client, Syscoin Core, Bridge, and NEVM modules, while third-party applications and older branches are out of scope. The program aims to identify issues that could affect the reliability or performance of Syscoin’s next-generation blockchain infrastructure.
Reward Structure Submissions are classified using a 4-tier severity model based on system impact.
Level 1 – Non-Breaking Issues: UI glitches, typos, or platform-specific errors that do not interrupt functionality. Rewards up to $250, unlimited number of submissions.
Level 2 – Breaking Local Issues: Bugs that halt or manipulate data locally without affecting the overall network. Rewards up to $2,500, capped at 25 accepted reports.
Level 3 – Breaking Network Issues: Bugs that halt the network or allow manipulation of network-wide data. Rewards up to $25,000, capped at 5 accepted reports.
Level 4 – Critical Composite Exploits: Combinations of vulnerabilities or multi-layered attack vectors that affect both the network and users. Rewards and acceptance are discretionary.
All rewards are assessed and classified by the Syscoin security team based on reproducibility, scope of impact, and adherence to eligibility guidelines.
Submission Requirements To be eligible for a reward, bug reports must include a fully functional proof of concept (PoC) and detailed steps to reproduce the vulnerability. Submissions without code or demonstrable impact will be rejected.
Payouts All rewards are denominated in USD and paid in SYS, Syscoin’s native token. Payouts are processed directly by the Syscoin team after validation and successful KYC approval.