Back to Home
Security Policy

QBC Security Policy & Disclosure

Last reviewed 2026-07-18. RFC 9116 security.txt: /.well-known/security.txt.

Reporting a vulnerability

Send a description of the issue with reproduction steps to security@qbc.network. Please do not disclose publicly until we have confirmed receipt and agreed an embargo timeline.

Bounty program at Immunefi (launching before the production-readiness Phase 4 action gate). Tier capped at $50,000 during onboarding, raised to $250,000 critical post-audit.

What we commit to

  • • Initial acknowledgement within 48 hours.
  • • Triage + severity assignment within 5 business days.
  • • Embargo end no later than 90 days from initial report.
  • • Public credit in docs/SECURITY_ACKNOWLEDGEMENTS.md (opt-in).
  • • CVE assignment via MITRE for any CVSS ≥ 7.0 finding.

Scope

In scope:

  • • L1 consensus, finality, slashing (Substrate pallets + runtime)
  • • L2 QVM execution + JSON-RPC + state-root attestation
  • • All deployed contracts on chain 3303 (per contract_registry.json)
  • • Cross-chain bridge contracts on every supported network
  • • AethersMind binary (signing keys, gradient submission, AetherEpoch interactions)
  • • Frontend at qbc.network (CSP, wallet flow, JWT cookie, SIWE)
  • • Reproducibility primitives in docs/REPRODUCIBILITY.md

Out of scope:

  • • DoS via deliberate resource exhaustion of public endpoints (rate limits exist; abuse them and we'll ban).
  • • Findings requiring physical access to a validator host.
  • • Social engineering of project contributors.
  • • Third-party dependencies with patches already published upstream.

Severity & bounty (post-audit)

SeverityExampleBounty range
CriticalChain halt, mint unbacked QBC, drain bridge vault, sudo bypass$50K – $250K
HighValidator slashing bypass, AetherEpoch fake-finalise, ProxyAdmin takeover$10K – $50K
MediumRPC info disclosure, session hijack via XSS, oracle griefing$1K – $10K
LowLogging-only failures, minor CSP regression, mitigable DoS$200 – $1K

Hardening commitments

  • No hand-rolled cryptography under value. Confidential transfers use post-quantum Dilithium5 signing with a STARK-based range argument, live since spec-165 and cleared by two internal red-team passes. The earlier classical Pedersen and Bulletproofs design is superseded lineage, not the live path. An external cryptographer audit remains a named launch gate.
  • No admin keys gating core consensus. Sudo + reversibility pallet scheduled for removal at Phase 4 of the production-readiness migration; the universal EOA is scheduled for on-chain burn.
  • Reproducible builds. Two-builder hash match for the last 3 releases.
  • Audit + bounty before public funds. Sigma Prime + Spearbit joint engagement; Immunefi bounty open ≥ 30 days before the action gate.

Further reading