Back to Home
Security Policy
QBC Security Policy & Disclosure
Last reviewed 2026-07-18. RFC 9116 security.txt: /.well-known/security.txt.
Reporting a vulnerability
Send a description of the issue with reproduction steps to security@qbc.network. Please do not disclose publicly until we have confirmed receipt and agreed an embargo timeline.
Bounty program at Immunefi (launching before the production-readiness Phase 4 action gate). Tier capped at $50,000 during onboarding, raised to $250,000 critical post-audit.
What we commit to
- • Initial acknowledgement within 48 hours.
- • Triage + severity assignment within 5 business days.
- • Embargo end no later than 90 days from initial report.
- • Public credit in
docs/SECURITY_ACKNOWLEDGEMENTS.md(opt-in). - • CVE assignment via MITRE for any CVSS ≥ 7.0 finding.
Scope
In scope:
- • L1 consensus, finality, slashing (Substrate pallets + runtime)
- • L2 QVM execution + JSON-RPC + state-root attestation
- • All deployed contracts on chain 3303 (per
contract_registry.json) - • Cross-chain bridge contracts on every supported network
- • AethersMind binary (signing keys, gradient submission, AetherEpoch interactions)
- • Frontend at qbc.network (CSP, wallet flow, JWT cookie, SIWE)
- • Reproducibility primitives in
docs/REPRODUCIBILITY.md
Out of scope:
- • DoS via deliberate resource exhaustion of public endpoints (rate limits exist; abuse them and we'll ban).
- • Findings requiring physical access to a validator host.
- • Social engineering of project contributors.
- • Third-party dependencies with patches already published upstream.
Severity & bounty (post-audit)
| Severity | Example | Bounty range |
|---|---|---|
| Critical | Chain halt, mint unbacked QBC, drain bridge vault, sudo bypass | $50K – $250K |
| High | Validator slashing bypass, AetherEpoch fake-finalise, ProxyAdmin takeover | $10K – $50K |
| Medium | RPC info disclosure, session hijack via XSS, oracle griefing | $1K – $10K |
| Low | Logging-only failures, minor CSP regression, mitigable DoS | $200 – $1K |
Hardening commitments
- No hand-rolled cryptography under value. Confidential transfers use post-quantum Dilithium5 signing with a STARK-based range argument, live since spec-165 and cleared by two internal red-team passes. The earlier classical Pedersen and Bulletproofs design is superseded lineage, not the live path. An external cryptographer audit remains a named launch gate.
- No admin keys gating core consensus. Sudo + reversibility pallet scheduled for removal at Phase 4 of the production-readiness migration; the universal EOA is scheduled for on-chain burn.
- Reproducible builds. Two-builder hash match for the last 3 releases.
- Audit + bounty before public funds. Sigma Prime + Spearbit joint engagement; Immunefi bounty open ≥ 30 days before the action gate.