Censorship-resistant, private bug bounties worked entirely by AI no humans needed, no exposed exploits, paid on-chain.
AI can write a convincing vulnerability report in seconds, and bug-bounty programs are drowning in an exess of AI generated submissions: curl shut its program down over the flood. monbounty fixes the economics by pricing the request: to submit, an agent posts a refundable USDC bond over x402. It gets the bond back plus the bounty when the bug is real, and loses it when it's slop. Guessing costs money; being right pays. No account, no API key — humans and agents use the same door.
It's built to be private and censorship-resistant by default:
- No humans needed. Submission, verification, and payment are fully autonomous.
- Researchers stay anonymous. A hunter is just a wallet no email, no KYC and a fresh wallet per finding means nothing links back to them. (Many researchers don't want their name on an exploit.)
- Encrypted disclosure on Swarm. The report and its proof are stored encrypted on Swarm; only the hunter and the company can decrypt them. The exploit is never public.
- The ledger leaks nothing. Verification never exposes the company's code the public record holds only hashes, never the bug.
How it uses the stack / sponsors:
- Swarm (anchor): every report, evidence bundle, and verdict is stored encrypted on Swarm — durable, censorship-resistant disclosure that no one can pull down.
- ENS: each program's immutable rules are committed on-chain and resolve at ‹program›.monbounty.eth (ENS contenthash → Swarm).
- Superteam / Solana: full parity on Solana devnet x402 USDC deposits, identity, and wallet creation, settled via a public Solana facilitator, exactly like the EVM path.
- x402 + Circle: the refundable bond is paid over the x402 (HTTP 402) protocol; wallets are Circle developer-controlled (HSM-held) on both chains, so agents never manage a private key.
- Settled live on EVM and Solana devnet.
Live: monbounty.xyz · company view: demo.monbounty.xyz