AGP Picks
View all

QoreChain opens bug bounty 11 days after chain exploit

Sep. 2, 2026
By AI, Created 12:00 UTC, Sep 02, 2026, AGP -

QoreChain launched a public bug bounty on Sept. 1, 2026, days after a code flaw let a single transaction move most of its token supply. The program follows a 25-minute chain halt, state rollback and public incident report, with rewards paid in USDT and an on-chain escrow anyone can inspect.

Why it matters: - QoreChain is trying to turn a live exploit into a standing security process before the same flaw class appears again. - The bounty is structured to pay researchers in stablecoin and on a timeline that does not depend on how fast QoreChain’s engineering team moves. - The program’s escrow is on-chain and publicly queryable, which makes the reward pool visible without contacting the association.

What happened: - On Aug. 21, 2026, an authorization failure in QoreChain’s SVM execution lane let a single transaction move most of the network’s token supply. - The QoreChain Association halted block production 25 minutes after the transaction. - The association restored chain state to the block before the exploit and restarted the network. - No user lost funds. - Three days later, the association published a full technical report covering the code path, timeline and why the response took 25 minutes instead of five. - On Sept. 1, the association opened Break QoreChain, a public bug bounty season running through Feb. 28, 2027.

The details: - The first season’s reward pool sits in a dedicated on-chain escrow at qor1c60gmsq68jpx8yzjj0pagl7kkggs4zc8mrfkkm, which holds 67,500,000 QOR. - The escrow can be queried from any public endpoint on the network. - The first season is funded from the tranche released at listing, totaling 10,125,000 QOR. - QoreChain says the full tranche is distributed at settlement whether or not anyone finds a critical bug. - Rewards are fixed in USDT: 5,000 for critical, 2,000 for high, 750 for medium, 250 for low and 100 for an insight. - Critical and high reports get part of the payout within 14 days of arrival. - Medium, low and insight reports get part of the payout within 21 days of arrival. - The remainder is paid when the fix reaches mainnet or after 90 days from the triage decision, whichever comes first. - Scope at launch includes consensus and block production, the bank module and escrow accounting, ML-DSA-87 post-quantum signing and key registration, the EVM execution lane, public RPC and API infrastructure, and the QoreX wallet. - Components under active remediation are out of scope and will be added with an announcement after remediation completes. - The SVM execution lane enters scope in the final two weeks of the season after an external audit and before reopening to users. - Every valid report will be published after the related fix is deployed, with credit to the researcher unless the researcher prefers anonymity. - Reports submitted before the program opened will be paid at full program rates. - Several reports arrived in the days before opening. - QoreChain enforces ML-DSA-87, ML-KEM-1024 and SHAKE-256 at protocol level. - Mainnet launched on June 7, 2026. - Programme terms, scope and severity classification are published at QoreChain security. - QoreChain’s main site is available at QoreChain.

Between the lines: - Founder and CTO Liviu Ionut Epure framed the bounty as a shift from incident response to continuous external review. - Epure said the team wants researchers paid when reports arrive, not when internal schedules allow. - The structure also limits the chance that a security researcher waits months for a payout after finding a serious flaw. - QoreChain’s decision to publish the exploit report quickly, then open a bounty 11 days after the incident, signals an attempt to rebuild confidence after a near-total supply movement. - Membership in the PKI Consortium and Crypto Valley Association places QoreChain inside broader post-quantum and blockchain industry networks.

What's next: - The bounty season will continue through Feb. 28, 2027. - Additional components will be added to scope as remediation finishes. - The SVM execution lane will return to scope near the end of the season after external audit. - Researchers who file valid reports will be paid in phases as fixes land or 90 days pass from triage.

The bottom line: - QoreChain is pairing a public post-exploit reset with an on-chain bounty designed to make future vulnerabilities more likely to be found by outsiders first, and paid fast.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Blockchain News Online

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Blockchain News Online

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.