Active · paid in ZEC

Bug Bounty

We would rather pay a researcher to tell us about a flaw than have it found the hard way. Rewards are paid in ZEC from a transparent pool you can verify on-chain, and scaled by real-world impact — not by how the issue sounds on paper.

Runs until public launch.

Reward pool

7 ZEC

Funded and verifiable on-chain.

t1bV6TkNwWBGBPtGhJCNEQZChpGVivHhHGE
Verify on the explorer

Reward tiers

Critical

3 ZEC

Remote message decryption, key recovery, or theft of funds.

High

1.5 ZEC

Breaking a stated privacy property — e.g. de-anonymizing a sender or recipient.

Medium

0.5 ZEC

Authentication bypass or a server-side flaw with limited blast radius.

Low

0.1 ZEC

Minor information leak or hardening gap with a working proof of concept.

Rewards are paid to a shielded ZEC address you provide. Final severity and payout are set by the team based on real-world impact.

Payouts so far

Every reward we have paid, linked to its transaction. Check any of them on-chain.

Date
Severity
Transaction
2026-06-11
Low · 0.1 ZEC

In scope

  • The Z-Text app — wallet, messaging, PIN/biometric, and panic PIN
  • The Z-Text wire protocol and on-chain message encoding
  • Ed25519 receipt signing and verification
  • The premium-server APIs at z-text.com

Out of scope

Anything listed under what Z-Text does not protect against is a known, documented limitation — not a bounty-eligible bug. That includes ISP-level visibility, device or seed-phrase compromise, the underlying cryptography being broken, global passive adversaries, and social engineering. Also out of scope:

  • Denial-of-service and volumetric attacks
  • Missing security headers or best-practice gaps without a working exploit
  • Automated scanner output without a reproducible proof of concept
  • Issues only reproducible on outdated app versions
  • Social engineering of our team, testers, or infrastructure providers

How to submit

Send your report by email to [email protected]. A plain email is fine; PGP encryption is optional and entirely up to you — we never require it. We aim to acknowledge within 72 hours and to coordinate disclosure from there.

Rules

  • Report privately first and give us the coordinated disclosure window before going public.
  • Do not access, modify, or destroy data that is not yours, run denial-of-service tests, or social-engineer anyone.
  • One reward per unique root cause. The first reporter of an issue receives the reward.
  • Final severity and payout are determined by the team based on real-world impact.
  • We will not pursue legal action against good-faith research that follows these rules.

Want the full picture — threat model, encryption design, and what we openly do not protect against?

Read Security & Transparency
Z-TEXT logoZ-TEXT

Your keys. Your messages. Your freedom.
The zk-SNARKs blockchain messenger BEYOND REACH OF CENSORSHIP.

zk means zero leaks

Company

Z-TEXT Ltd

Trust Company Complex

Ajeltake Road, Ajeltake Island

Majuro, Marshall Islands

MH96960

Technical glossary

zk-SNARKs
Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge — cryptographic proofs that verify a statement without revealing the data behind it. Reference.
BitcoinZ (BTCZ)
Community-driven, no-premine cryptocurrency with zk-SNARKs shielded transactions, launched 2017. Launch announcement.
Equihash
Memory-hard proof-of-work algorithm used by BitcoinZ consensus; it is part of the network security model, not a standalone post-quantum guarantee. Reference.
AES-256-GCM
NIST-standard authenticated encryption used for local message payload encryption before on-chain broadcast. NIST SP 800-38D.
Ztext

Built with for privacy

Built by fighters for free speech and digital freedom