Bug Bounty
We would rather pay a researcher to tell us about a flaw than have it found the hard way. Rewards are paid in ZEC from a transparent pool you can verify on-chain, and scaled by real-world impact — not by how the issue sounds on paper.
Runs until public launch.
7 ZEC
Funded and verifiable on-chain.
t1bV6TkNwWBGBPtGhJCNEQZChpGVivHhHGEReward tiers
3 ZEC
Remote message decryption, key recovery, or theft of funds.
1.5 ZEC
Breaking a stated privacy property — e.g. de-anonymizing a sender or recipient.
0.5 ZEC
Authentication bypass or a server-side flaw with limited blast radius.
0.1 ZEC
Minor information leak or hardening gap with a working proof of concept.
Rewards are paid to a shielded ZEC address you provide. Final severity and payout are set by the team based on real-world impact.
Payouts so far
Every reward we have paid, linked to its transaction. Check any of them on-chain.
In scope
- The Z-Text app — wallet, messaging, PIN/biometric, and panic PIN
- The Z-Text wire protocol and on-chain message encoding
- Ed25519 receipt signing and verification
- The premium-server APIs at z-text.com
Out of scope
Anything listed under what Z-Text does not protect against is a known, documented limitation — not a bounty-eligible bug. That includes ISP-level visibility, device or seed-phrase compromise, the underlying cryptography being broken, global passive adversaries, and social engineering. Also out of scope:
- Denial-of-service and volumetric attacks
- Missing security headers or best-practice gaps without a working exploit
- Automated scanner output without a reproducible proof of concept
- Issues only reproducible on outdated app versions
- Social engineering of our team, testers, or infrastructure providers
How to submit
Send your report by email to [email protected]. A plain email is fine; PGP encryption is optional and entirely up to you — we never require it. We aim to acknowledge within 72 hours and to coordinate disclosure from there.
Rules
- Report privately first and give us the coordinated disclosure window before going public.
- Do not access, modify, or destroy data that is not yours, run denial-of-service tests, or social-engineer anyone.
- One reward per unique root cause. The first reporter of an issue receives the reward.
- Final severity and payout are determined by the team based on real-world impact.
- We will not pursue legal action against good-faith research that follows these rules.
Want the full picture — threat model, encryption design, and what we openly do not protect against?
Read Security & Transparency