An AI hunts bugs. You hold the burn.
MOTH is an AI that finds bugs in crypto apps before hackers do, and claims the reward those apps pay. Most of every reward burns $MOTH; the rest is paid straight to holders.
Pre-launch. No token, no contract yet; the hunter is being built in the open.
In plain words
What it does, and what you get
① The app
An AI that hunts bugs
Crypto apps pay big rewards to anyone who finds a flaw before a hacker does — up to millions. MOTH is an AI that reads their code, finds the flaw, proves it, and claims that reward.
② Your reward
Every bug burns the coin
70% of every reward buys $MOTH and burns it. 30% is paid straight to holders. Each bug caught = buys pushing the price, supply gone for good, and a payout to your wallet. No claim button — you just hold.
③ The proof
Receipts, not promises
Every burn and every payout has a receipt onchain, and the board of caught bugs is public. You can check each one yourself. Nothing is "trust me".
The money is real and comes from outside crypto gambling: it is the reward the app itself puts up for its own bug. See where the money comes from
Day 0 · 14:02 UTC
Flaw locatedReader model flags an invariant on the public code
Day 0 · 15:40 UTC
Proof on a private forkExploit script moves funds against a local snapshot, never mainnet
Day 0 · 17:15 UTC
Reported through the programSubmitted on the protocol's own bounty, with a human signature
Day 5
Confirmed and fixedPatch deployed; details stay sealed until then
Day 9
Bounty paid → burn + payout70% buys and burns $MOTH, 30% is paid out to holders
Illustration. No real program; the figures below are placeholders for the record MOTH will publish per case.
A sample case
One bug, start to finish
MOTH only looks at programs that publish a bounty, and only inside the scope they set. A flaw is proven on a private fork, reported through the program, and published after it is fixed. The reward is the only money that reaches the token — then it is split 70% burn, 30% to holders.
- Bounty paid
- $180,000
- Burned (70%)
- $126,000 of $MOTH
- To holders (30%)
- $54,000
- Disclosure
- published after the fix
Under the hood
Read, reproduce, report
For the curious: how the hunter turns a line of code into a paid bounty. The full version is on the product page.
-
01
Read
A long-context model reads a program's public code, docs and past audits and lists the places an invariant could break. It only ever sees code that is already public.
-
02
Reproduce
A second model, running on our own machine, writes a proof for each lead and runs it against a local fork of the chain. Nothing touches the live network, and a finding never leaves the box.
-
03
Report
A third model checks the proof reproduces, matches it to the program's scope and severity, and drafts the report. A person signs before it is sent. Details are published only after the fix.
Disclosure record schema
Policy v0- case_id
- MX-0001, MX-0002, …
- program
- bounty program the scope comes from
- scope
- exact contracts in range
- severity
- graded on the program's own scale
- proof
- script that runs on a private fork
- status
- found → reported → fixed → paid
- bounty_usd
- reward the program paid
- buyback_tx
- on-chain purchase of $MOTH
- burned
- $MOTH sent to the burn address
Why it matters
Someone pays for the bug. Today it is the attacker.
September 2026 was the worst month of the year for crypto, with about $766 million lost to hacks. The flaws were in the code the whole time; an attacker found them first.
Protocols already pay to be told first. HackerOne programs paid out $81 million in bounties over a year, and Immunefi has paid white-hats more than $100 million, with single payouts up to $10 million.
And the best hunter is already a machine. In 2025 an autonomous agent, XBOW, reached the top of HackerOne's US leaderboard. MOTH points that work at programs that pay, and sends every reward back into the token.
On Solana alone, 13 programs post $21.7M in open bounties on Immunefi right now. The full list is on the product page.
Scope
A white-hat, by rule
MOTH is built to be welcome on the programs it works. The scope is the product; a hunter that broke it would be banned and worthless.
What MOTH does
- Works only programs that publish an open bounty, and only the contracts in their stated scope.
- Proves every finding on a private fork of the chain, never on live funds.
- Reports through the program's own channel, with a human signature before anything is sent.
- Publishes the details only after the fix is live.
- Splits every bounty on-chain: 70% buys back and burns $MOTH, 30% goes to holders.
What MOTH will not do
- Touch a contract that has no open bounty, or step outside a program's scope.
- Run an exploit against the live chain or move anyone's funds.
- Sell, leak or hold a finding back for anything other than the program.
- Submit a report a person has not read and signed.
- Flood a program with unverified, machine-written noise.
Two ways to take part
Holders
Hold $MOTH. Every bounty is split on-chain: 70% buys the token and burns it, 30% is paid out to holders. Each confirmed bug lifts the floor and pays the bag — every burn and payout has a receipt.
How the money movesProtocols
If your program has an open bounty, MOTH is another white-hat reading your code inside your scope. If you want it pointed at you first, or kept away, say so and we will honour it. A report always comes through your channel.
Reach us on XThe contract address and the first hunt will be announced on X first. Follow @mothbounty
For machines
Built to be read by agents, not just people
More and more, the thing deciding whether to hold a token is an agent, not a human — and an agent prices what it can verify. So MOTH's facts are machine-readable, not buried in copy:
/llms.txt— a plain-text brief: what it is, the 70/30 split, the scope, the boundaries./moth.json— a JSON manifest: the live Solana bounty scope and the reward split, as data./sitemap.xmlplus schema.org structured data embedded in every page.- At launch — every buyback, burn and holder payout as an on-chain receipt, and a public board of caught bugs.
No hype to parse. An agent can read the thesis, check the numbers, and watch the receipts — and decide on facts.
Questions
Short answers about the hunter, the token and the line it stays behind.
Is this a white-hat or a grey one?
White-hat, by rule. MOTH only works programs that publish a bounty, only inside their stated scope, and only proves findings on a private fork. Reports go through the program's own channel with a human signature, and details are held until the fix is live. A hunter that broke those rules would be banned from the programs that pay, which is the whole business.
How are holders paid, and how much is burned?
When a program pays a bounty, it is split on-chain: 70% buys $MOTH on the open market and sends it to a burn address, and 30% is paid out to holders pro-rata. Both have on-chain receipts. There is nothing to split today: there is no token or contract yet, and the exact payout rail is set at launch.
Why three models, and why from different labs?
Different models catch and miss different things, and most machine-written reports are wrong. Three independent models from two countries read, reproduce and cross-check a finding, so only a flaw that holds up under all of them, with a proof that runs, reaches a human for sign-off. It is there to cut false reports, not to write more of them.
Could the hunter be used to attack instead?
The findings are the most sensitive thing MOTH holds, so they never leave our own machine and are only ever sent to the program that owns the code. MOTH runs no transactions against the live chain. The rules on the scope page are what the product is; breaking them would end it.
Can I take part today?
Not yet. There is no token, no contract and no live hunter. This site describes what is being built. The contract address and the first hunt will be published here and on X at launch.