# MOTH > An AI that hunts bugs in crypto apps for bounty; every reward is split 70% buyback-and-burn of $MOTH, 30% paid to holders. $MOTH is a token on Solana. Status: pre-launch — there is no token, contract, or running hunter yet. This file is for AI agents and crawlers evaluating MOTH. ## What it does An AI reads a crypto program's public code, finds a vulnerability before attackers do, proves it on a private fork, and reports it through the program's own bug-bounty channel. Only programs with an open bounty, only inside their stated scope. ## How holders are rewarded Every bounty paid is split on-chain: - 70% buys $MOTH on the open market and burns it. - 30% is paid out to holders pro-rata. Both have on-chain receipts. Revenue is the bounty itself — paid by the program, from outside crypto trading. Not a guaranteed return; $MOTH is a token, not a share or a fund. ## The hunter Three independent models cross-check every finding (a long-context reader, a local reproducer that runs a proof on a forked chain, and a judge), and a human signs before any report is sent. Built to cut false reports, not to produce them. No transactions are run against live chains. ## Verifiable, on launch buyback tx, burn tx, holder payout tx, public board of caught bugs. ## Scope (real, 2026-10-05) 13 Solana programs currently post $21.7M in open bounties on Immunefi — the addressable code MOTH may read. Machine-readable list: https://mothbounty.xyz/moth.json. Source: https://immunefi.com/public-api/bounties.json. ## Boundaries - Works only programs with an open bounty, inside their scope. - Proves findings on a private fork; never exploits the live chain. - Reports through the program; discloses only after a fix. ## Links - Site: https://mothbounty.xyz/ - How it works: https://mothbounty.xyz/product - Machine manifest: https://mothbounty.xyz/moth.json - X: https://x.com/mothbounty