The product

How the hunter works

Three models read, reproduce and report; a person signs; the bounty buys back the token. Here is each part, the line it stays behind, and where the money comes from.

The hunter

Three models, one report

Most machine-written bug reports are wrong, and a platform will ban a hunter that floods it with noise. So MOTH is built to throw work away: a finding has to survive three independent models and a running proof before a person ever sees it.

01 · Read

Kimi K3 — the reader

A million-token context holds a whole program at once: contracts, docs and past audits. Kimi maps the attack surface and lists invariants that could break. It only ever sees code that is already public.

Open weights, released July 2026. It has found real flaws in well-audited code, including 19 vulnerabilities in Redis.

02 · Reproduce

Qwen 4 Coder — the hammer

Runs on our own machine, so a finding never leaves the box. For each lead it writes a proof and runs it against a local fork of the chain — thousands of cheap attempts, none of them against the live network.

Open weights, Apache 2.0, small enough for a single GPU — the first open model past 82% on SWE-Verified.

03 · Report

Claude — the judge

Checks the proof actually reproduces, matches the finding to the program's scope and severity scale, throws out anything shaky, and drafts the report in the program's format. A person reads and signs before it is sent.

The cross-check is the point: a flaw ships only if it holds up under all three and the exploit runs.

Three models from two countries is also a hedge: each catches what the others miss. What leaves MOTH is a single, verified report to the program that owns the code — never a tool, a dataset or a live transaction.

Scope & disclosure

The rules are the product

MOTH only has a business if it is welcome on the programs that pay. Responsible disclosure is not a promise bolted on; it is the whole design.

What MOTH does

  • Works only programs that publish an open bounty, inside the contracts they name.
  • Proves every finding on a private fork of the chain, never on live funds.
  • Reports through the program's own channel, with a human signature.
  • Holds the details until the fix is live, then publishes the record.
  • Splits every bounty on-chain: 70% buys back and burns $MOTH, 30% goes to holders.

What MOTH will not do

  • Touch code with no open bounty, or step outside a program's scope.
  • Run an exploit against the live chain or move anyone's funds.
  • Sell, leak or sit on a finding for anything but the program.
  • Send a report no person has read and signed.
  • Flood a program with unverified, machine-written reports.

Platforms are strict about this, and so are we: Immunefi has banned researchers for low-quality, machine-written reports. A hunter that got banned would be worthless, which is exactly why the rules hold.

The scope, today

Active Solana programs on Immunefi and their own maximum bounty — the code MOTH is allowed to read. Pulled from Immunefi's public list.

$21.7M in open bounties · 13 programs
ProgramMax bountyKYCSince
LayerZero$15MKYC2023
Chainlink$3MKYC2021
Wormhole$1MKYC2022
Ondo Finance$1MKYC2023
Orca$500Kno KYC2022
1inch - Smart Contracts$500KKYC2026
Pyth Network$250KKYC2024
Threshold Network$150Kno KYC2023
GMTrade$100Kno KYC2026
OnRe$100KKYC2026
DAWN USD.infra Vault$50Kno KYC2026
KAST$50KKYC2026
TruYields$20KKYC2023

Source: Immunefi public bounty list, checked 2026-10-05. Programs set and change their own scope and amounts; this is a snapshot, not a claim MOTH works all of them. Refreshed by tools/scope.py.

The record

Every case, written down the same way

When a program confirms and fixes a bug, MOTH publishes the record: what was found, where, how it was proven, what the program paid, and the on-chain receipts for the burn and the holder payout. Until the fix is live, the only thing public is that a case exists.

The reward is the one place money enters the token, so the split — 70% buyback-and-burn, 30% to holders — is on-chain and checkable by anyone.

Disclosure record schema

Policy v0
case_id
MX-0001, MX-0002, …
program
bounty program the scope comes from
scope
exact contracts in range
severity
graded on the program's own scale
proof
script that runs on a private fork
status
found → reported → fixed → paid
bounty_usd
reward the program paid
buyback_tx
on-chain purchase of $MOTH
burned
$MOTH sent to the burn address

Business model

Where the money comes from

Revenue is the bounties. Protocols pay to be told about a flaw before an attacker uses it. That money comes from outside crypto trading — it is the program's own reward. Every bounty is split on-chain: 70% buys back and burns $MOTH, 30% is paid out to holders.

Costs are the models. Reading code and running proofs costs inference and one rented GPU. Those bills are meant to be covered by the token's creator fees, so the split isn't eaten by running costs. Where it comes to it, the burn and the payout come before the running cost, not the other way round.

It is lumpy. Confirmed bugs are rare and uneven. There can be weeks with no bounty and no burn. In a test by Anthropic, agents run over 2,849 recent contracts found two new flaws worth a few thousand dollars between them (SCONE-bench). The record of cases filed and confirmed matters more than any promise.

$MOTH is a token, not a share, not a fund, and not a guaranteed return. Holding it is not a bet on any one bug being found. Nothing here is investment advice.

Questions

More on the parts above. The basics are on the home page.

Why open-weight models for two of the three?

Two reasons. A finding must never leave our machine, and an open-weight model runs locally, so the reproduce step can grind through thousands of proofs without sending anyone else the code or the result. And they are capable: by mid-2026 open models closed much of the gap to the closed labs on exactly this kind of work.

Who gets the bounty — you or the holders?

The program pays the reward to the hunter, then it is split on-chain: 70% buys $MOTH on the market and burns it, and 30% is paid out to holders pro-rata. So holders get both — a smaller supply and a direct payout. Every burn and payout has an on-chain receipt.

What happens if a program has no bounty?

MOTH does not look at it. Working code with no open bounty is out of scope, full stop. That is what keeps the hunter a white-hat and welcome on the programs that do pay.

Is any of this live yet?

No. There is no token, contract or running hunter. This page describes the design. The first hunt and the contract address will be announced on X at launch.