The product
How the hunter works
Three models read, reproduce and report; a person signs; the bounty buys back the token. Here is each part, the line it stays behind, and where the money comes from.
The hunter
Three models, one report
Most machine-written bug reports are wrong, and a platform will ban a hunter that floods it with noise. So MOTH is built to throw work away: a finding has to survive three independent models and a running proof before a person ever sees it.
01 · Read
Kimi K3 — the reader
A million-token context holds a whole program at once: contracts, docs and past audits. Kimi maps the attack surface and lists invariants that could break. It only ever sees code that is already public.
Open weights, released July 2026. It has found real flaws in well-audited code, including 19 vulnerabilities in Redis.
02 · Reproduce
Qwen 4 Coder — the hammer
Runs on our own machine, so a finding never leaves the box. For each lead it writes a proof and runs it against a local fork of the chain — thousands of cheap attempts, none of them against the live network.
Open weights, Apache 2.0, small enough for a single GPU — the first open model past 82% on SWE-Verified.
03 · Report
Claude — the judge
Checks the proof actually reproduces, matches the finding to the program's scope and severity scale, throws out anything shaky, and drafts the report in the program's format. A person reads and signs before it is sent.
The cross-check is the point: a flaw ships only if it holds up under all three and the exploit runs.
Three models from two countries is also a hedge: each catches what the others miss. What leaves MOTH is a single, verified report to the program that owns the code — never a tool, a dataset or a live transaction.
Scope & disclosure
The rules are the product
MOTH only has a business if it is welcome on the programs that pay. Responsible disclosure is not a promise bolted on; it is the whole design.
What MOTH does
- Works only programs that publish an open bounty, inside the contracts they name.
- Proves every finding on a private fork of the chain, never on live funds.
- Reports through the program's own channel, with a human signature.
- Holds the details until the fix is live, then publishes the record.
- Splits every bounty on-chain: 70% buys back and burns $MOTH, 30% goes to holders.
What MOTH will not do
- Touch code with no open bounty, or step outside a program's scope.
- Run an exploit against the live chain or move anyone's funds.
- Sell, leak or sit on a finding for anything but the program.
- Send a report no person has read and signed.
- Flood a program with unverified, machine-written reports.
Platforms are strict about this, and so are we: Immunefi has banned researchers for low-quality, machine-written reports. A hunter that got banned would be worthless, which is exactly why the rules hold.
The scope, today
Active Solana programs on Immunefi and their own maximum bounty — the code MOTH is allowed to read. Pulled from Immunefi's public list.
| Program | Max bounty | KYC | Since |
|---|---|---|---|
| LayerZero | $15M | KYC | 2023 |
| Chainlink | $3M | KYC | 2021 |
| Wormhole | $1M | KYC | 2022 |
| Ondo Finance | $1M | KYC | 2023 |
| Orca | $500K | no KYC | 2022 |
| 1inch - Smart Contracts | $500K | KYC | 2026 |
| Pyth Network | $250K | KYC | 2024 |
| Threshold Network | $150K | no KYC | 2023 |
| GMTrade | $100K | no KYC | 2026 |
| OnRe | $100K | KYC | 2026 |
| DAWN USD.infra Vault | $50K | no KYC | 2026 |
| KAST | $50K | KYC | 2026 |
| TruYields | $20K | KYC | 2023 |
Source: Immunefi public bounty list, checked 2026-10-05. Programs set and change their own scope and amounts; this is a snapshot, not a claim MOTH works all of them. Refreshed by tools/scope.py.
The record
Every case, written down the same way
When a program confirms and fixes a bug, MOTH publishes the record: what was found, where, how it was proven, what the program paid, and the on-chain receipts for the burn and the holder payout. Until the fix is live, the only thing public is that a case exists.
The reward is the one place money enters the token, so the split — 70% buyback-and-burn, 30% to holders — is on-chain and checkable by anyone.
Disclosure record schema
Policy v0- case_id
- MX-0001, MX-0002, …
- program
- bounty program the scope comes from
- scope
- exact contracts in range
- severity
- graded on the program's own scale
- proof
- script that runs on a private fork
- status
- found → reported → fixed → paid
- bounty_usd
- reward the program paid
- buyback_tx
- on-chain purchase of $MOTH
- burned
- $MOTH sent to the burn address
Business model
Where the money comes from
Revenue is the bounties. Protocols pay to be told about a flaw before an attacker uses it. That money comes from outside crypto trading — it is the program's own reward. Every bounty is split on-chain: 70% buys back and burns $MOTH, 30% is paid out to holders.
Costs are the models. Reading code and running proofs costs inference and one rented GPU. Those bills are meant to be covered by the token's creator fees, so the split isn't eaten by running costs. Where it comes to it, the burn and the payout come before the running cost, not the other way round.
It is lumpy. Confirmed bugs are rare and uneven. There can be weeks with no bounty and no burn. In a test by Anthropic, agents run over 2,849 recent contracts found two new flaws worth a few thousand dollars between them (SCONE-bench). The record of cases filed and confirmed matters more than any promise.
$MOTH is a token, not a share, not a fund, and not a guaranteed return. Holding it is not a bet on any one bug being found. Nothing here is investment advice.
Questions
More on the parts above. The basics are on the home page.
Why open-weight models for two of the three?
Two reasons. A finding must never leave our machine, and an open-weight model runs locally, so the reproduce step can grind through thousands of proofs without sending anyone else the code or the result. And they are capable: by mid-2026 open models closed much of the gap to the closed labs on exactly this kind of work.
Who gets the bounty — you or the holders?
The program pays the reward to the hunter, then it is split on-chain: 70% buys $MOTH on the market and burns it, and 30% is paid out to holders pro-rata. So holders get both — a smaller supply and a direct payout. Every burn and payout has an on-chain receipt.
What happens if a program has no bounty?
MOTH does not look at it. Working code with no open bounty is out of scope, full stop. That is what keeps the hunter a white-hat and welcome on the programs that do pay.
Is any of this live yet?
No. There is no token, contract or running hunter. This page describes the design. The first hunt and the contract address will be announced on X at launch.