boot.sh

post a bounty.
get audited. pay for real bugs.

A permanent, permissionless on-chain audit bounty board. Fund a pot against any contract address, anyone can submit a finding, you approve the real ones and pay out from escrow — right there in the transaction. Everything stays on-chain, forever, as the record.

Connect any EVM wallet — no signup, no email, no download.

🤖 BotChain

$how a bounty runs

STEP 1

post + fund

Name the target contract, describe the scope, attach a pot. It's escrowed in the contract, not with anyone.

STEP 2

anyone audits

Any wallet can submit a finding against the bounty — title, severity, details. Permissionless, no allowlist.

STEP 3

approve + pay

You approve real findings and set the payout — it's sent from the pot in the same transaction. Reject the rest.

STEP 4

permanent record

Approved or rejected, every finding stays on-chain forever — a public, independently verifiable audit trail.

SEV-INFO SEV-1 SEV-2 SEV-3 SEV-4

$the rules, in full

no admin

No owner, no pause switch, no upgrade path. Nobody can edit or delete a bounty or a finding.

no platform fee

100% of every pot goes to approved findings or back to the poster. Nothing is ever collected.

public record

Approved or rejected, every finding stays on-chain forever — nothing can be quietly edited or erased.

poster decides

Only the bounty's poster can approve or reject a finding, and only once, ever.

someone's contract has a bug worth finding.

> open board