An AI hunts bugs. You hold the burn.

MOTH is an AI that finds bugs in crypto apps before hackers do, and claims the reward those apps pay. Most of every reward burns $MOTH; the rest is paid straight to holders.

Pre-launch. No token, no contract yet; the hunter is being built in the open.

A 3D render of a moth, wings spread, lit from above by a warm lamp.

$MOTH

Solana
Contract address Published at launch

In plain words

What it does, and what you get

① The app

An AI that hunts bugs

Crypto apps pay big rewards to anyone who finds a flaw before a hacker does — up to millions. MOTH is an AI that reads their code, finds the flaw, proves it, and claims that reward.

② Your reward

Every bug burns the coin

70% of every reward buys $MOTH and burns it. 30% is paid straight to holders. Each bug caught = buys pushing the price, supply gone for good, and a payout to your wallet. No claim button — you just hold.

③ The proof

Receipts, not promises

Every burn and every payout has a receipt onchain, and the board of caught bugs is public. You can check each one yourself. Nothing is "trust me".

The money is real and comes from outside crypto gambling: it is the reward the app itself puts up for its own bug. See where the money comes from

Case MX‑0007 Critical Sample
Program
A lending market on Solana name withheld until fixed
Class
Oracle rounding lets a position borrow past its collateral
  1. Day 0 · 14:02 UTC

    Flaw locatedReader model flags an invariant on the public code

  2. Day 0 · 15:40 UTC

    Proof on a private forkExploit script moves funds against a local snapshot, never mainnet

  3. Day 0 · 17:15 UTC

    Reported through the programSubmitted on the protocol's own bounty, with a human signature

  4. Day 5

    Confirmed and fixedPatch deployed; details stay sealed until then

  5. Day 9

    Bounty paid → burn + payout70% buys and burns $MOTH, 30% is paid out to holders

Illustration. No real program; the figures below are placeholders for the record MOTH will publish per case.

A sample case

One bug, start to finish

MOTH only looks at programs that publish a bounty, and only inside the scope they set. A flaw is proven on a private fork, reported through the program, and published after it is fixed. The reward is the only money that reaches the token — then it is split 70% burn, 30% to holders.

Bounty paid
$180,000
Burned (70%)
$126,000 of $MOTH
To holders (30%)
$54,000
Disclosure
published after the fix

Under the hood

Read, reproduce, report

For the curious: how the hunter turns a line of code into a paid bounty. The full version is on the product page.

  1. 01

    Read

    A long-context model reads a program's public code, docs and past audits and lists the places an invariant could break. It only ever sees code that is already public.

  2. 02

    Reproduce

    A second model, running on our own machine, writes a proof for each lead and runs it against a local fork of the chain. Nothing touches the live network, and a finding never leaves the box.

  3. 03

    Report

    A third model checks the proof reproduces, matches it to the program's scope and severity, and drafts the report. A person signs before it is sent. Details are published only after the fix.

Disclosure record schema

Policy v0
case_id
MX-0001, MX-0002, …
program
bounty program the scope comes from
scope
exact contracts in range
severity
graded on the program's own scale
proof
script that runs on a private fork
status
found → reported → fixed → paid
bounty_usd
reward the program paid
buyback_tx
on-chain purchase of $MOTH
burned
$MOTH sent to the burn address

Why it matters

Someone pays for the bug. Today it is the attacker.

September 2026 was the worst month of the year for crypto, with about $766 million lost to hacks. The flaws were in the code the whole time; an attacker found them first.

Protocols already pay to be told first. HackerOne programs paid out $81 million in bounties over a year, and Immunefi has paid white-hats more than $100 million, with single payouts up to $10 million.

And the best hunter is already a machine. In 2025 an autonomous agent, XBOW, reached the top of HackerOne's US leaderboard. MOTH points that work at programs that pay, and sends every reward back into the token.

On Solana alone, 13 programs post $21.7M in open bounties on Immunefi right now. The full list is on the product page.

Scope

A white-hat, by rule

MOTH is built to be welcome on the programs it works. The scope is the product; a hunter that broke it would be banned and worthless.

What MOTH does

  • Works only programs that publish an open bounty, and only the contracts in their stated scope.
  • Proves every finding on a private fork of the chain, never on live funds.
  • Reports through the program's own channel, with a human signature before anything is sent.
  • Publishes the details only after the fix is live.
  • Splits every bounty on-chain: 70% buys back and burns $MOTH, 30% goes to holders.

What MOTH will not do

  • Touch a contract that has no open bounty, or step outside a program's scope.
  • Run an exploit against the live chain or move anyone's funds.
  • Sell, leak or hold a finding back for anything other than the program.
  • Submit a report a person has not read and signed.
  • Flood a program with unverified, machine-written noise.

Two ways to take part

Holders

Hold $MOTH. Every bounty is split on-chain: 70% buys the token and burns it, 30% is paid out to holders. Each confirmed bug lifts the floor and pays the bag — every burn and payout has a receipt.

How the money moves

Protocols

If your program has an open bounty, MOTH is another white-hat reading your code inside your scope. If you want it pointed at you first, or kept away, say so and we will honour it. A report always comes through your channel.

Reach us on X

The contract address and the first hunt will be announced on X first. Follow @mothbounty

For machines

Built to be read by agents, not just people

More and more, the thing deciding whether to hold a token is an agent, not a human — and an agent prices what it can verify. So MOTH's facts are machine-readable, not buried in copy:

  • /llms.txt — a plain-text brief: what it is, the 70/30 split, the scope, the boundaries.
  • /moth.json — a JSON manifest: the live Solana bounty scope and the reward split, as data.
  • /sitemap.xml plus schema.org structured data embedded in every page.
  • At launch — every buyback, burn and holder payout as an on-chain receipt, and a public board of caught bugs.

No hype to parse. An agent can read the thesis, check the numbers, and watch the receipts — and decide on facts.

Questions

Short answers about the hunter, the token and the line it stays behind.

Is this a white-hat or a grey one?

White-hat, by rule. MOTH only works programs that publish a bounty, only inside their stated scope, and only proves findings on a private fork. Reports go through the program's own channel with a human signature, and details are held until the fix is live. A hunter that broke those rules would be banned from the programs that pay, which is the whole business.

How are holders paid, and how much is burned?

When a program pays a bounty, it is split on-chain: 70% buys $MOTH on the open market and sends it to a burn address, and 30% is paid out to holders pro-rata. Both have on-chain receipts. There is nothing to split today: there is no token or contract yet, and the exact payout rail is set at launch.

Why three models, and why from different labs?

Different models catch and miss different things, and most machine-written reports are wrong. Three independent models from two countries read, reproduce and cross-check a finding, so only a flaw that holds up under all of them, with a proof that runs, reaches a human for sign-off. It is there to cut false reports, not to write more of them.

Could the hunter be used to attack instead?

The findings are the most sensitive thing MOTH holds, so they never leave our own machine and are only ever sent to the program that owns the code. MOTH runs no transactions against the live chain. The rules on the scope page are what the product is; breaking them would end it.

Can I take part today?

Not yet. There is no token, no contract and no live hunter. This site describes what is being built. The contract address and the first hunt will be published here and on X at launch.