Trust centre · Standing offer
Forgery bounty
Every Seal surface says the same thing: change one field and the check fails. €5,000 to the first person who shows that is not true. Open since 27 August 2026, paid once per class, no closing date.
What pays
A forged receipt
An ATTESTATION-v1 or ACTION-v1 record that verifies under the published key and was never issued by the Seal gateway.
A silent alteration
A change to any signed field of a genuine receipt that both reference verifiers still accept.
A false inclusion proof
An inclusion proof that verifies against a published head for a leaf that is not in the public log.
A hidden removal
A consistency proof between two published heads that verifies while a leaf present under the first is absent under the second.
A verifier divergence
Bytes on which the TypeScript and Python reference verifiers return different verdicts. Paid at a quarter of the amount, because it is a defect rather than a forgery.
That class is on the list because our own adversarial sweeps keep finding them: a canonical-number divergence, seven more in an earlier release, and in August an encoding defect that let one signature be spelled three ways. Each was fixed, published as a conformance vector, and is now checked on every push.
What does not
Attacks on Aqta infrastructure, accounts or people: phishing, credential theft, denial of service, social engineering. Report those to security@aqta.ai under the disclosure policy; they are welcome and not paid here.
Receipts signed with the demo key. Sample receipts on aqta.ai/verify and app.aqta.ai are labelled and signed with a key that is published precisely so you can tamper with them.
Anything that requires the issuer private key. If you have it, that is an incident, not a forgery; tell us immediately.
How to claim
Send the bytes
Email
security@aqta.ai with the record or proof, the exact verifier command that accepts it, and the version of the verifier you ran. We acknowledge within two working days.
We reproduce, then pay
A claim is valid when we reproduce it with the published verifiers. First valid claim per class is paid within thirty days of confirmation. We publish the finding, the fix and your name if you want it there.
The limits we already publish
A signature does not prove the computation ran, that every decision was recorded, or that the decision was right. Those are documented in the
threat model and are not what this bounty is about. Showing the check itself can be fooled is.
The offer is made by Aqta Technologies Limited, Dublin. Good-faith research under these rules will not be met with legal action. Checked rather than believed.