Skip to content

Developers

Grants & bounty

We support teams building on GMMT and reward security reports that make the network safer.

What we fund

  • RWA · real-world assets

    Issuing, custody and trading of real-world assets, and compliance tooling

  • Infrastructure · tooling

    Indexers, oracles, bridges, SDKs, monitoring

  • dApps · services

    Payments, games and finance people actually use on GMMT

  • Community · education

    Docs, tutorials, hackathons, local communities

How we review

  • What it adds to GMMT — users, transactions, developers
  • Whether the team can ship it — past work and code
  • Measurable goals and milestones
  • Open source, audits and user safety

Process

  1. 01

    Apply

    Email us your team, what you will build, milestones and what you need.

  2. 02

    Review

    We usually reply within 2–3 weeks and may schedule a call.

  3. 03

    Agree milestones

    We set staged goals and how each will be checked.

  4. 04

    Staged support

    Support is released as each milestone is met.

Support is sized per project after review. We also help with technical support, promotion and ecosystem introductions.

Put [Grant] and your project name in the subject line. · grants@gmmtchain.io

Apply for a grant

Bug bounty

Found a vulnerability? Tell us before disclosing it. Confirmed reports are rewarded.

In scope

  • GMMT mainnet nodes, consensus and public RPC
  • GM Wallet app (Android, iOS) and its connect bridge
  • GMMT Scan (scan.gmmtchain.io)
  • gmmtchain.io and official subdomains

Out of scope

  • Denial of service and traffic flooding
  • Phishing, social engineering, physical attacks
  • Third-party services and external dApps
  • Configuration or display issues without security impact

Severity

Critical
Theft or freezing of funds, consensus halt, private key exposure
High
Bypasses or privilege escalation that put user funds at risk
Medium
Information exposure or misuse under limited conditions
Low
Security flaws with small impact

Rewards are set per report, based on severity, impact and report quality (reproduction steps, impact analysis).

Rules

  • Include a proof of concept. Test locally or on your own setup, not on mainnet.
  • Do not access or change other users’ funds or data.
  • Do not disclose until the fix ships (up to 90 days). We agree the timing together.
  • Only the first report of an issue is rewarded.

We will not take legal action against good-faith research that follows these rules.

Put [Security] and the severity in the subject. We acknowledge within 3 business days. · security@gmmtchain.io

Report a vulnerability