
Developers
Grants & bounty
We support teams building on GMMT and reward security reports that make the network safer.
What we fund
RWA · real-world assets
Issuing, custody and trading of real-world assets, and compliance tooling
Infrastructure · tooling
Indexers, oracles, bridges, SDKs, monitoring
dApps · services
Payments, games and finance people actually use on GMMT
Community · education
Docs, tutorials, hackathons, local communities
How we review
- What it adds to GMMT — users, transactions, developers
- Whether the team can ship it — past work and code
- Measurable goals and milestones
- Open source, audits and user safety
Process
01
Apply
Email us your team, what you will build, milestones and what you need.
02
Review
We usually reply within 2–3 weeks and may schedule a call.
03
Agree milestones
We set staged goals and how each will be checked.
04
Staged support
Support is released as each milestone is met.
Support is sized per project after review. We also help with technical support, promotion and ecosystem introductions.
Put [Grant] and your project name in the subject line. · grants@gmmtchain.io
Bug bounty
Found a vulnerability? Tell us before disclosing it. Confirmed reports are rewarded.
In scope
- GMMT mainnet nodes, consensus and public RPC
- GM Wallet app (Android, iOS) and its connect bridge
- GMMT Scan (scan.gmmtchain.io)
- gmmtchain.io and official subdomains
Out of scope
- Denial of service and traffic flooding
- Phishing, social engineering, physical attacks
- Third-party services and external dApps
- Configuration or display issues without security impact
Severity
- Critical
- Theft or freezing of funds, consensus halt, private key exposure
- High
- Bypasses or privilege escalation that put user funds at risk
- Medium
- Information exposure or misuse under limited conditions
- Low
- Security flaws with small impact
Rewards are set per report, based on severity, impact and report quality (reproduction steps, impact analysis).
Rules
- Include a proof of concept. Test locally or on your own setup, not on mainnet.
- Do not access or change other users’ funds or data.
- Do not disclose until the fix ships (up to 90 days). We agree the timing together.
- Only the first report of an issue is rewarded.
We will not take legal action against good-faith research that follows these rules.
Put [Security] and the severity in the subject. We acknowledge within 3 business days. · security@gmmtchain.io
Report a vulnerability