← COHIBA

OPEN · PRE-MAINNET · INDEPENDENT EYES WANTED

BREAK IT
BEFORE MAINNET.

Most projects ask you to trust the launch. COHIBA is asking you to challenge it first. Review the assumptions, state machine, token invariants, recovery logic, evidence layer and privacy boundaries before anything irreversible happens.

Open / Review Issues ↗Full Scope ↗Security Evidence

What we want challenged

P0

Launch safety

Unauthorized launch, duplicate mint, concurrency, persistence and recovery.

P1

Token invariants

Exact supply, destination balance, immutable metadata and authority revocation.

P2

Evidence integrity

Can public claims drift away from source, CI or chain evidence?

P3/P4

Web, API & privacy

Origin/rate/path controls, malformed requests and aggregate analytics privacy.

Rules

Do not attack production availability, steal credentials, test third-party infrastructure outside its rules, or attempt Mainnet launch. Use static analysis, local testing and Devnet wherever possible. Sensitive findings should follow SECURITY.md rather than public exploit disclosure.

Recognition

Verified reviewers and contributors can receive public attribution, evidence-log credit, contributor spotlight and consideration for Builder/Trust Ambassador roles.

Financial bounty: no cash/token reward is promised until a funded amount and payment terms are publicly posted. We will not advertise an unfunded bounty.

What success looks like

External finding

A real weakness is found, reproduced and fixed.

External contribution

A useful test, patch, review or evidence improvement is merged.

Independent review

A qualified third party reviews a defined commit and scope.

Harder to fool

The project becomes more independently verifiable before Mainnet.

Start here

Independent Review Package ↗
Threat Model ↗
Verification Specification ↗
Evidence Log ↗

Share the review

X / TECH COMMUNITY

Bring adversarial eyes

Share the campaign with engineers and reviewers using the tracked X source.

Share on X ↗

OPEN SOURCE

Send engineers to scoped issues

Five review targets are already open so contributors can start immediately.

Open GitHub Issues ↗

SOLANA COMMUNITY

Technical discussion link

Use this tracked URL when sharing in relevant Solana engineering/community channels.

Solana-community link →

SECURITY RESEARCH

Independent review link

Use the dedicated source link for audit/security outreach.

Security-review link →

Mainnet remains locked

This campaign is a review campaign. It does not authorize Mainnet launch, liquidity creation or any irreversible token operation.