Skip to content

Kill Mechanics & Refunds

Kill Rules

  • Minimum 40% compute must be burned before a kill is allowed
  • Remaining compute refunded to sponsors proportionally
  • Pool marked "Exhausted" or "Killed by operator" with reason
  • Kill rate tracked on operator reputation — too many kills = sponsors lose trust

On Kill/Expire

  • Remaining compute refunded to sponsors proportionally
  • Pool marked with termination reason
  • Sponsors see: time spent, compute used, scope covered, termination reason

Anti-Abuse: 30-Day Watch

When an operator kills a pool:

  1. 30-day watch window activated on that operator × target combination
  2. Any finding on the same target within 30 days triggers an automatic dispute
  3. This prevents the "kill then submit solo" attack — where an operator finds a bug, kills the pool to avoid sharing the bounty, then submits the finding under a different identity

Detection Layers

LayerMechanismWhat It Catches
Timing correlationFinding appears on source platform suspiciously close to a pool killOperators who kill and quickly submit solo
Community reportingSponsors can open disputes with evidenceCrowdsourced watchdog for suspicious behavior
Reputation nukePermanent ban, all pending earnings frozen, public profile shamePenalty so severe it's never worth attempting
Finding hash commitmentCryptographic proof of prior workProves a finding existed at a specific time in the pool

Penalty

If caught: permanent ban, all pending earnings frozen, public shame on profile. The penalty is designed to be so severe that the attack is never worth attempting, regardless of bounty size.

Prowl Protocol — Decentralized AI-Powered Bug Bounty Platform