BERTOpen dApp

Important

This is an active test environment.

BERT runs on Arc Testnet while we validate security, economics and UX before mainnet. Testnet USDC, ETH and every displayed testnet balance are for testing only. Do not treat them as redeemable assets or rely on the testnet for production activity.

Before you start

What is real, and what can change.

Real testnet execution

Wallet signatures, USDC approvals, Community roles, votes, settlements, Treasury requests and validator rewards are sent to deployed Arc Testnet contracts.

Testnet conditions

Deployments, settings, indexers and testnet balances can be reset or changed during development. Record transaction hashes when reporting unexpected behavior.

PoP is required

BERT uses World ID proof-of-personhood to issue a short-lived on-chain verification signature. Verify before attempting protected actions such as creating an idea or voting.

Help harden BERT

If something behaves incorrectly, reproduce it on testnet first and report it privately. Do not exploit a weakness beyond the minimum proof needed to demonstrate impact.

World ID Simulator

Complete verification without scanning a QR code.

For the staging World App, click Start verification in BERT and use the browser simulator. A physical World App or QR scan is not required for this testnet flow.

  1. 1

    Open the simulator

    When World ID opens, select “Use simulator” rather than scanning the displayed QR code.

  2. 2

    Use the correct proof

    In the simulated phone flow choose World ID v3, then choose the Device credential.

  3. 3

    Approve once

    Finish the simulator flow and return to BERT. Keep the wallet connected to the same address that started verification.

  4. 4

    Retry cleanly if needed

    If the widget reports duplicate_nonce, refresh BERT and start a new verification. Do not retry within the same old modal.

Why v3 + Device? The current BERT staging integration verifies this credential path. Selecting World ID v4 in the simulator does not match the active staging proof flow and will be rejected by the host application.

Testnet bug bounty

Help find the issue before mainnet.

BERT welcomes responsible reports for the open core contracts, V3 Community Layer, backend verification service and frontend integration. Public source code is intentional: security must survive review, not depend on hiding implementation details.

In scope

  • Smart-contract access control, accounting, upgrade and state-machine flaws.
  • V2/V3 business logic, Treasury, voting, settlement and reward defects.
  • Backend proof validation and signature integration.
  • Frontend defects that misrepresent on-chain state or enable an unsafe flow.

Out of scope

  • Known, duplicate or purely theoretical reports without a reproduction.
  • Social engineering, phishing, denial of service, spam or third-party service issues.
  • Testnet token value claims and reports that require harming other users.
  • Reports containing copied secrets, personal data or public exploit details.

Reward: an initial Validator seat

For a confirmed, previously unknown and responsibly disclosed high-impact report before mainnet launch, BERT may include the researcher's wallet in initialValidators when the official BERT Community is deployed. It is not an immediate cash payment or transferable asset, and remains subject to available seats and conduct requirements. After the Community is live, new Validators must follow the standard on-chain eligibility path.

Open full program and report form

Private disclosure only

Send a reproducible report.

Use a GitHub Private Security Advisory. Include the affected repository and component, preconditions, exact reproduction steps, expected and actual behavior, impact, transaction hashes or screenshots, and a proposed mitigation if you have one.