Real testnet execution
Wallet signatures, USDC approvals, Community roles, votes, settlements, Treasury requests and validator rewards are sent to deployed Arc Testnet contracts.
Important
BERT runs on Arc Testnet while we validate security, economics and UX before mainnet. Testnet USDC, ETH and every displayed testnet balance are for testing only. Do not treat them as redeemable assets or rely on the testnet for production activity.
Before you start
Wallet signatures, USDC approvals, Community roles, votes, settlements, Treasury requests and validator rewards are sent to deployed Arc Testnet contracts.
Deployments, settings, indexers and testnet balances can be reset or changed during development. Record transaction hashes when reporting unexpected behavior.
BERT uses World ID proof-of-personhood to issue a short-lived on-chain verification signature. Verify before attempting protected actions such as creating an idea or voting.
If something behaves incorrectly, reproduce it on testnet first and report it privately. Do not exploit a weakness beyond the minimum proof needed to demonstrate impact.
World ID Simulator
For the staging World App, click Start verification in BERT and use the browser simulator. A physical World App or QR scan is not required for this testnet flow.
When World ID opens, select “Use simulator” rather than scanning the displayed QR code.
In the simulated phone flow choose World ID v3, then choose the Device credential.
Finish the simulator flow and return to BERT. Keep the wallet connected to the same address that started verification.
If the widget reports duplicate_nonce, refresh BERT and start a new verification. Do not retry within the same old modal.
Why v3 + Device? The current BERT staging integration verifies this credential path. Selecting World ID v4 in the simulator does not match the active staging proof flow and will be rejected by the host application.
Testnet bug bounty
BERT welcomes responsible reports for the open core contracts, V3 Community Layer, backend verification service and frontend integration. Public source code is intentional: security must survive review, not depend on hiding implementation details.
For a confirmed, previously unknown and responsibly disclosed high-impact report before mainnet launch, BERT may include the researcher's wallet in initialValidators when the official BERT Community is deployed. It is not an immediate cash payment or transferable asset, and remains subject to available seats and conduct requirements. After the Community is live, new Validators must follow the standard on-chain eligibility path.
Private disclosure only
Use a GitHub Private Security Advisory. Include the affected repository and component, preconditions, exact reproduction steps, expected and actual behavior, impact, transaction hashes or screenshots, and a proposed mitigation if you have one.