Islamic Finance Principles Assessment
Riba — Does Bitsec.ai involve interest?
Bitsec.ai does not appear to involve interest-based lending, borrowing, or fixed-rate income in its core design. Its revenue model rests on audit contests, bug bounties, and a scanning service sold to other protocols — all service-based, not interest-based. For Muslim investors, the absence of riba in the base protocol is a positive, though the staking-reward structure warrants closer reading below.
Assessment: Moderate Riba
Score: 69/100
Our methodology examines 10 criteria to evaluate how well Bitsec.ai avoids interest-based mechanisms.
Bitsec's stated revenue sources — audit contests, bug bounty payouts, and subscriptions to its "Bitsec Scanner" service — are fee-for-service in nature, not interest income from loans or treasury holdings. No lending, borrowing, or interest-bearing reserve activity is described anywhere in the available material. The DeFi lending/interest-rate references that surface in broader searches (Aave, Compound) concern unrelated third-party protocols, not Bitsec itself. On the information available, the project's income model is consistent with permissible fee-based commerce rather than riba-based finance.
Rewards to miners and validators are distributed through Bittensor's Yuma Consensus based on agent performance against SCA-Bench — a variable, output-linked mechanism rather than a fixed or guaranteed rate resembling interest. This performance-based structure is a meaningfully more permissible design than a fixed-yield staking product, since payouts fluctuate with genuine contribution quality. A "burn uid" mechanism can render a portion of incentive permanently inaccessible, which reduces speculative reward inflation. However, SN60-specific staking terms (lock-ups, custodial status, slashing) are not documented, so the contract classification cannot be fully verified.
Gharar — How much uncertainty does Bitsec.ai involve?
Bitsec.ai carries a moderate degree of uncertainty, concentrated less in what the protocol does and more in what remains undisclosed about it. Open-source code and public scoring logs reduce ambiguity, but the lack of a named third-party audit and unclear tokenomics increase it. On balance, this is a project with real transparency in some areas and real gaps in others.
Assessment: Moderate Gharar (Material Uncertainty)
Score: 55.4/100
Our methodology examines 15 criteria including team transparency, audit quality, and governance.
The team is named, not anonymous: John Yu is identified as founder with a cited 13-year crypto background, and Greg Schwartz as Senior AI Engineer with a Stanford CS master's. The project's code is open-source on GitHub, and after each round, agent code, scores, and logs are made public — a strong transparency practice. Some search noise exists from unrelated companies also named "Bitsec," but this does not implicate the subnet itself. No fraud, hack, or regulatory action specific to Bitsec.ai/SN60 appears in the sources.
No named, reputable third-party audit firm (such as Halborn or Trail of Bits, both of which appear in the sources only in connection with unrelated projects) has reviewed Bitsec/SN60. The project's own site displays an "Audit Report Details" page citing 14,825 lines of code and 9 open, 0 resolved findings, but without an identified auditor or methodology. This should be named plainly as a gharar concern: an unaudited protocol carries elevated uncertainty regardless of its stated utility, and tokenomics details (distribution, vesting, pre-mine) are also undocumented despite a tracker page existing.
Maysir — Does Bitsec.ai involve gambling or speculation?
Bitsec.ai does not resemble a gambling or zero-sum speculative structure at the protocol level; it is built around a genuine service — AI-driven vulnerability scanning — with cited results of over $275 million in vulnerabilities found across real codebases. The core design channels rewards toward productive security work rather than chance-based payout. As with any listed token, secondary-market speculation can occur, but that is a matter of third-party trading behavior, not the protocol's own design.
Assessment: Moderate Maysir (High Risk)
Score: 65.5/100
Our methodology examines 11 criteria to determine whether Bitsec.ai is a gambling instrument or a genuine economic tool.
Bitsec/SN60 coordinates miners submitting AI agents that hunt for code and smart-contract vulnerabilities, evaluated by validators against a defined benchmark (SCA-Bench). Reported outcomes include identifying over $275 million in vulnerabilities across real codebases, and the team is pursuing revenue through audit contests, bug bounties, and a scanning service sold to other subnets and protocols. This is tangible, productive utility — closer to a security-auditing business than a speculative instrument — and such genuine output-linked activity is what distinguishes the protocol from maysir-type structures where outcomes depend purely on chance.
Weighed against this utility, the token still trades on open markets (one tracker cites $1.41M in 24h volume), and like any tradable crypto asset it can attract short-term speculative behavior from secondary buyers. This third-party trading conduct, however, does not reflect the protocol's own design, which is oriented toward performance-based rewards for genuine security work rather than chance-driven payout. The bigger practical caution for investors is less about gambling-like design and more about the documentation gaps noted elsewhere — undisclosed tokenomics and the absence of an independent audit — which merit care before participation.
The Full 27-Point Screening
1. Legitimacy (4 criteria)
| Criterion | Score | Analysis |
|---|
| Team Transparency | 60/100 | Official channels name a credentialed founder and engineer, but unrelated LinkedIn profiles under the same "Bitsec" name introduce ambiguity not resolved by the sources. |
| Fraud & Scam Risk | 70/100 | No fraud, hack or regulatory action tied specifically to this project appears in the sources, though this is an absence-of-evidence signal rather than a confirmed clean record. |
| Use Case Legitimacy | 85/100 | Sources describe concrete AI-driven vulnerability detection with cited findings worth $275m+, indicating genuine functional utility rather than pure hype. |
| Ethical Practices | 90/100 | The protocol's own stated purpose is cybersecurity/code-auditing, a sector with no inherent Shariah concern. |
Summary: The core team behind Bitsec/SN60 is named and credentialed on official channels, though unrelated same-named entities elsewhere create some identification ambiguity, and no fraud or regulatory action against this specific project is reported.
2. Project Operations (9 criteria)
| Criterion | Score | Analysis |
|---|
| Core Protocol Business | 90/100 | The base protocol is an AI security-auditing subnet, not situated in any prohibited sector. |
| Transaction Fees | 65/100 | A Bittensor-level burn mechanism removes incentive from circulation rather than extracting it for insiders, but SN60-specific fee schedules are not detailed. |
| Treasury Assets | 45/100 (low evidence) | The sources do not describe the treasury's composition or holdings, so interest-bearing exposure cannot be ruled in or out. |
| Revenue Model | 85/100 | Revenue is described as coming from audit contests, bug bounties and scanning fees, all service-based rather than interest-based. |
| Transparency | 85/100 | Code is hosted openly on GitHub and agent code/scores are published publicly after each evaluation round. |
| Governance | 40/100 | Control appears concentrated with the subnet owner/team (e.g., burn-key control); no decentralized holder-governance process is described. |
| Launch Fairness | 55/100 | The project is described as an organic solo-founder launch with no marketing budget, but no pre-mine or initial-sale details are given either way. |
| Token Distribution | 40/100 (low evidence) | A tokenomics/vesting tracker page is referenced but its content (allocations, cliffs, vesting) is not provided in the sources. |
| Speculation/Utility Ratio | 70/100 | Qualitative descriptions emphasize a working security product over speculative narrative, but no quantitative usage-vs-trading data is given. |
Summary: Bitsec operates as an open-source Bittensor subnet where AI agents compete to find code vulnerabilities, with performance-based reward distribution and a burn mechanism, though governance is team-centralized and full launch/distribution details are not available.
3. Financial Health (4 criteria)
| Criterion | Score | Analysis |
|---|
| Protocol Revenue | 85/100 | Stated revenue streams (bounties, audit contests, scanning) are service fees, not riba-based income. |
| Financial Status | 50/100 | Only a single trading-volume data point is available; no broader financial statements or stability record are present. |
| Interest Assessment | 90/100 | The protocol functions as a code-auditing subnet with no lending, borrowing or interest mechanism described at the protocol level. |
| Audit Quality | 30/100 | An internal audit report page exists showing findings counts, but no named reputable external audit firm or date is confirmed for Bitsec itself. |
Summary: Revenue is described as service-fee based (bounties, audit contests, scanning) with no lending/interest activity at the protocol level, but no confirmed independent, named security audit of Bitsec itself and limited financial disclosure were found.
4. Token Economics (5 criteria)
| Criterion | Score | Analysis |
|---|
| Token Purpose | 75/100 | The token is tied to a described utility function (security-agent network participation) though deeper token-economic detail is not given. |
| Governance Rights | N/A | No holder-governance voting mechanism is described; the absence of such a feature is not inherently a Shariah concern. |
| Rewards Distribution | 75/100 | Rewards to miners/validators are described as performance-based via consensus scoring rather than fixed, though token-holder-level reward mechanics are not detailed. |
| Speculation Controls | 45/100 | A burn mechanism limits some circulating incentive, but no broader anti-speculation design (limits, vesting enforcement) is documented. |
| Asset Backing | 55/100 | Value is tied to described utility/service revenue rather than any reserve-asset backing, per the available information. |
Summary: The token is positioned around genuine security-service utility with performance-based, non-fixed rewards, but holder governance rights, anti-speculation design details, and asset backing are largely undocumented in the sources.
5. Staking Mechanism (5 criteria)
| Criterion | Score | Analysis |
|---|
| Mechanism Type | 50/100 | General Bittensor staking/delegation into subnets is implied, but SN60-specific lock-up and custody terms are not documented in the sources. |
| Islamic Contract Classification | 35/100 (low evidence) | The sources give no basis to classify the reward/staking mechanism under any Islamic contract framework. |
| Rewards Structure | 65/100 | Rewards are tied to agent-performance scoring rather than a fixed rate, but token-holder-level staking reward mechanics specific to SN60 are not detailed. |
| Documentation | 40/100 | Documentation covers miner/validator setup and incentive mechanics generally, but no dedicated staking terms/risk disclosure for token holders is found. |
| Shariah Alignment | 35/100 (low evidence) | The sources leave the core Shariah question about any staking-like reward unaddressed, so no resolution can be reported. |
Summary: A general Bittensor-style staking/delegation mechanism appears to exist with performance-linked rewards, but SN60-specific lock-up terms, custody status, and Islamic contract classification are not established in the available sources.
Overall Assessment: Bitsec/SN60 presents as a genuine, utility-driven AI security-auditing subnet rather than a meme coin, but several Shariah-relevant details — treasury composition, named third-party audits, token distribution/vesting, and staking documentation — could not be confirmed from the available sources.