Skip to main content

Get Atto / Contributions

Make Atto better.
Get rewarded.

Useful pull requests can qualify for ATTO rewards. Improve the code, documentation, integrations, or experience, then work with maintainers to get the change reviewed.

Opening a PR does not guarantee a merge or a reward. For larger work, check in first through an issue, discussion, or draft PR.

The pull request path

  1. ReviewUseful work, reviewed by maintainers.
  2. Tier labelThe reward decision, before merge.
  3. MergeThe accepted contribution lands.
  4. RewardATTO is sent automatically.
For PRs accepted for reward. Critical security reports follow the separate private process below.

Useful work.
Clear reward tiers.

Maintainers assign a tier before merge when a PR is accepted for reward. The label is the reward decision.

Critical vulnerability
1,500,000ATTO
Private report of an urgent security issue that could threaten users, funds, or core network safety.
Epic PR
1,500,000ATTO
Large accepted project with broad impact across one or more repositories.
Major PR
400,000ATTO
Meaningful accepted feature, integration, refactor, documentation project, or fix.
Minor PR
100,000ATTO
Smaller accepted improvement, bug fix, documentation update, test, or tool change.
Tweak PR
20,000ATTO
Small accepted cleanup, copy fix, UI polish, optimization, or maintenance change.

Amounts are guidelines and may change over time. If amounts change, maintainers consider when the tier label was assigned or the private security report was acknowledged.

The tier can depend on impact, difficulty, completeness, review effort, and usefulness to the project. Read the full tier policy →

What qualifies.
And what does not.

Normal rewards are considered for useful PRs. Reports and suggestions are appreciated, but do not qualify by themselves.

Work that can qualify

  • Code changes and feature work
  • Bug fixes submitted as pull requests
  • Tests, tooling, CI, examples, and developer-experience improvements
  • Documentation, tutorials, and integration guides
  • Wallet, UI, or UX improvements
  • Useful ecosystem work connected to Atto repositories

Not reward-eligible by itself

  • Ordinary bug reports
  • Feature requests or product suggestions
  • Issue comments, Discord messages, or informal feedback
  • Duplicate work
  • Abandoned or unmerged PRs
  • Generated, low-effort, or noisy changes
  • Public disclosure of security vulnerabilities before private review

If a bug report becomes an accepted fix PR, the PR may qualify. Critical vulnerabilities are the only report-only exception: use the private security process.

From a useful change.
To a labeled, merged PR.

Maintainers may decide that work is not a good fit, needs a different approach, or falls outside current project priorities.

  1. 01 / CHOOSE

    Pick useful work.

    Improve Atto for users, developers, or operators. For larger work, discuss the direction first through an issue, discussion, or draft PR.

  2. 02 / REVIEW

    Open a PR and work through review.

    Use the relevant Atto repository. Explain what changed and why it matters, then respond to maintainer feedback.

  3. 03 / MERGE

    Receive a tier before merge.

    If the contribution qualifies, maintainers add its reward-tier label before merging. After the labeled PR is merged, the ATTO reward is sent automatically.

Found a vulnerability?
Keep the report private.

Critical vulnerabilities are the only report-only exception. Do not open a public issue or pull request for security vulnerabilities.

Private review comes first.

To qualify for the critical vulnerability tier, report privately through GitHub Security Advisories, wait for the team to acknowledge the report, and do not share details publicly until the issue is addressed.

Report privately

A useful contribution.
A place to start.

Find the repository your change belongs in and check the reward policy before beginning.