Skip to content

Latest commit

 

History

29,827 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Alpenglow Bug Bounty Competition

Alpenglow is Solana's new consensus protocol. During development, monorepo migration and internal audit phases, the Alpenglow logic has been excluded from scope of the Agave bug bounty program. To mark its introduction to eligibility, we're hosting a bug bounty competition to raise awareness and catch standing issues that have evaded prior review efforts

  • Prize pool: up to 50,000 SOL
  • Submission window: 2026-08-05 16:00 UTC to 2026-08-19 16:00 UTC
  • How to submit: use the submission portal at https://alpenglow.anza.xyz/; sign in with GitHub, burn a non-refundable 0.5 SOL, and the portal files your finding as a GitHub Security Advisory on this repository, one finding per advisory. Submissions received through any other channel are ineligible
  • Full rules: RULES.md (scope, severity categories, rewards, eligibility, and duplicate policy)

Do not disclose a finding publicly (for example as a GitHub issue here or on agave), as public findings are ineligible for a reward. Any attempt to cheat the submission system or the competition process will lead to disqualification. Findings submitted outside the window are handled under the standing Agave security policy

Start here

The Alpenglow consensus code subject to the competition is hosted in Anza's Agave GitHub repository anza-xyz/agave. Begin with:

These four crates are the core, but the scope extends to the Alpenglow integration surface across the validator; see RULES.md section 3 for the full list.

Background: the Alpenglow whitepaper and SIMD-0326.

To recap, the code subject to the competition resides in the Agave repository, while competition submissions are made through the submission portal at https://alpenglow.anza.xyz/ and land as security advisories on this repository

Known issues

The tracker below lists issues found during Alpenglow's development and review. They can point you to areas worth investigating, but they are also the known-issues baseline: anything already listed there (or otherwise public) at the time you submit is out of scope (RULES.md section 8):

Alpenglow related issues on Agave

In addition, KNOWN_NON_ISSUES.md lists rejection criteria and known non-issues. Check it before submitting to avoid re-reporting closed work.

Get notified

Follow @anza_xyz on X and Watch this repository. Further competition details will be announced in both places.

About

No description, website, or topics provided.

Resources

Security policy

Stars

145 stars

Watchers

24 watching

Forks

Releases

Packages

Contributors