• 5 mins read
  • Published

Solana's Alpenglow Bug Bounty Requires 0.5 SOL Upfront Fee

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

Solana's Alpenglow Bug Bounty Requires 0.5 SOL Upfront Fee EgonCoin © egoncoin.com
Solana's Alpenglow Bug Bounty Requires 0.5 SOL Upfront Fee © egoncoin.com

Security researchers must pay a non-refundable 0.5 SOL fee to submit bug reports for Solana's new Alpenglow consensus protocol, with eligibility and rewards determined only after submission and review

Solana infrastructure developer Anza has launched a two-week bug bounty competition for its proposed Alpenglow consensus protocol, but with a controversial twist: researchers must pay a non-refundable 0.5 SOL fee for each report they submit. The competition, which closes at 16:00 UTC on August 19, targets flaws in Alpenglow's core consensus components and validator integrations. All submissions must be filed through a designated portal that burns the fee and creates a confidential GitHub Security Advisory. Reports sent through any other channel are automatically disqualified.

Fee Structure and Submission Rules

Unlike most bug bounties, Anza's process requires researchers to pay the filing fee before any determination of validity, severity, or duplication. Each report must specify the exact code commit where the flaw appears, reproduce the issue on that version, and arrive before the bug is fixed on the master branch. The protocol's moving codebase means researchers are racing against both other participants and ongoing development. Placeholder or speculative submissions are discouraged by the proof-of-concept requirement and the upfront cost, but this also risks deterring valid but uncertain findings.

Scope, Exclusions, and Award Structure

The Alpenglow bounty covers a defined set of new consensus code, including the Votor voting engine, BLS signature and certificate verification, migration paths from TowerBFT, and validator integration points. Publicly known issues, test code, third-party cryptography, and legacy TowerBFT-only paths are excluded. Researchers must demonstrate bugs in a local or simulated environment-mainnet and public testnet attacks are not permitted. The earliest valid report at a given severity level receives the award for that root cause, while duplicates are only rewarded if they demonstrate a higher severity. If a fix is merged before adjudication, eligibility for payment is lost, even if the report was valid at the time of submission.

Reward Pools and Payment Terms

The maximum aggregate bounty pool is 50,000 SOL, but only the most severe loss-of-funds finding unlocks the full amount. Other categories-consensus violations, liveness failures, and denial-of-service-unlock smaller pools. Individual awards range from 315 SOL for minor DoS bugs to 25,000 SOL for critical loss-of-funds vulnerabilities. If total awards exceed the unlocked pool, payouts are reduced proportionally. All payments are subject to KYC and are locked for 12 months, while the 0.5 SOL filing fee is burned immediately. The competition's rules do not specify minimum participation or report quality thresholds, leaving some uncertainty about the trade-off between discouraging spam and pricing out legitimate research.

Alpenglow's design introduces BLS-based vote and certificate aggregation, with notarization and finalization thresholds set at 60% and 80% of stake, respectively. The protocol aims for 40% crash-failure resilience and is incompatible with Solana's current consensus logic. The migration path and validator code are included in the bounty's scope, putting both new and transitional logic under scrutiny. The submission window's close does not activate Alpenglow or complete the migration; findings remain confidential until fixes are merged and relevant feature gates are enabled.

As of August 18, the official rules still listed August 19 as the cutoff, with no extension announced. The number of submissions and their quality will remain private until fixes are shipped. The economics of the competition mean that researchers must risk 0.5 SOL per report, with compensation dependent on later adjudication and a one-year lockup. This approach stands in contrast to other crypto security programs, where upfront costs are rare and participation metrics are often public. For context, recent coverage of security practices in the industry, such as the risks associated with audit badges, can be found in EgonCoin's analysis of how audit labels may mislead users about actual protections.

According to public blockchain data, Solana's native token SOL traded between $165 and $180 during the week leading up to the Alpenglow bounty window, with daily trading volumes exceeding $1 billion across major exchanges. The 0.5 SOL filing fee thus represented approximately $80-$90 per report at the time of the competition. The total 50,000 SOL bounty pool, if fully unlocked, would be valued at roughly $8-$9 million, though actual payouts depend on the severity and number of valid findings.

Bug bounty programs are a common tool for open-source blockchain projects to identify and fix critical vulnerabilities before mainnet deployment. By requiring a non-refundable filing fee, Anza aims to filter out low-quality or speculative reports, but this approach also shifts risk onto independent researchers. The balance between discouraging spam and encouraging broad participation is a persistent challenge in crypto security, especially as protocols grow more complex and the stakes for network safety increase. The Alpenglow competition's outcome may influence how future blockchain projects structure their own security incentives and disclosure processes.

Related articles