Solana's big security contest made researchers pay to report bugs. That's the catch.
Anza turned Alpenglow review into a live market, but the rules make researchers eat real cost if timing or eligibility moves against them.

CryptoVibe Desk · solana · agave · alpenglow

- →Anza ran an Alpenglow bug bounty from Aug. 5 to Aug. 19, with a 50,000 SOL prize ceiling.
- →Researchers had to burn 0.5 SOL per report, and findings had to survive Agave master branch changes.
- →Watch whether valid reports get cut by eligibility rules before adjudication closes on Sept. 2.
- Agave → Agave is one software client that validators run to take part in Solana.
- Alpenglow → Alpenglow is Solana's planned consensus system for deciding which blocks become final.
- BLS verification → BLS verification checks compact cryptographic signatures from many validators.
- master branch → The master branch is the live development line where code can change before release.
Anza put 50,000 SOL on the table. Its Alpenglow bug bounty ran from Aug. 5 at 16:00 UTC to Aug. 19 at 16:00 UTC, according to Anza's rules. The scope covered Solana's Agave client on master, including Votor, BLS verification, certificate validation, validator integration, and the TowerBFT-to-Alpenglow migration path.
The code review target is real. The submission risk is also real. Anza's rules required every report to go through its portal with a non-refundable 0.5 SOL burn. If you're a security researcher, that changes the math before you even open the diff.
This is not a normal open-ended bounty. The rules say the 50,000 SOL pool is a ceiling, not a floor. The highest-severity valid finding unlocks the aggregate pool, but each award stays capped by category. Anza also says awards can be reduced pro-rata if total valid awards exceed the unlocked pool.
The top category is loss of funds. Anza's rules list 6,250 to 25,000 SOL for that class, with 25,000 SOL as the maximum single award. Consensus and safety violations sit at 3,125 to 12,500 SOL. Liveness failures land at 1,250 to 5,000 SOL. DoS findings get 315 to 1,250 SOL.
The tradeoff is spam resistance for researcher risk. A burn can stop low-effort reports. It can also punish careful reports that miss a moving eligibility line. The rules tie eligibility to Agave master: the bug must exist in the cited in-window commit and still be unfixed on master when submitted.
That last clause matters. Agave v4.3.0-beta.0 already includes multiple Alpenglow, Votor, and BLS changes. The release notes include migration gating, BLS vote-window bounds, skip-vote handling, and certificate handling changes. This is a cache invalidation problem dressed as a bounty rule. Your finding can be correct against one commit and dead against the next.
Anza is trying to secure Solana's largest consensus migration before it reaches production weight. That part is good engineering. But the contest quietly makes researchers pay for uncertainty that the protocol team controls. Read the rules, not the prize number. The only number that matters may be 0.5 SOL, if it keeps the right person from filing the right bug.
Anza is making valid researchers pay for Anza-controlled code churn. Without refunds for valid in-scope reports, the burn tax is sloppy security engineering.
Before adjudication closes on Sept. 2, watch whether Anza publishes any valid report rejected because master changed before submission.
Primary links and supporting reads used by the desk for this story.
Forward this.











