Alpenglow bug bounty closes with 300+ submissions and up to 50,000 SOL in rewards

The Alpenglow bug bounty, organized by Anza as the first large-scale adversarial review of the upgrade, closed on Aug. 19, 2026, after receiving more than 300 vulnerability submissions. The program offered up to 50,000 SOL in rewards, valued at $5 million, for valid findings, with payouts determined by severity and the full pool reserved for specific high-impact cases such as a verified potential loss of funds. Alpenglow is designed to reduce Solana’s transaction finality from 12.8 seconds to 100-150 milliseconds by reworking the network’s consensus mechanism. Reports targeted critical components of the Agave validator codebase, including votor, votor-messages and bls-sigverify. Submissions ran from Aug. 5 to Aug. 19 through a portal that charged a non-refundable 0.5 SOL fee per report and required private filing through GitHub Security Advisories. Anza and the Solana Foundation will assess submissions through Sept. 2, while awarded SOL will remain locked for one year after the competition ends.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.