Solana closes bug bounty for Alpenglow upgrade with 300 submissions

1 hour ago 1



Solana’s most ambitious consensus upgrade just passed its first stress test, and the testers were paid handsomely to try to break it. The Alpenglow bug bounty competition, organized by Anza, closed on August 19 after a two-week sprint that pulled in more than 300 vulnerability submissions from security researchers around the world. The reward pool? Up to 50,000 SOL, distributed based on how severe the bugs turn out to be. What Alpenglow actually changes Alpenglow is not a minor patch. It’s a full rethinking of Solana’s consensus mechanism, designed to slash transaction finality times from the current 12.8 seconds down to somewhere in the range of 100 to 150 milliseconds. The bug bounty specifically targeted critical components within the Agave validator codebase. That includes crates related to the votor, votor-messages, bls-sigverify, and other integration mechanisms that form the backbone of Alpenglow’s new voting and consensus logic. Notably, Alpenglow had been excluded from prior Agave bug bounty programs, making this dedicated competition the protocol’s first real exposure to adversarial security review at scale. How the bounty worked The competition ran from August 5 to Augus...

Read Entire Article