4,000USDG Total Prizes | ||
1,500 USDG 1st 1,000 USDG 2nd 700 USDG 3rd 500 USDG 4th 300 USDG 5th |
62
SUBMISSIONS
Syncing...
REMAINING
RELATED LIVE LISTINGS
Security remains one of the biggest challenges in Solana program development. Many exploits do not come from complex attacks, but from simple mistakes: missing account validation, incorrect authority checks, unsafe arithmetic, or misunderstood CPI behavior.
Anchor and Pinocchio provide strong abstractions, but they do not automatically make programs safe. Developers still need to understand why a pattern is dangerous and how to fix it correctly.
This bounty focuses on building a clear, educational security reference for Solana developers by contrasting vulnerable code with secure alternatives. The goal is to make security concepts practical and obvious, especially for developers learning Anchor or Pinocchio.
You will create a repository of at least 5 Solana programs where each example contains a deliberately broken instruction and a corresponding fixed version, with comments explaining what went wrong and how it was corrected.
Your submission must include:
A public repository containing multiple security examples
Each example must include:
A vulnerable instruction
A secure version of the same instruction
Clear inline comments explaining the issue and the fix
Code must be fully open source
A deep-dive content piece explaining the security patterns (video or written)
Build solo or with a team of up to 4 people
The winning submission will be pushed to the SuperteamNG repository
This bounty is about clarity, not scale. Small, focused examples are encouraged.
Possible structures include:
Side-by-Side Program Examples
One instruction labeled “vulnerable”
One instruction labeled “secure”
Same business logic, different security handling
Pattern-Based Modules
A folder per vulnerability type
Each folder contains multiple small examples
Shared README explaining the pattern
Your submission should demonstrate:
Solid understanding of Solana’s account model
Correct use of Anchor constraints and checks
Awareness of CPI and re-entrancy risks
Safe handling of arithmetic and state mutation
Clear reasoning, not just code changes
This is an educational bounty. Readability and explanation matter as much as correctness.
You may use Anchor, Pinocchio, or both.
Tests are encouraged but not mandatory.
Submissions will be evaluated based on:
Accuracy of vulnerability examples
Quality of explanations and comments
Coverage of real-world Solana attack patterns
Code clarity and organization
Usefulness as a learning resource
Bonus points for:
Tests that demonstrate the exploit and the fix
Clear README summaries per vulnerability
Clean comparison between Anchor and Pinocchio approaches
A total prize pool of $4,000 USDC will be distributed among the top submissions:
1st Place: 1,500 USDC
2nd Place: 1,000 USDC
3rd Place: 700 USDC
4th Place: 500 USDC
5th Place: 300 USDC
Resources
Anchor Documentation
https://www.anchor-lang.com/docs
Solana Documentation
Pinocchio Framework
https://github.com/anza-xyz/pinocchio
Solana Account Model
SKILLS NEEDED
Backend
CONTACT
Reach outif you have any questions about this initialBounty
WINNER ANNOUNCEMENT BY