Superteam Earn
Superteam Nigeria

1

Abhishek

Intermediate Developer Challenge: Anchor/Pinocchio Security Template

by Superteam Nigeria

|
|
4,000USDG

Total Prizes

1,500

USDG

1st

1,000

USDG

2nd

700

USDG

3rd

500

USDG

4th

300

USDG

5th

62

SUBMISSIONS

Syncing...

REMAINING

REGIONAL LISTING

This listing is only open for people in Nigeria

Overview

Security remains one of the biggest challenges in Solana program development. Many exploits do not come from complex attacks, but from simple mistakes: missing account validation, incorrect authority checks, unsafe arithmetic, or misunderstood CPI behavior.

Anchor and Pinocchio provide strong abstractions, but they do not automatically make programs safe. Developers still need to understand why a pattern is dangerous and how to fix it correctly.

This bounty focuses on building a clear, educational security reference for Solana developers by contrasting vulnerable code with secure alternatives. The goal is to make security concepts practical and obvious, especially for developers learning Anchor or Pinocchio.

You will create a repository of at least 5 Solana programs where each example contains a deliberately broken instruction and a corresponding fixed version, with comments explaining what went wrong and how it was corrected.


Requirements

Your submission must include:

  • A public repository containing multiple security examples

  • Each example must include:

    • A vulnerable instruction

    • A secure version of the same instruction

    • Clear inline comments explaining the issue and the fix


Additional requirements:

  • Code must be fully open source

  • A deep-dive content piece explaining the security patterns (video or written)

  • Build solo or with a team of up to 4 people

  • The winning submission will be pushed to the SuperteamNG repository


What You Can Build

This bounty is about clarity, not scale. Small, focused examples are encouraged.

Possible structures include:

Side-by-Side Program Examples

  • One instruction labeled “vulnerable”

  • One instruction labeled “secure”

  • Same business logic, different security handling

Pattern-Based Modules

  • A folder per vulnerability type

  • Each folder contains multiple small examples

  • Shared README explaining the pattern


Technical Expectations

Your submission should demonstrate:

  • Solid understanding of Solana’s account model

  • Correct use of Anchor constraints and checks

  • Awareness of CPI and re-entrancy risks

  • Safe handling of arithmetic and state mutation

  • Clear reasoning, not just code changes

This is an educational bounty. Readability and explanation matter as much as correctness.


Tech Stack Suggestions

You may use Anchor, Pinocchio, or both.

Tests are encouraged but not mandatory.


Judging Criteria

Submissions will be evaluated based on:

  • Accuracy of vulnerability examples

  • Quality of explanations and comments

  • Coverage of real-world Solana attack patterns

  • Code clarity and organization

  • Usefulness as a learning resource

Bonus points for:

  • Tests that demonstrate the exploit and the fix

  • Clear README summaries per vulnerability

  • Clean comparison between Anchor and Pinocchio approaches


Prizes

A total prize pool of $4,000 USDC will be distributed among the top submissions:

  • 1st Place: 1,500 USDC

  • 2nd Place: 1,000 USDC

  • 3rd Place: 700 USDC

  • 4th Place: 500 USDC

  • 5th Place: 300 USDC


Resources

Anchor Documentation

https://www.anchor-lang.com/docs


Solana Documentation

https://solana.com/docs


Pinocchio Framework

https://github.com/anza-xyz/pinocchio


Solana Account Model

https://solana.com/docs/core/accounts

SKILLS NEEDED

Backend

CONTACT

Reach outif you have any questions about this initialBounty

WINNER ANNOUNCEMENT BY

February 14, 2026 - as scheduled by the sponsor.