Report security vulnerabilities in software maintained by Anza. Choose a program below and file your report through this portal; each submission opens a draft GitHub security advisory on the program's repository, one finding per advisory.
Do not disclose a finding publicly: public findings are ineligible for a reward. Scope, severity categories, rewards, and duplicate policy are defined in each program's security policy.
Sign-in binds this report's credit to your GitHub account and unlocks the form. No scopes are requested, only your public identity.
Sign in with GitHubYou can read the whole form below. It unlocks after sign-in.
Scope, components, rewards, and rules differ per program.
Choose a program to report against.
You must accept the Terms & Conditions.
One finding per submission. Submissions with multiple findings will be closed. The description fields support Markdown; use the Preview tab to check formatting.
Summary is required.
Please choose a category.
You pick the category; Anza assesses final severity per the program's security policy. Rewards are denominated in 12-month locked SOL; ranges shown are draft and subject to change.
Select the affected component.
Select the affected release.
Submitting requires a one-time burn of … SOL on ….
The burn must be signed by, and funded from, this wallet.
A valid Solana wallet address is required.
Preparing your burn command…
A valid burn transaction signature is required.
Please confirm you have sent the burn.