Degraded service: a burn may not verify right away. Consider waiting a few minutes before sending your burn.

Anza Bug Bounty

Report security vulnerabilities in software maintained by Anza. Choose a program below and file your report through this portal; each submission opens a draft GitHub security advisory on the program's repository, one finding per advisory.

Agave validator client On-chain programs SOL submission fee

Do not disclose a finding publicly: public findings are ineligible for a reward. Scope, severity categories, rewards, and duplicate policy are defined in each program's security policy.

Competition not yet live
Submissions open soon
You can sign in now. The form unlocks automatically at go-live.
--:--:--

Sign in to submit

Sign-in binds this report's credit to your GitHub account and unlocks the form. No scopes are requested, only your public identity.

Sign in with GitHub

You can read the whole form below. It unlocks after sign-in.

02 · Choose a program

Scope, components, rewards, and rules differ per program.

Choose a program to report against.

03 · Terms & Conditions

You must accept the Terms & Conditions.

04 · Vulnerability details

One finding per submission. Submissions with multiple findings will be closed. The description fields support Markdown; use the Preview tab to check formatting.

256 characters remaining

Summary is required.

Please choose a category.

You pick the category; Anza assesses final severity per the program's security policy. Rewards are denominated in 12-month locked SOL; ranges shown are draft and subject to change.

05 · Affected component

Select the affected component.

Select the affected release.

06 · Payment verification

Submitting requires a one-time burn of SOL on .

!The burn is non-refundable. Send it only when your report is ready to submit.
A

The burn must be signed by, and funded from, this wallet.

A valid Solana wallet address is required.

B
Run this from a terminal with the Solana CLI installed
Preparing your burn command…
One burn = one report.
Submit before your session expires.
Burn from the same wallet you entered above.
Five verification attempts per session.
C

A valid burn transaction signature is required.

Please confirm you have sent the burn.

Submitting opens a draft GHSA and checks for your burn.

Report submitted

Program
Advisory
Session reference
Burn signature
Payout wallet