Feed
Bounty Rolling

Solana Mobile Bug Bounty Program

Solana Mobile pays up to $75,000 in SKR for critical vulnerabilities in Seed Vault, the SKR onchain programs and the Seeker Genesis Token backend. Reports are accepted on a rolling basis.

The Solana Mobile Bug Bounty Program pays up to $75,000 in SKR for vulnerabilities in the core parts of the Solana Mobile platform. Solana Mobile announced the program on August 13, 2026 together with a vulnerability disclosure policy and a security grants initiative.

Rewards depend on severity. A critical issue that puts funds at risk without user action pays up to $75,000. A high issue that puts funds at risk but requires user action pays up to $37,500. A medium issue such as denial of service pays up to $15,000, and a low issue such as a cosmetic or copy problem pays up to $750.

Three areas are in scope. The first is Seed Vault on Seeker, including the hardware backed key custody, the TEE application, the Android service and the wallet management interface. The second is the SKR onchain programs, the Inflation Program and the Staking Program. The third is the Seeker Genesis Token backend with its APIs for token minting and ID management.

Reports go through the security portal at security.solanamobile.com. A report needs a summary, the affected component, reproduction steps, working proof of concept code and an impact assessment. Solana Mobile asks researchers never to open a public GitHub issue, because that counts as premature disclosure and voids eligibility.

SKR rewards vest after at least 30 days and carry a 12 month use restriction after vesting. Their value is set by the 7 day volume weighted average price on the resolution date. Researchers sign an Award Agreement before payment. A separate security grants program funds ecosystem security research in SKR, with EthelSec named as the first recipient.