Solana Mobile Launches Bug Bounty Program With Rewards Up to $75K in SKR

Solana Mobile has launched a Vulnerability Disclosure Policy and Bug Bounty Program that pays researchers up to $75,000 in SKR for critical vulnerabilities found in Seed Vault, SKR's onchain programs, and Seeker Genesis Token infrastructure. The program launched August 13, 2026, alongside a separate Solana Mobile Security Grants initiative.

What's in scope for the bug bounty

The program covers three components that sit closest to user funds and identity on Seeker:

  • Seed Vault: Seeker's hardware-backed key custody system, including its Trusted Application running in the device's TEE (trusted execution environment, an isolated chip-level enclave separate from the main Android OS), the Android system service around it, and the seed and wallet management UI

  • SKR onchain programs: specifically the Inflation Program that controls token issuance and mint authority, and the Staking Program that manages deposits and rewards

  • Seeker Genesis Token backend: covering the soul-bound token minting APIs and Seeker ID management

Rewards are classified into four tiers by real-world impact:

  • Tier 1: Funds at risk, no user action required, up to $75,000

  • Tier 2: Funds at risk, user action required, up to $37,500

  • Tier 3: Denial of service, up to $15,000

  • Tier 4: Cosmetic UI or invalid copy, up to $750

How researchers get paid

Bounties are paid in SKR under a signed Award Agreement rather than a direct wallet transfer. The token quantity is calculated using the 7-day volume-weighted average price at the time the vulnerability is validated as resolved, and vesting starts 30 days after that resolution. Delivered tokens carry a 12-month use restriction before they reach the researcher's wallet.

Submissions need to be complete to qualify: a summary, the affected component, numbered reproduction steps, working proof-of-concept code, and an impact assessment. Testing has to stay confined to local test validators or a researcher's own production Seeker device, and reports go through a secure Airtable form rather than a public GitHub issue, keeping live vulnerabilities out of view while they're fixed.

Security Grants program launches alongside the bounty

Solana Mobile is also introducing Security Grants as part of its broader grants program, a separate track from the bug bounty aimed at funding security research rather than paying out for specific found vulnerabilities. EthelSec is the first team to receive one, credited for their security research work.

The bounty rewards someone who finds a live flaw. The grants fund the research that might catch one before it ships. Together, the two programs cover Seeker's key custody, SKR issuance, and identity layer, the three systems the bug bounty's own scope names as most exposed to loss of funds.

Read More: Introducing the Solana Mobile Vulnerability Disclosure Policy, Bug Bounty Program, and Security Grants