Solana Mobile has launched a Vulnerability Disclosure Policy and Bug Bounty Program that pays researchers up to $75,000 in SKR for critical vulnerabilities found in Seed Vault, SKR's onchain programs, and Seeker Genesis Token infrastructure. The program launched August 13, 2026, alongside a separate Solana Mobile Security Grants initiative.
What's in scope for the bug bounty
The program covers three components that sit closest to user funds and identity on Seeker:
Seed Vault: Seeker's hardware-backed key custody system, including its Trusted Application running in the device's TEE (trusted execution environment, an isolated chip-level enclave separate from the main Android OS), the Android system service around it, and the seed and wallet management UI
SKR onchain programs: specifically the Inflation Program that controls token issuance and mint authority, and the Staking Program that manages deposits and rewards
Seeker Genesis Token backend: covering the soul-bound token minting APIs and Seeker ID management
Rewards are classified into four tiers by real-world impact:
Tier 1: Funds at risk, no user action required, up to $75,000
Tier 2: Funds at risk, user action required, up to $37,500
Tier 3: Denial of service, up to $15,000
Tier 4: Cosmetic UI or invalid copy, up to $750
How researchers get paid
Bounties are paid in SKR under a signed Award Agreement rather than a direct wallet transfer. The token quantity is calculated using the 7-day volume-weighted average price at the time the vulnerability is validated as resolved, and vesting starts 30 days after that resolution. Delivered tokens carry a 12-month use restriction before they reach the researcher's wallet.
Submissions need to be complete to qualify: a summary, the affected component, numbered reproduction steps, working proof-of-concept code, and an impact assessment. Testing has to stay confined to local test validators or a researcher's own production Seeker device, and reports go through a secure Airtable form rather than a public GitHub issue, keeping live vulnerabilities out of view while they're fixed.
Security Grants program launches alongside the bounty
Solana Mobile is also introducing Security Grants as part of its broader grants program, a separate track from the bug bounty aimed at funding security research rather than paying out for specific found vulnerabilities. EthelSec is the first team to receive one, credited for their security research work.
The bounty rewards someone who finds a live flaw. The grants fund the research that might catch one before it ships. Together, the two programs cover Seeker's key custody, SKR issuance, and identity layer, the three systems the bug bounty's own scope names as most exposed to loss of funds.