The Other Price List: Bug Bounty Payouts on Solana and Move
Off Ethereum, a critical bug is priced, hunted and paid on different rails. Here is what a Solana or Move vulnerability is actually worth in 2026, and who collects.
In early December 2021, a small German research firm called Neodyme found a flaw in one of Solana’s most widely forked lending programs. The bug was almost embarrassingly plain: deposit into a reserve on one block, borrow or withdraw against it on the next, and the accounting let you take out more than you had put in. Neodyme estimated an attacker could have siphoned roughly $27 million an hour from pools built on the code, and by the time the coordinated fix landed the researchers put the total exposure at more than $2.6 billion across Solend, Tulip, Larix and other lenders, according to Bitcoin.com News.
That $2.6 billion is one of the largest at-risk figures ever attached to a single crypto disclosure. The reward that changed hands was not $2.6 billion, or anything close to it. That gap, between the money a bug could have cost and the money a researcher actually collects, is the entire subject of bug bounty payouts. On Ethereum the crypto press has told that story many times over. Off Ethereum, on Solana and the Move-based chains Sui and Aptos, the same gap exists, but the machinery that produces it looks different: different bug classes, different hunters, different ceilings, and in at least one landmark case a recovery that came down to 114 validators agreeing to freeze a thief in place.
This is the other price list.
Why the bounty looks different once you leave Ethereum
Ethereum’s bounty economics are, by now, well documented. Programs advertise ceilings that reach into eight figures: the stablecoin issuer Usual set a $16 million maximum on Sherlock in 2025, the largest in software history, and Uniswap v4 and LayerZero sit just below it at $15.5 million and $15 million, per Sherlock’s 2026 leaderboard. Yet Immunefi’s own data, drawn from 593 programs, shows a median critical payout of just $20,000 and a mean of $114,355. The ceiling is a billboard; the receipt is something else.
The single largest bounty crypto has ever paid also happens to straddle both worlds. In February 2022 the researcher known as satya0x collected $10 million from Wormhole for privately reporting a flaw in the bridge’s contract-upgrade machinery, and Wormhole is a Solana-to-Ethereum bridge. That number still tops Sherlock’s ceiling leaderboard years later. It is the exception that frames the rule: the biggest money in non-EVM security sits at the bridges, where the dollars concentrate, not inside any single Solana or Move protocol.
Why does the rest of the price list look different? Because the bugs are different. Ethereum’s signature vulnerability is reentrancy, the trick of calling back into a contract before it finishes updating its own state. Solana’s runtime does not work that way. As Robert Chen, founder of the Solana-focused audit firm OtterSec, put it to SolanaFloor, one theory is that “programs on Solana are fundamentally more secure because of the programming model,” and “there’s no re-entrancy on Solana, which mitigates a pretty large attack surface.” DefiLlama’s 2024 tally in the same report backs the shape of that claim: about $792.6 million in EVM hacks against $33.5 million on Solana. Chen’s caveat matters just as much, though: “any sort of economic exploit is VM agnostic.” Oracles, liquidations and governance can be gamed on any chain.
The bugs that pay: the account model and Rust
Solana programs are stateless. They do not hold their own storage the way an Ethereum contract does; instead, every account a program touches is passed in explicitly with each instruction. That design removes reentrancy, but it introduces a family of bugs that barely exist on the EVM. The program has to check, by hand, that the accounts it was handed are the right ones. Forget one check and an attacker substitutes an account they control.
The recurring classes, laid out in Cantina’s developer security guide, are a short and unglamorous list. A missing signer check lets a caller act without proving they authorized the action. A missing owner check lets a fake account masquerade as one owned by the right program. Account or type confusion exploits Solana’s loose typing to pass one kind of account where another is expected. Integer overflow is a particular trap in Rust: arithmetic panics in debug builds but silently wraps in release builds, and Solana programs ship as release builds. Arbitrary cross-program invocation lets a program be tricked into calling code it should not. The Anchor framework, which automates the signer and owner checks and now underpins the large majority of deployed Solana programs, exists precisely because these mistakes were so easy to make.
| Bug class | What goes wrong | Why it is a non-EVM problem |
|---|---|---|
| Missing signer check | Program acts without confirming the caller signed | Accounts are passed in, not implicit; the check is manual |
| Missing owner check | A spoofed account passes as one the program owns | No built-in ownership guarantee on supplied accounts |
| Account / type confusion | One account type is accepted where another is required | Loose typing across the account model |
| Integer overflow | Arithmetic wraps instead of panicking | Rust release builds skip the debug overflow checks |
| Arbitrary CPI | Program is steered into calling attacker code | Cross-program invocation is a first-class primitive |
These are not theoretical. Neodyme, a German firm founded in 2021 that has become one of the most prolific hunters of Solana core bugs, made its name on a vault-draining flaw tied to a hash collision in Solana’s program-derived addresses, patched in a single day in mid-2021. The lesson that stuck: on Solana the dangerous bug is rarely a clever cryptographic break. It is a forgotten check.
What the chain itself pays
Above the protocols sits the base layer, and the base layer runs its own bounty. The Solana Foundation offers up to $2 million in SOL, locked for twelve months, for vulnerabilities in the core protocol. The tiers tell you what the network fears most. A consensus or safety violation, the kind of bug that could let an attacker forge state or spend without a signature, is worth up to $1 million. A remote bug that could partition or halt the network, in effect turning Solana off, carries a $400,000 reward.
That last figure has a memorable origin. Jacob Creech, then head of developer relations at the Solana Foundation, spelled it out bluntly on-chain, as CryptoPotato reported: “Fyi there’s a $400k reward for anyone that can find code that can turn off Solana.” The categories that qualify read like a list of a validator’s nightmares: theft without signatures, unauthorized transfers, vote-program exploits that drain delegated stake, and remote partition attacks. That third category has a direct parallel on Ethereum, where the risk lands on whoever controls large pools of delegated capital; our look at who controls staked ETH traces the same anxiety from the delegator’s side.
One detail in the Foundation’s terms is easy to skim past and matters enormously to the person collecting: the reward is paid in SOL and locked for a year. A researcher who earns the maximum is handed a token position, not a cheque, and carries a full year of price risk before they can touch it. Hold that thought; it comes back later.
Alpenglow: adversarial review meets a consensus rewrite
The clearest 2026 illustration of the chain-level bounty in action was Alpenglow. Alpenglow is a fundamental redesign of Solana’s consensus, built to cut transaction finality from roughly 12.8 seconds to somewhere between 100 and 150 milliseconds by reworking the voting logic and signature handling inside the validator client. Rewriting the part of a protocol that decides what is true is exactly the sort of change you do not want to ship without adversaries looking at it first.
So Solana ran a time-boxed bounty. According to Bitget News, the program ran from 5 to 19 August 2026, offered a pool of up to 50,000 SOL, and drew more than 300 submissions, with an adjudication window that extended through 2 September. Two design choices stand out. Each report required a non-refundable 0.5 SOL fee, a stake-to-submit filter meant to price out spam and, increasingly, AI-generated noise. And the full 50,000 SOL only unlocked for a verified scenario that could lead to loss of funds; lesser findings paid less. At SOL’s late-September price near $120, tracked by Coinbase, that ceiling was worth roughly $6 million, though, as with the Foundation program, the rewards are locked for a year after the contest closes. It was, in the organizers’ framing, the protocol’s first real exposure to adversarial security review at scale.
Kamino and the shape of a Solana DeFi bounty
Drop down from the base layer to the applications and the numbers change again. Solana’s largest continuous protocol bounty belongs to Kamino, the lending and liquidity venue, which launched a program on Immunefi in October 2025 that Coinspeaker called the chain’s biggest. The structure is worth reading closely because it is the template most Solana DeFi programs now follow. A critical smart-contract bug pays 10% of the funds directly at risk, up to a maximum of $1.5 million. Unusually, it also sets a floor: a confirmed critical never pays less than $150,000, a deliberate signal that Kamino would rather overpay a small critical than teach researchers that disclosure is a bad trade. High-severity bugs pay up to $100,000, medium a flat $10,000, and website or app issues up to $50,000.
The 10%-of-at-risk model is the same convention that governs the EVM world, and it is why ceilings and receipts diverge so sharply. If your protocol holds $3 million in a given pool, the most a critical there can pay is $300,000, no matter how large the advertised maximum. Kamino is not alone; the Solana venues that draw the most value, including the perpetual-futures markets we cover in our guide to how on-chain perp DEXs work, all run programs shaped roughly this way. Here is how the non-EVM ceilings line up in 2026.
| Program | Chain / layer | Advertised maximum | Model |
|---|---|---|---|
| Wormhole | Solana-Ethereum bridge | $10,000,000 | Continuous (Immunefi) |
| Solana Foundation | Solana core protocol | $2,000,000 (locked SOL) | Tiered: consensus / partition |
| Kamino | Solana DeFi | $1,500,000 | 10% of at-risk, $150k floor |
| Firedancer | Solana validator client | $500,000 | Continuous (Immunefi) |
| Aptos | Move L1 | Undisclosed | Tiered critical |
| Sui Foundation | Move L1 | Not published | Critical incl. supply inflation |
Set that against the EVM ceilings, Usual’s $16 million, Uniswap’s $15.5 million, LayerZero’s $15 million, and the pattern is clear. With the single exception of the Wormhole bridge, the non-EVM price list tops out lower, not because the chains are worth less but because the value is spread across newer protocols with smaller individual pools, and the 10% rule ties the reward to the pool, not to the chain.
Firedancer and the client-layer bounty
There is a tier between the single protocol and the whole chain that the EVM press rarely dwells on: the validator client. Firedancer, the independent Solana client built by Jump Crypto, runs a continuous $500,000 Immunefi bounty on Sherlock’s 2026 leaderboard, and it has also been the subject of a dedicated, time-boxed audit competition. That pricing looks high for a single piece of software until you remember what a client bug is. A flaw in a widely run client is not a protocol exploit; it is a chain-halting or chain-splitting event, closer in blast radius to the Foundation’s consensus tier than to any one application’s TVL.
This is the client-diversity argument stated in dollars. A chain that runs on one client has a single point of failure worth pricing accordingly, which is why Firedancer’s arrival, giving Solana a second production-grade client, was treated as a security milestone in its own right and not merely a performance upgrade.
The Move chains: Sui, Aptos and “safe by design”
Move, the language behind Sui and Aptos, was designed after Solidity’s worst years with those years’ lessons baked in. Assets are represented as resources that the type system refuses to copy or silently discard, a borrow checker enforces ownership at compile time, there is no reentrancy, and the Move Prover offers formal verification as a first-class tool rather than a bolt-on. The marketing shorthand is “safe by design,” and there is real substance behind it.
The bounty programs reflect that confidence and its limits. The Sui Foundation has run an Immunefi program since 2023 whose critical category, per Sui’s own announcement, explicitly includes exotic Move-specific failures such as exceeding the maximum 10 billion SUI supply and claiming the excess, alongside ordinary loss-of-funds bugs; the headline maximum is not published. Aptos runs a critical-severity program of its own. But two of 2026’s most instructive non-EVM incidents landed squarely on Move chains, and both showed that a safer language moves the bugs rather than abolishing them.
Cetus: when the validators become the recovery mechanism
On 22 May 2025, Cetus, the largest decentralized exchange on Sui, lost about $220 million. The root cause was not a forgotten check or a reentrancy trick but an arithmetic overflow in a shared math library used to price liquidity positions; the attacker fed it a value large enough to break the calculation and mint themselves liquidity that no real deposit backed. Cetus responded the way EVM protocols do, with a public offer: as Cointelegraph documented, it messaged the attacker on-chain, “In exchange, you can keep 2,324 ETH ($6M) as a bounty, and we will consider the matter closed and will not pursue any further legal, intelligence, or public action,” while warning it would escalate with full legal and intelligence resources if the funds moved to mixers.
The bounty offer is not what makes Cetus a landmark. The recovery is. Sui’s validators, 114 in all, deployed patched code that froze roughly $162 million of the stolen funds by simply declining to process the attacker’s transactions, then voted through a hard fork to restore that balance to users, as The Defiant reported. About $63 million had already been bridged to Ethereum and was gone, beyond the reach of any validator vote and into the laundering pipeline that our piece on the FATF grey list describes. This is the non-EVM recovery mechanic in its purest form: on a fast Byzantine-fault-tolerant chain with a known, coordinating validator set, the validators can collectively act as a freeze button no Ethereum protocol possesses. It also drew immediate criticism that a chain whose validators can freeze funds by fiat is, in its detractors’ words, closer to a “centralized, permissioned database” than the decentralization label suggests. The power that saved $162 million is the same power that makes the chain censorable.
The Aptos Move-VM bug: $70 billion and a $3,000 server
If Cetus showed how Move chains recover, the Aptos episode showed how much a single non-EVM bug can be worth in raw exposure, and how little it can cost to find. Researchers at the security firm Hexens, led by co-founder and chief technology officer Vahe Karapetyan, discovered what they called a stale-cache bug in the Move virtual machine, the component that executes every smart contract on Aptos. It produced a type-confusion condition: the machine could be tricked into treating one on-chain resource as another, the Move equivalent of handing over your house keys because the label on the ring was wrong.
CoinDesk reported the numbers that made the finding notorious. Hexens put the first-order systemic exposure, spanning stablecoins, DeFi, bridges and centralized-exchange pathways, at roughly $70 billion, with direct Aptos-native value at risk in the low single-digit billions; an independent verifier calculated about $250 million in Aptos-native TVL directly exposed. The kicker was the cost of the attack. A server renting for about $3,000 was enough to run it, with a success rate near 90%, landing 17 or 18 times out of roughly 20 attempts. Mudit Gupta, chief information security officer at Polygon, reviewed the work and confirmed, in CoinDesk’s account, “It ran as claimed, and the exploit made sense.”
Hexens reported the flaw privately on 25 February 2026; Aptos patched it within hours, the public pull request followed on 27 February, and the full technical account only became public in July. No funds were lost. “No users or funds were impacted at any point,” Aptos stated, per Crypto Briefing. The detail that should stay with anyone thinking about payouts is the counterfactual. A bug that cheap to weaponize and that broad in reach would command far more than any bounty on a grey market that sells working exploits to people who intend to use them. The researchers chose disclosure anyway. Every bounty program is, in the end, a bid to make that the rational choice.
Ceilings versus receipts: the gap that defines the topic
Return to the number that opened this piece. Solana’s token-lending flaw put more than $2.6 billion at risk, and no headline bounty of that magnitude was ever paid, because the fix landed through coordinated disclosure before anyone lost money. That is the pattern, not the exception. Immunefi’s research across 593 programs found a median critical payout of $20,000 against a mean of $114,355, a spread that tells you a handful of enormous rewards sit atop a long tail of modest ones. Ceilings are marketing. Receipts are what researchers bank.
Non-EVM incidents make the gap especially vivid because so many of them ended in negotiated returns rather than program payouts. When Loopscale, a Solana lending protocol, lost about $5.8 million in April 2025 to a pricing manipulation, roughly 90% of the funds (about 35,527 SOL) came back within 72 hours and the attacker kept the other 10% (about 3,947 SOL) as a negotiated bounty plus a release from liability, as The Block reported. The table below sets advertised or at-risk figures against what was actually paid or recovered.
| Incident | At risk / stolen | What was actually paid or recovered |
|---|---|---|
| SPL token-lending bug (2021) | Over $2.6 billion at risk | Patched pre-exploit; no headline payout disclosed |
| Cetus on Sui (2025) | ~$220 million stolen | ~$162 million frozen by validators; $6 million offered; ~$63 million escaped |
| Mango Markets (2022) | ~$116 million drained | Attacker kept ~$47 million after a governance vote framed it as a bounty |
| Crema Finance (2022) | ~$8.8 million stolen | Most returned; ~45,455 SOL (~$1.6 million then) kept as bounty |
| Loopscale (2025) | ~$5.8 million stolen | ~90% returned in 72h; ~10% kept as negotiated bounty |
The Solana hack history compiled by Helius is full of these part-refund endings, from Crema Finance to Mango Markets, where the attacker who drained about $116 million in 2022 kept roughly $47 million after a governance vote relabeled the remainder a bounty; the criminal case that followed was later overturned on appeal, a saga with its own long tail. The through-line is that on non-EVM chains, as on Ethereum, the realized number is set by negotiation, leverage and speed far more often than by the sticker on the program page.
Who hunts out here: Neodyme, OtterSec and the specialists
A different price list draws a different workforce. Finding Solana bugs demands fluency in Rust and in the account model; finding Move bugs means knowing a resource type system almost nobody learned in school. The result is a smaller, more specialized bench than the sprawling EVM audit crowd, and the firms that dominate it are recognizable names. Neodyme has reported dozens of Solana core bugs and runs a recurring Solana security workshop that doubles as a recruiting funnel. OtterSec, founded by Robert Chen, says it has secured tens of billions of dollars in TVL across the Solana, Wormhole and Jito ecosystems with an offensive-first, break-it-yourself methodology.
Chen’s own framing, quoted earlier, captures why the numbers look the way they do. If Solana’s model really does remove an entire attack surface, there are fewer of the catastrophic bugs that command eight-figure ceilings, which pushes the median down. But his caveat that “any sort of economic exploit is VM agnostic” explains why the biggest realized losses, Mango, Loopscale, the oracle and liquidation games, look identical to their EVM cousins. The scarce, expensive skill is not breaking the cryptography; it is understanding how a specific protocol’s economics can be turned against it, and that skill pays on any chain.
When the code was fine and the keys were not
One category of loss reliably distorts the Solana hack headlines and pays no bounty at all: the key compromise. The 2022 Slope wallet incident, catalogued in the Helius hack history, drained around $8 million not because of a program bug but because the wallet quietly shipped users’ seed phrases to a logging server. A string of later losses across chains came the same way, through compromised operational or bridge keys rather than flawed contracts. A bounty pays for a disclosed code flaw. When the failure is a leaked seed phrase or a hijacked signing key, there is nothing to disclose to the protocol and, frequently, no one to negotiate a return with.
This is why so much of serious crypto security has migrated from the smart contract to the key, and why the choice between splitting a key with a multisig or a threshold-signature scheme, which we walk through in our guide to multisig versus MPC, matters more to most treasuries than any single audit. It also sharpens what a bug bounty is really buying. A bounty covers the code. It does not cover the humans holding the keys, and on an honest accounting, a large slice of headline losses were never in scope for any bounty in the first place.
The SEC, the CFAA and a reward that can crater
None of this happens outside the law, and the legal picture in the United States is unsettled in ways that directly affect payouts. A researcher who reports a bug through a program is on solid ground. A researcher who exploits a live contract to “rescue” funds, even meaning to return them, sits in a gray zone under the Computer Fraud and Abuse Act; neither the SEC nor the Department of Justice has blessed self-help hacking, and the line between a white-hat rescue and unauthorized access is drawn after the fact. Safe-harbor frameworks try to close that gap by pre-authorizing good-faith intervention during an active exploit, but they cover only the protocols that adopt them and typically cap the reward, which limits their usefulness on the largest hacks.
Then there is the money itself. In the United States a bug bounty is ordinary income, reported on a Form 1099-NEC and Schedule C and taxed at its dollar value on the day it is received. Now recall that Solana’s Foundation program and the Alpenglow contest both pay in SOL locked for a year. A researcher can be taxed on the value of a reward they cannot yet sell, and if the token falls before the lock expires, as SOL has done through more than one cycle, the tax bill can outrun the eventual proceeds. A reward denominated in a volatile token is exposed to exactly the macro swings that sent crypto to an eight-month high after a hawkish Fed, and to the drawdowns that follow them. The SEC regulates the tokens and the venues; it does not insure the researcher against being paid in one that drops.
What it means for 2026 and beyond
The non-EVM bounty is professionalizing on every layer at once. The chains run tiered programs and time-boxed contests like Alpenglow; the clients run their own; the protocols follow Kamino’s template; and Move markets a prover-first pitch that treats verification as part of the build rather than an afterthought. Immunefi, which anchors most of this activity, reported that crypto lost about $972 million across a record 207 incidents in the first half of 2026, per its H1 report carried by KuCoin, even as the total came in below 2025 and Immunefi’s cumulative researcher payouts passed $130 million. More programs, more researchers, more coverage, and yet the defining gap between ceiling and receipt has not closed.
Mitchell Amador, Immunefi’s chief executive, tends to frame the numbers as a learning curve rather than a scoreboard, arguing that crypto security is adversarial and never stops evolving. The non-EVM evidence supports a narrower claim. Outside Ethereum the bounty runs on genuinely different rails: the biggest ceiling still sits on a bridge, the biggest recovery came from validators freezing a thief rather than any reward being paid, and the biggest systemic scare was defused for the price of a $3,000 server and a researcher’s decision to disclose. The price list is different. The lesson is the one Ethereum learned first: a bounty is only worth what a researcher can actually collect, and the whole game is making honest disclosure pay better than the alternative.
Frequently Asked Questions
What is the largest bug bounty ever paid on Solana or a Move chain?
The single largest crypto bounty on record is Wormhole’s $10 million payout to the researcher satya0x in February 2022, and Wormhole is a Solana-to-Ethereum bridge. Among standing protocol programs, Kamino’s $1.5 million maximum is the largest continuous bounty native to Solana, while the Solana Foundation offers up to $2 million in locked SOL for core-protocol bugs.
Why are Solana and Move bug bounties often smaller than Ethereum’s?
Most non-EVM ceilings are lower because value is spread across newer protocols with smaller individual pools, and the standard model pays 10% of the funds at risk, which ties the reward to the pool rather than to the whole chain. The clear exception is bridges such as Wormhole, where dollars concentrate and the $10 million ceiling still leads the market.
How did Sui recover $162 million after the Cetus hack without paying the hacker?
Sui’s 114 validators deployed patched code that froze roughly $162 million of the stolen funds by refusing to process the attacker’s transactions, an action the thief never authorized. About $63 million that had already been bridged to Ethereum escaped, because a validator freeze only works while the funds remain on-chain and the validator set agrees to act.
Do I owe US taxes on a Solana bug bounty paid in locked SOL?
Yes. In the United States a bug bounty is treated as ordinary income, reported on a Form 1099-NEC and Schedule C and taxed at its dollar value on the day it is received. If the reward is paid in SOL locked for a year, you can owe tax on a value you cannot yet sell, and the token can fall before the lock expires.
Is it legal to exploit a live contract to rescue funds and claim a bounty?
In the United States it is a legal gray zone under the Computer Fraud and Abuse Act, and neither the SEC nor the Department of Justice has endorsed self-help hacking. Safe-harbor frameworks try to pre-authorize good-faith action during an active exploit, but they protect only the protocols that adopt them and usually cap the reward.
By Anneke de Vries, security desk, HOGE Wire.