2026-08-21 · solana-mobile
Solana Mobile has announced a formal vulnerability disclosure policy, a bug bounty program, and a new security grants initiative. The company says rewards can reach up to $75,000 in SKR for vulnerabilities affecting Seed Vault, SKR onchain programs, and Seeker Genesis Token infrastructure. This is a notable shift because it moves Solana Mobile further into platform-security mode. Instead of relying only on internal hardening, it is now paying external researchers to stress critical mobile wallet and device-adjacent infrastructure before attackers do.
The launch combines three pieces: a public vulnerability disclosure policy, a paid bug bounty program, and a security grants track for ecosystem research. Solana Mobile specifically names Seed Vault, SKR programs, and Seeker Genesis Token infrastructure as in-scope areas, and says EthelSec is the first security grant recipient.
This strengthens confidence in the Solana Mobile stack by creating clearer reporting paths and financial incentives for responsible disclosure. It also signals that mobile-native Solana security is becoming a first-class ecosystem concern rather than an afterthought around device launches.
Security researchers and builders working on Solana Mobile integrations should review the new disclosure and bounty rules immediately. Holders and developers using Seeker or Seed Vault-based flows should treat this as a positive signal that the mobile stack is being actively audited and opened to external scrutiny.
Read Original Post →