Colosseum Codex: Alpenglow Bug Bounty, Quantumglow, 0x Swap API

Alpenglow 50k SOL Bug Bounty Program, Quantum Resistant Alpenglow, 0x Swap API Beta, BAM's Maker Priority Plugin

Share
Colosseum Codex: Alpenglow Bug Bounty, Quantumglow, 0x Swap API

This issue's biggest items aren't about this week at all, they're about the future of Solana. Community signaling opened on SIMD-0550 and SIMD-0553, both aiming to tighten SOL supply, and it's the first real run of the new Solana Governance Proposals process, so I'll cover the results once voting closes. Anza published a quantum-resistant version of Alpenglow and launched a 50k SOL bug bounty, the last wide-open look at the new consensus code before mainnet.


πŸ”₯ Alpenglow Bug Bounty

Anza is running a two-week bug bounty competition on Alpenglow with a prize pool up to 50,000 SOL. It opened Aug 5 and closes Aug 19, 2026.

Alpenglow is the biggest consensus change in Solana's history. It retires Proof of History timing and TowerBFT voting in favor of Votor (validator voting) and Rotor (block propagation layer). Target finality is 100 to 150ms, down from 12.8 seconds. It shipped as SIMD-0326 and is headed to mainnet this year. 

Alpenglow sat outside the standard Agave bounty through development and internal audits, so this is its first real exposure to outside researchers. The code under review lives in anza-xyz/agave, not the alpenglow repo. 

Core crates in scope are:

  • votor: Event loop, consensus pool, voting service, vote history, timers, rooting
  • votor-messages: Certificate and vote serialization, migration handover
  • bls-sigverify and bls-cert-verify: Certificate verification and stake-threshold checks
  • Plus named integration points in core, runtime, entry, ledger, and turbine

Out of scope are TowerBFT-only paths, leader-only block emission, scaffolding behind inactive features, test code, and bugs in the underlying BLS12-381 dependency, which go upstream. The TowerBFT-to-Alpenglow migration path is explicitly included, as are SIMD-0337 fast leader handover and SIMD-0357 validator admission. 

The governing test is whether a fault "occurs only because the Alpenglow feature is active, wherever in the tree it lives." 

Scope is a moving target by design. It tracks master HEAD continuously, so code landing mid-window is immediately eligible and the standing one-week-on-master rule is waived. Each report has to cite the specific commit where the bug was found, and the bug has to still be unfixed on master at submission time. If a fix lands first, the finding becomes ineligible retroactively.

Rewards vary by impact and severity:

  • 315 to 1,250 SOL for DoS
  • 1,250 to 5,000 SOL for liveness
  • 3,125 to 12,500 SOL for a consensus or safety violation
  • 6,250 to 25,000 SOL for loss of funds

Multiple findings at the same level do not raise the ceiling, and if total awards exceed the unlocked pool everyone gets cut pro rata. Payouts are lump sum after adjudication and KYC, in SOL locked for 12 months.

Submissions go through the Alpenglow bug bounty portal and are gated behind a non-refundable 0.5 SOL burn. 

A working proof of concept is required at every severity, demonstrated on a local fork, multi-node harness, or simulation. Attacking mainnet or public testnet is not authorized, and reports without a reproducing PoC "are closed as speculative." 

Anza commits to a first response within 72 hours and an initial severity call within 7 days. Public disclosure anywhere disqualifies a finding, and on duplicates the whole reward goes to the earliest report that substantiates the issue at its assessed severity, not its claimed one.

Alpenglow rips out two core parts of Solana and replaces both at once. Audits aren't enough when we're talking about what gets finalized. Yeah, your payout is locked for 12 months, but spend that year holding a network that is more secure because you showed up!

Alpenglow Bug Bounty Competition


πŸ›‘οΈ Quantumglow

Anza published Quantumglow, a post-quantum version of Alpenglow that keeps the protocol's finality speed instead of trading it away for quantum resistance. 

Swapping in post-quantum signatures naively does not work, because they are far larger than the EdDSA and BLS signatures Alpenglow uses. Worse, BLS aggregation has no post-quantum equivalent. The candidates need 10s to 100s of KB and take seconds to aggregate.

Quantumglow works around both. 

Votes are signed with Ax, a custom hash-based scheme built for the protocol, with signatures squeezed into single packets using pre-cached validator keys and omitted Merkle paths. Aggregation is dropped entirely and replaced by lightweight approval messages, and per-shred signatures collapse into one block commitment authenticated over Rotor. 

Blocks still fast-finalize the moment 80% of stake notarizes, with the extra approval round reserved for misbehavior or network trouble. Security assumptions and the safety and liveness properties are unchanged.

Threats from quantum attacks are real, but still a long way off. Baking the answer into the protocol now means Anza is solving the problem before it happens.

Quantumglow: Will Solana’s Performance Survive Quantum Computing?


πŸ”€ 0x Swap API on Solana

0x put its Swap API on Solana in open beta, the first time the aggregator has supported a non-EVM chain. It covers SPL tokens, native SOL, and Token2022 assets across 10+ liquidity sources.

The design point for builders is that swap-instructions returns a quote, a route plan, and instructions rather than a finished transaction. 0x never submits anything or sets priority fees, so signing, submission, and compute budget stay on your side. 

The response reserves transaction bytes for your own instructions, supports Address Lookup Tables for multi-hop routes, handles associated token account creation, and can send output to a different address than the taker. 

0x reports 99.97% uptime and median quote response under 250ms, and says its quotes survive simulation 97.8% of the time, which is its own measurement rather than a third-party benchmark. Kamino, Titan, Matcha Meta, and Relay used the API during closed beta.

Swap fees are zero during the beta. After that, integrators can take a percentage on either side of a swap, with multiple fee recipients allowed in one transaction.

0x has been EVM-only its entire life, so Solana being the first chain outside of that says more about where swap volume occurs than any comparison chart.

0x Swap API on Solana is now in open beta


⚑ BAM's Maker Priority Plugin

Jito published three-month results for the Maker Priority Plugin, BAM's first implementation of Application Controlled Execution (ACE).

MPP inserts enrolled market maker transactions at the top of every micro-batch BAM schedules within a slot, ahead of all other traffic, so oracle updates land in the same slot without routing through multiple landing services or guessing at fees.

Seventeen programs are onboarded, including SolFi, Tessera, Scorch, BisonFi, ZeroFi, and Archer, accounting for over $500M in daily spot volume. About 39% of oracle updates in BAM slots from enrolled users now land through MPP.

BAM schedules into roughly eight 50ms market ticks per slot, which spreads updates evenly through the slot instead of letting them cluster. Jito also cut the fee to 1 lamport per CU per transaction and shipped multi-market updates plus transaction, batch, and simulate endpoints. An intra-slot clock is next.

The plugin itself is for market makers, but ACE lets an app define how its own transactions get scheduled inside a block. MPP is just the first thing anyone built with it.

An Update on BAM’s Maker Priority Plugin


⭐ Highlights

Optimizing Solana Programs with sBPF - Subh
A guide to compute optimization based on how the sBPF VM actually executes rather than a list of tricks.

The Simple Economics of L1 Value Capture - @MaxResnick
If you've ever wondered how to actually value SOL, this is a serious attempt at it.

Introducing @theshiptalk: A new home for Solana Ship Talk - @solana_stream
A live, weekly session with Colosseum builders on what traction actually looks like after the hackathon.


⚑ Quick Hits

Superteam USA resident builder application and website are live - @SuperteamUSA

Speaker applications are now open for Scale or Die London - @solana_devs

Lamport Press: Solana program examples explained as books - @moviendo_me

Official Solana MCP adopts the new MCP spec - @dev_jodee

Career advice for people trying to break into crypto - @kashdhanda

Openfort now supports Jito bundling on Solana, powered by Quicknode - @openfort_hq



βš™οΈ Tools & Resources

harness-trade - An open-source Solana trading terminal built in TypeScript with SvelteKit and Bun, putting Phoenix perps and Jupiter spot swaps behind one account.

sbpf-eye - A Rust tool for inspecting compiled Solana sBPF programs, extracting instructions, basic blocks, function entry points, reachability, and direct call edges from the text section of a .so file.

falcon - An AVX-512 implementation of Falcon post-quantum signature verification, written in C and originating from the Firedancer project. Ships with benchmarking tools and correctness tests in a self-contained codebase.


πŸ’“ Ecosystem Pulse

🚨 Tuktuk crank turners drained for 36.6 SOL - A bug let anyone schedule a task that made a crank turner sign a SOL transfer out of its own wallet. It only reached the SOL that turners keep on hand to pay tx fees, so no protocol funds, crank rewards, or regular users were touched, and a patch has already been applied.


🎧 Listen to This

Bits to Bricks

Brandon Arvanaghi, CEO of Meow, joins Amira Valliani on Bits to Bricks to talk about what happens when AI agents get their own bank accounts.

Meow is the first fintech to let an agent open a business account and issue virtual cards, and it exposes an MCP endpoint so Claude, ChatGPT, Cursor, or Gemini can connect to banking infrastructure directly.

The conversation covers the shift from traditional banks to fintech, where stablecoins fit into that, and how agents change day to day financial operations for a business.

The Future of Banking with AI Agents - Meow


πŸ“… Event Calendar

Colosseum Demo Day: Accelerator Cohort V, San Francisco, CA, Aug 26
Colosseum hosts its first in-person demo day, where 21 teams from the Frontier Hackathon pitch after eight weeks of building in San Francisco. Doors open at 10:00 AM with pitches starting at 11:00 AM, followed by a founder mixer lunch. Registration requires host approval and is aimed at investors, operators, and builders in the Solana ecosystem.


πŸ‘©β€πŸ”§ Get Hired


SIMD-0550 and 0553 need 15% of active stake by August 18 and they're sitting under 6%. Do you know how the validator you're staked with is voting, and did you know you can override it?"

Thanks for reading ✌️

Follow me on X!