Colosseum Codex: Summer School, Anchor v2, Solana Mobile Bug Bounty

Solana School Fall Class, Anchor v2 RC1, Solana Mobile Bug Bounty

Share
Colosseum Codex: Summer School, Anchor v2, Solana Mobile Bug Bounty

The gap between learning and shipping on Solana got smaller this week, on both the training side and the tooling side. Solana School is the one that matters most, teaching Pinocchio, Anchor, and Geyser to people who've never written a Solana program, in the same week Anchor v2 makes programs 90% smaller and 3-6x faster.


🏫 Solana School: Fall Class

The Solana Foundation opened applications for Solana School: Fall Class, a free seven-week cohort program running August 31 through October 16.

Sessions run virtually Monday, Wednesday, and Friday for 1.5 hours each, roughly 21 live classes in total. Every class ends with working code.

The course opens on Solana architecture, PDAs, and environment setup. From there, students build vault and escrow projects in Anchor, work through Token 2022 and transfer hooks, and write native Rust with Pinocchio alongside compute unit optimization. The later weeks cover Metaplex, Codama and client generation, and indexing with Geyser and real-time streams.

Between sessions, students get a challenge to solve on their own, then bring it back and debug it as a group in the next class. That works out to about 31 hours of live instruction over the seven weeks, plus whatever the solo challenges take. Working Solana developers give guest lectures, and Solana Foundation DevRel holds open office hours for the cohort.

This is the second cohort, and the entry requirements changed. The summer class was limited to current college students with a valid school email, while the fall class is open to any developer who applies. Registration goes through Luma and requires host approval. The curriculum assumes foundational coding ability but no prior Solana experience.

The program ends with Demo Day on October 16, where students present what they built. The announcement calls that pitch "a dry run for the one that could land them a spot in a Colosseum Accelerator cohort with $250,000 in pre-seed funding."

Teaching Pinocchio, Codama, and Geyser to people who have never written a Solana program means this cohort graduates ready to ship production apps.

Solana School: Fall Class


βš“ Anchor v2 RC1

OtterSec released the first release candidate for Anchor v2, a complete rewrite of the framework on top of Pinocchio. The announcement puts programs at over 90% smaller than v1 and 3 to 6 times cheaper in compute. The v2 docs go further, citing benchmarks up to 94% smaller and 50.4x fewer CU.

The rewrite trades v1's macro-heavy design for a trait-based architecture with less boilerplate and clearer constraints. Crates are #![no_std] compatible with alloc on by default. Teams can add their own constraints through the derive system, and swap in a custom entrypoint when a hot path needs it.

Fuzzing is on by default, through an integration with Crucible, a coverage-guided fuzzer for Solana programs built by Asymmetric Research, run with anchor fuzz.

The release also adds anchor debugger for step-by-step test debugging, anchor coverage for lcov output, and anchor test --profile, which wraps LiteSVM to produce debugger traces. The release candidate went through two independent audits.

I'm glad OtterSec is giving Anchor some love with major updates like this. V2 is going to be the best of both worlds.

Anchor v2.0.0-rc.1 is here


πŸ•΅οΈβ€β™€οΈ Solana Mobile Bug Bounty

Solana Mobile published a vulnerability disclosure policy and opened a bug bounty program alongside a separate security grants track.

Bounties run across four tiers: 

  • Tier 1 - Critical: Funds at risk, no user action required, up to $75,000
  • Tier 2 - High: Funds at risk, user action required, up to $37,500
  • Tier 3 - Medium: Denial of service, up to $15,000
  • Tier 4 - Low: Cosmetic UI or invalid copy, up to $750

Submissions need to be complete to qualify with a working proof-of-concept code, and an impact assessment.

Bounties are paid in SKR under a signed Award Agreement rather than a direct wallet transfer. The token quantity is calculated using the 7-day volume-weighted average price at the time the vulnerability is validated as resolved, and vesting starts 30 days after that resolution. Delivered tokens carry a 12-month use restriction before they reach the researcher's wallet.

Solana Mobile is also introducing Security Grants as part of its broader grants program, a separate track from the bug bounty aimed at funding security research rather than paying out for specific found vulnerabilities. 

Introducing the Solana Mobile Vulnerability Disclosure Policy, Bug Bounty Program, and Security Grants


⭐ Highlights

Solana's Road From 400ms to 200ms Slots - @a26nine
Why this matters for speed, epochs, finality, and keeping a global validator set.

Live bug bounties, real payouts, from $8M+ - @rektoff_xyz
A roundup of bug bounties across the Solana ecosystem.

Solana's newest brand refresh - @clockwrrk
A fun look at the history of Solana branding over the years and how we got to where we are now.

How I Went From ETH Maxi to Solana Maxi - @tomi204
Why Solana's culture of rewarding devs who ship beats rewarding research without products.


⚑ Quick Hits

▢️ How Solana Mobile Apps Talk to Wallets - @beeman_nl

Transaction v1 and the ALT Trade-off - Solana

Solana Foundation joins the Agentic Payments Alliance - @SolanaFndn

Anza Is Activating 1st Slot Time Reduction on Mainnet - @bw_solana

▢️ Solana: the greatest comeback in crypto history - @JupiterExchange

Solana Changelog: August 20 - @solana_devs



βš™οΈ Tools & Resources

Build Web3 - A plugin that loads Quicknode's product knowledge into AI coding agents so generated code uses real method signatures and schemas. It pairs a build-web3 skill with Quicknode's MCP server.

LocalWallet - A Tauri desktop app for managing many Solana wallets at once, with keys in a local vault encrypted using Argon2id and XChaCha20-Poly1305. It runs batch balance checks across SPL Token and Token-2022, closes empty accounts to reclaim rent, and manages stake accounts.

Solana SQL API - A SQL interface from Coinbase Developer Platform for querying roughly three months of Solana transfers and decoded SPL Token and Token-2022 instructions. Queries run against the solana.transfers and solana.instructions tables, either in a browser playground that needs no API key or through a REST endpoint.


πŸ’“ Ecosystem Pulse

πŸ’€ Printr winds down - Printr began returning staked positions and earned fees to depositing wallets on August 18, and the app goes offline after August 31 with the planned TGE and airdrop cancelled.


🎧 Listen to This

oxResearch

Crypto’s next breakthrough could come from fundamentally rethinking how companies are built, funded, and governed.

This week, Michael Rinko from Colosseum joins 0xResearch to explore how MetaDAO, Colosseum, and Solana are reshaping startup formation, governance, and distribution, touching on futarchy, internet capital markets, tokenized equities, AI-powered builders, and where consumer crypto goes next.

Can MetaDAO Reinvent Crypto Capital Formation?


πŸ“… Event Calendar

Colosseum Demo Day: Accelerator Cohort V, San Francisco, CA, Aug 26
Colosseum hosts its first in-person demo day, where 21 teams from the Frontier Hackathon pitch after eight weeks building in San Francisco. Doors open at 10:00 AM with pitches starting at 11:00 AM, followed by a founder mixer lunch. Registration requires host approval and is aimed at investors, operators, and builders in the Solana ecosystem.


πŸ‘©β€πŸ”§ Get Hired


Solana Mobile's top tier pays up to $75,000 for a critical bug. There's $8M+ out there to be won. Have you ever submitted to a bug bounty, and did you get paid for what you found?

Thanks for reading ✌️

Follow me on X!