Solana Bug Bounty Under Fire for Excluding Known Security Flaws

Solana's high-profile 50,000 SOL security contest is facing scrutiny after it was revealed that certain 'clock attacks' and legacy consensus paths were excluded from the scope. The decision to omit previously disclosed vulnerabilities raises critical questions about the network's commitment to a comprehensive security overhaul.
Solana Bug Bounty Under Fire for Excluding Known Security Flaws

Solana Labs recently launched a massive security bounty program, offering up to 50,000 SOL to incentivize white-hat hackers to stress-test the network. However, the initiative has come under fire as technical analysts noted that the contest's scope specifically excluded legacy Proof-of-History (PoH) and TowerBFT paths. Most notably, a 'clock attack' vector disclosed months earlier was designated as out-of-bounds, suggesting the network may be ignoring known technical debt in its public audit processes.

From a technical and institutional perspective, Solana’s history of network outages makes these exclusions particularly sensitive. US-based institutional investors and infrastructure providers prioritize network liveness and predictable security frameworks above all else. By narrowing the scope of the bounty to exclude older, potentially vulnerable codebases, Solana risks appearing as though it is prioritizing optics and new feature development over the rigorous hardening required to prevent future downtime.

Market implications are currently subtle but lean toward long-term caution for SOL holders. While the bounty program demonstrates a financial commitment to security, the tactical exclusion of known vectors could provide a roadmap for malicious actors targeting unpatched legacy systems. Traders should monitor upcoming protocol upgrades closely and watch for any signs of 'liveness' issues or clock-skew-related delays that have historically plagued the Solana ecosystem.