finds.dev← search

// the find

Frankcastleauditor/Solana-Audit-Arena

★ 121 · Rust · updated Sep 2026

Weekly Solana smart contract security competition, audit programs, find bugs, and build your on-chain security track record.

A weekly CTF-style security competition where a new intentionally-vulnerable Solana/Anchor program drops every Monday and researchers submit findings as GitHub Issues with a working PoC. It's for people trying to build a public track record in Solana security research, not a library or tool you'd pull into a project.

The targets are hand-written, varied programs (staking vaults, bonding curves, x402 payment rails, agent delegation) rather than recycled CTF boilerplate, so the bug classes actually map to what's shipping in production. Judging happens entirely in public GitHub Issues, which means the Issues tab doubles as a growing, searchable archive of real Solana vulnerability patterns — genuinely more useful for learning than a closed leaderboard. The submission template forces a PoC and a specific impact statement instead of vague severity claims, which cuts down on noise compared to typical bug bounty triage.

Scoring and validity calls rest entirely on one person with no appeals process beyond 'comments shape my read' — that's a single point of failure and a bias risk once the program has any money or reputation riding on it. There's no CI, no fuzzing harness, and no shared test scaffolding across the target repos (just ad hoc Anchor projects with a handful of TypeScript tests), so each week you're rebuilding your own environment from scratch. First-finder-wins via Issue timestamp is easy to snipe and the repo doesn't say anything about detecting sybil accounts or coordinated submissions beyond a 'solo entries only' rule on the honor system.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →