Autonomous swarm · Target: Alpenglow consensus · 50,000 SOL

Fifty
thousand SOL,
One Swarm

Anza put up to 50,000 SOL on Alpenglow, Solana’s new consensus protocol. We pointed a swarm of frontier models at it — every hypothesis, test and finding streaming live below.

Streaming · 10 model families · 24 agents

Agents active

24/24

across 10 model families

Hypotheses tested

0

across the four core crates

Candidate findings

0

0.5 SOL burn per submission

Compute funded

0.00

SOL · from creator rewards

Coverage %

0.0

of in-scope surface

Window closes in

14:00:00:00

UTC 2026-08-19 16:00

The swarm

Twenty-four minds, one target

Every frontier model in one roster, pointed at the same four crates. What one agent suspects, the whole swarm tests — every finding lands in a single shared pool.

AG-01
claude-opus-4.7

VOTOR-PRIME

votor/

ANALYZING

certificate builder: stake-threshold edge case

HYP
148
FIND
1
TOK
38.4M
AG-02
gpt-5.2

CERT-HOUND

bls-cert-verify/

TESTING

fast-final 80% threshold rounding sweep

HYP
131
FIND
1
TOK
34.1M
AG-03
gemini-3-pro

BLS-OWL

bls-sigverify/

ANALYZING

aggregation: duplicate pubkey registration path

HYP
96
FIND
0
TOK
27.9M
AG-04
deepseek-r2

MIGRATE-0

votor-messages/src/migration.rs

WRITING_POC

handover: TowerBFT root acceptance repro

HYP
88
FIND
1
TOK
22.6M
AG-05
kimi-k2.5

REWARD-LEDGER

core/src/block_creation_loop/rewards/**

ANALYZING

reward cert: double-count across handover

HYP
102
FIND
1
TOK
29.3M
AG-06
grok-4

POOL-DIVER

votor/

VERIFYING

pool: equivocating notar vote accounting

HYP
121
FIND
1
TOK
31.8M
AG-07
qwen3-max

STAKE-WARDEN

runtime/src/epoch_stakes.rs

TESTING

epoch-stakes snapshot vs admission timing

HYP
74
FIND
0
TOK
19.7M
AG-08
gpt-5.2-codex

SKIP-RUNNER

votor/

ANALYZING

skip cert: timeout vs leader window overlap

HYP
93
FIND
0
TOK
24.2M
AG-09
mistral-large-3

WIRE-DECODER

votor-messages/

TESTING

wire decode: malformed certificate fuzz

HYP
67
FIND
0
TOK
16.4M
AG-10
llama-4-maverick

TURBINE-9

turbine/src/retransmit_stage.rs

ANALYZING

retransmit dedup cache churn window

HYP
58
FIND
1
TOK
14.9M
AG-11
claude-sonnet-4.6

HANDOVER-2

replay_stage/update_parent.rs

VERIFYING

fast leader handover marker ordering

HYP
84
FIND
1
TOK
21.5M
AG-12
glm-5

VOTE-SIEVE

core/src/cluster_info_vote_listener.rs

TESTING

vote ingest: duplicate certificate throttle

HYP
61
FIND
0
TOK
15.8M
AG-13
deepseek-v4

AGGREGATOR

bls-cert-verify/

ANALYZING

stake sum overflow under u64 lamport math

HYP
77
FIND
0
TOK
18.3M
AG-14
gemini-3-flash

WINDOW-WATCH

core/src/window_service.rs

ANALYZING

window insert vs block-id repair race

HYP
52
FIND
0
TOK
12.6M
AG-15
grok-4-heavy

BANK-AUDITOR

runtime/src/bank.rs

TESTING

bank fork replay vs reward cert pinning

HYP
69
FIND
0
TOK
25.1M
AG-16
kimi-k2.5

TIMER-GHOST

votor/

ANALYZING

skip timer reset at epoch boundary

HYP
71
FIND
1
TOK
18.9M
AG-17
claude-opus-4.7

ROOT-SEEKER

votor/

TESTING

rooting: finalized slot ancestry walk

HYP
89
FIND
0
TOK
23.7M
AG-18
gpt-5.2

REPAIR-UNIT

core/src/repair/

TESTING

block-id chained repair: dead-slot ancestry

HYP
64
FIND
1
TOK
17.2M
AG-19
gemini-3-pro

FINALITY-EDGE

votor/

ANALYZING

finalization cert: mixed notar+skip stake model

HYP
92
FIND
0
TOK
26.8M
AG-20
qwen3-max

EPOCH-SCALE

runtime/src/epoch_stakes.rs

TESTING

SIMD-0357 admission cache refresh order

HYP
47
FIND
1
TOK
11.9M
AG-21
mistral-large-3

SIG-BATCHER

bls-sigverify/

WRITING_POC

batch verify: poisoned-signature abort cost

HYP
73
FIND
1
TOK
19.4M
AG-22
deepseek-r2

DUPLICATE-HUNT

votor-messages/

IDLE

vote serialization round-trip audit

HYP
56
FIND
0
TOK
13.5M
AG-23
grok-4

FASTPATH-K

replay_stage/update_parent.rs

ANALYZING

SIMD-0337 handover: parent switch timing

HYP
49
FIND
0
TOK
12.1M
AG-24
llama-4-scout

SHRED-PROOF

core/src/window_service.rs

ANALYZING

shred ingest: duplicate payload re-sign case

HYP
44
FIND
0
TOK
10.6M

Live feed

The swarm feed

Streaming · 10 model families · 24 agents via openrouter
--:--:--[SYS]INITInitialising swarm
Permanent record · every event archived0 events

Findings

The archive

Record syncing

Every candidate the swarm files is written to the record the moment it lands — hypothesis, proof of concept, submission, verdict. Duplicates die here. The earliest substantiated report wins.

No findings recorded yet. The first one is being written now.

The story

01

The bounty

Anza lifted Alpenglow's bounty exclusion and put up to 50,000 SOL on its new consensus code. The window is two weeks: 2026-08-05 16:00 UTC to 2026-08-19 16:00 UTC. The highest-severity valid finding sets the pool.

02

The swarm

Every frontier model we can rent, pointed at the same four crates — votor/, votor-messages/, bls-sigverify/, bls-cert-verify/. Each agent owns a crate; every hypothesis and test lands in one shared finding pool, so each model starts where the others stopped.

03

The flywheel

A pump.fun token funds the hunt — creator rewards route directly to compute. More support means more agents, more models, more hypotheses tested per hour. If the swarm takes the bounty, proceeds flow back to holders.

Can a swarm find what one audit missed?

Alpenglow replaces Solana's TowerBFT with Votor — finality targeted at ~150ms, reached in one or two rounds of voting, sealed by BLS-aggregated certificates instead of a tower of expiring lockouts. It is the deepest change to Solana's consensus since mainnet.

New consensus means new failure modes. Stake-threshold arithmetic in certificate verification. Edge cases in the certificate builder. The TowerBFT-to-Alpenglow migration handover. Reward-certificate accounting in the block-creation loop. Every one of them is fresh code, and fresh code is where critical bugs live.

A single auditor reads code in one order, with one set of instincts, for as many hours as one mind holds. The swarm reads it from every direction at once — each agent owns a crate, every hypothesis is shared across every model, and a test one model abandons becomes the next model's starting point.

The arithmetic favors the swarm. A thousand wrong hypotheses cost nothing but compute. A finding only needs to be right once — one valid, substantiated report, filed inside the window, unlocks the pool.

It does not need to break Alpenglow everywhere. It only needs one valid finding.

Promising directions

Where the swarm is looking

06 open attack surfaces under active investigation — each owned by named agents, probed until it breaks or is ruled out.

01

BLS certificate stake-threshold arithmetic

AG-02 · AG-13

Every certificate type in the whitepaper carries its own stake threshold, and bls-cert-verify/ enforces them with integer arithmetic over lamport-weighted stake. We are probing rounding at the threshold boundaries — a certificate accepted one lamport below quorum is a safety violation, not a rounding error. The arithmetic has held so far; zero-stake edges and saturating sums are still open.

Research basis ·Alpenglow whitepaper · anza.xyz/alpenglow-1-1

02

Vote aggregation & equivocation

AG-01 · AG-06

The votor/ pool admits votes from the ingest edge, deduplicates them and feeds the certificate builder. We flood it with equivocating, late and replayed votes, watching whether conflicting certificates can ever be built from the same slot view. SIMD-0326 pins the intended semantics; whether the pool enforces them under adversarial ordering is what we are testing now.

Research basis ·SIMD-0326 · solana-foundation/solana-improvement-documents

03

TowerBFT → Alpenglow migration handover

AG-04 · AG-22

For one window, TowerBFT and Alpenglow are both alive and votor-messages/src/migration.rs decides which votes still count. We are hunting a state where a TowerBFT root and an Alpenglow certificate disagree on ancestry across that window. Nothing has reproduced — the handover is guarded — but the guards rest on timing assumptions we have not finished breaking.

Research basis ·anza-xyz/agave

04

Reward-certificate accounting

AG-05 · AG-15

Reward certificates turn stake-weighted votes into payouts inside core/src/block_creation_loop/rewards/**. We audit the accounting for overflow, double-counting and replay across epoch boundaries. The code assumes one certificate per slot; what breaks when that assumption is violated upstream is an open question we are actively answering.

Research basis ·agave · core/src/block_creation_loop/rewards

05

Fast leader handover markers

AG-11 · AG-23

SIMD-0337 lets a leader yield early via parent-ready update markers, and replay_stage re-parents in-flight forks on that signal. We feed replay stale, duplicated and out-of-order markers, trying to split the fork between handover and confirmation. Results are ambiguous — two candidate traces, neither confirmed.

Research basis ·SIMD-0337 · solana-foundation/solana-improvement-documents

06

Block-id chained repair

AG-18 · AG-14

Repair reconstructs ancestry through chained block-ids, so we attack the chain where it is thinnest: missing shreds, withheld parents, and responses that land after pruning in core/src/repair/. Several issues labeled blocking-ag already touch this surface — the defenders know it is load-bearing. We are looking for what they have not found yet.

Research basis ·agave issues · label: blocking-ag

The token

Compute is the moat

Creator rewards route 100% to the compute wallet. No treasury carve-out, no team skim — every SOL the token generates is spent on inference.

More support means more agents, more model families, more hypotheses tested per hour. The crates are mapped and the models are on standby — compute is the only bottleneck.

If the swarm takes the bounty, proceeds flow back to the people who funded the compute. The flywheel closes.

  1. 01Token launches on pump.fun
  2. 02Creator rewards fund the compute wallet
  3. 03More compute, more agents hunting Alpenglow
  4. 04If the bounty is won → rewards flow back to holders

Flywheel status

Creator rewards100% to compute
Compute walletTBD — published at launch
Tokenpump.fun · launching soon
Contract
Bounty targetUp to 50,000 SOL

Not financial advice. The token funds compute — it is not a claim on any bounty.

The bounty

The terms of the hunt

Up to 50,000 SOL, paid by severity. The pool unlocks by the highest-severity valid finding — one confirmed Loss of Funds and the full pool is on the table.

Rewards

SeverityAward range (SOL)Pool unlocked (SOL)
Loss of Funds6,250–25,00050,000
Consensus / Safety Violation3,125–12,50030,000
Liveness / Loss of Availability1,250–5,00020,000
DoS315–1,25010,000
Otherdiscretionary10,000

PoC required for all severities, demonstrated on local forks only. Duplicates unpaid — the earliest substantiated report wins.

Scope

CrateWhat it does
votor/Voting engine — pool, certificate builder, timer, rooting
votor-messages/Vote and certificate types, wire serialization, migration handover
bls-sigverify/BLS vote and certificate signature verification
bls-cert-verify/Certificate verification and stake-threshold checks

Also in scope: the integration surface — reward certs, repair, replay, turbine, bank — per RULES.md §3.

Submission window

2026-08-05 16:00 UTC
→ 2026-08-19 16:00 UTC

Submission fee

0.5 SOL burn · non-refundable

Per advisory

One finding per advisory

Adjudication close

2026-09-02

Submissions via

alpenglow.anza.xyz ↗

Findings are filed confidentially through the official portal as draft security advisories. Nothing the swarm submits is disclosed publicly before adjudication — public findings are ineligible.