
Announcing the [REDACTED] Hackathon Winners
For the entire month of April, Solana’s research, forensics, and security ecosystems competed for over $175,000 in bounties for the [REDACTED] Hackathon.
In total, the hackathon attracted 38 bounties and 926 submissions!
Thank You
To every participant: thank you for your hard work and contributions to the Solana ecosystem. Your enthusiasm for research, writing, and securing the network inspires all of us.
To all of the sponsors: thank you for donating your time, energy, and money to make this hackathon a success. You keep Solana safe every day, and make it the best place for founders to build.
To our friends at Superteam Earn: this hackathon wouldn’t have been possible without you. Thank you for the countless evenings helping us plan and execute on such a fast timeline.
Now, let’s celebrate the winners!
Below is every bounty and the top three winners.
Some bounties awarded more than three prizes. To see those winners, visit the official hackathon page or the respective bounty listing which is linked in each section.
Arkham: X ICOs ($16,250)
Arkham sponsored four bounties totaling $35,000!
Their largest bounty centered on investigating Initial Coin Offerings (ICOs) conducted or promoted through X.
🥇 1st: X-Based ICOs within Solana Ecosystem
🥈 2nd: What Happens When You Give Six Clowns $101M in 4 Days?
🥉 3rd: ICO Submission Links Collection
Range: War Games ($15,000)
This bounty from Range focused on mapping out routes bad actors might take to launder stolen funds off of Solana. Participants were tasked with creating a comprehensive report on exfiltration methods and labeling associated wallets.
🥇 1st: Aksusarya_eth's Research
🥈 2nd: Its0xRay's Analysis on Exfiltration Routes
🥉 3rd: Intel_nuel's Report
SolBlaze: Liquid Staking and Validator Ecosystem Data ($10,000)
This bounty encouraged the development of platforms or algorithms to provide insights into liquid staking and SolBlaze’s bSOL token.
🥇 1st: https://x.com/PineAnalytics/status/1916847235397992611
🥈 2nd: https://x.com/w3e_uk/status/1917629535450698185
🥉 3rd: https://x.com/tubaecci/status/1917633073673384186
RugCheck: Onchain Analysis ($7,000)
This open-ended bounty invited participants to use RugCheck APIs to build projects focused on identifying suspicious trading patterns, visualizing wallet relationships, profiling risky behaviors, and implementing preventative measures against scams.
🥇 1st: https://x.com/Dev_Syrem/status/1913577188957315120
🥈 2nd: https://github.com/Ge0frey/chainprobe
🥉 3rd: Josh0007-sunday's Analytics DeFi Portfolio
Arkham: Pump.fun ($6,250)
This bounty focused on using the Arkham Intel platform to identify and analyze activities related to serial Pump.fun deployers who make money by bundling and rugging tokens.
🥇 1st: Exit Liquidity Machines
🥈 2nd: OpenBook on Serial Deployers on Pumpfun
🥉 3rd: WarmPotato2070
Arkham: Solana Snipers ($6,250)
This bounty called for research into Solana sniper bots, their mechanisms, and impact.
🥇 1st: Milliseconds to Millions: Snipers
🥈 2nd: Justice for Jerome Powell or Justification for Snipers?
🥉 3rd: Solana Snipers Analysis
Arkham: Solana Mixers ($6,250)
This bounty aimed to identify and analyze mixer platforms on Solana, their growth patterns, transaction volumes, and obfuscation techniques. The goal was to understand how these mixers are used to anonymize activity within the ecosystem.
🥇 1st: Tracing the Untraceable
🥈 2nd: Investigating Privacy Tools and Instant Swap Platforms
🥉 3rd: The Shadow Economy
Helius & Pashov Audit Group: History of Solana Security Incidents ($6,000)
This joint bounty with Pashov Audit Group called for a data-driven analysis of Solana's history of bugs, hacks, and security incidents. Researchers were asked to examine root causes, repercussions, and lessons learned from past vulnerabilities.
🥇 1st: A Comprehensive Analysis of Solana’s Security History
🥈 2nd: History of Solana Security Incidents: A Deep Dive
🥉 3rd: The History of Solana Security Incidents
GoFundMeme: Memecrime Scene Investigation ($5,269)
This bounty from GoFundMeme involved creating a dashboard to investigate activities related to memecoins and suspicious trading.
Helius: Malicious MEV and Sandwiching ($5,000)
This bounty focused on identifying and analyzing malicious MEV activities and sandwich attacks.
🥇 1st: MostlyData_ — Sandwiches on Solana
🥈 2nd: Fknmarqu
🥉 3rd: Solstatz
Helius: Account Dusting and Address Poisoning ($5,000)
This bounty aimed to quantify and address the issue of account dusting and address poisoning, where attackers send tiny amounts of crypto to spam users or try to trick them into sending money to fake addresses.
🥇 1st: Solana Account Dusting and Address Poisoning
🥈 2nd: TheLaughingMan
🥉 3rd: Spam to Scams
Jito: Jito's Role in Solana Deep Dive ($5,000)
This bounty asked for a deep dive into Jito's role within Solana. Specific aspects of Jito's MEV infrastructure, staking solutions, or governance were areas of exploration.
🥇 1st: Pine Analytics
Solana Foundation: Solana Forensic Analysis Tool ($5,000)
This bounty from the Solana Foundation asked participants to build a tool for tracking and visualizing the onchain movement of funds on Solana. The ideal solution would offer sophisticated transaction flow mapping, wallet analysis, and entity identification.
🥇 1st: https://github.com/Ge0frey/chainprobe
🥈 2nd: https://github.com/pramaths/SolanaOnchainFE
🥉 3rd: https://github.com/Assylum-Labs/forensic-analysis-tool
Messari: Crime Fighting AI Toolkit ($5,000)
This bounty challenged participants to use Messari’s AI Toolkit to generate novel, actionable insights related to crypto crimes and market events.
🥇 1st: Detectives vs Shillers: An Engagement Race
🥈 2nd: MessariMCP GitHub Repo
🥉 3rd: Solana Sentiment Analysis GitHub Repo
Superteam India: Solana Security Dashboard ($5,000)
This bounty from Superteam India aimed to expand the original Superteam Security handbook into a live, open-source dashboard. The dashboard was expected to cover all major exploits in the Solana ecosystem with onchain data, analytics, and resources for users.
🥇 1st: ST Security Dashboard
🥈 2nd: Superteam Security Dashboard Variant
🥉 3rd: Solana Security Dashboard Teal
Asset Dash: New Smart Wallet List & Signal Feed Bounty ($5,000)
This bounty challenged participants to propose a concept for a new Asset Dash feed that generates onchain alpha by identifying specific wallets and transactions worth monitoring.
🥇 1st: GMGN $ AXIOM Top Traders
🥈 2nd: Tracking Top Crypto Wallets
🥉 3rd: Next-Gen Whale Monitoring Feed
Ottersec & Squads: Securing Squads ($5,000)
This joint bounty from Ottersec and Squads focused on improving the signing experience for high-value transactions using Squads.
🥇 1st: https://github.com/hogyzen12/squads-go
🥈 2nd: https://github.com/AdedejiAdetola/securing_squads
🥉 3rd: https://crates.io/crates/secure-squads
Accretion: Reverse Engineering Closed Source Solana Programs ($5,000)
This bounty from the Solana security auditing firm Accretion, invited security experts to create of tools or guides for reverse engineering closed-source programs. Submissions could include tools to extract instructions, assist manual reverse engineering, or provide walkthroughs.
🥇 1st: IDLGuesser by @LeoQ7_
🥈 2nd: Lernean Lens by @bill_papas_12
🥉 3rd: MCP Solana Revving by @GSfilatino
Vybe: Vybe Telegram Bot Challenge ($5,000)
This bounty involved creating a Telegram bot that uses Vybe's APIs to deliver real-time, onchain analytics to crypto communities (e.g. wallet tracking, token metrics, or whale alerts).
🥇 1st: Scout by iamjoey.sol
🥈 2nd: mira4sol
🥉 3rd: Neeraj138
Guvenkaya: Web2 Security Issues in Web3 ($5,000)
This bounty from the Solana security auditing firm Guvenkaya focused on exploring how traditional web2 security vulnerabilities can lead to web3 vulnerabilities.
🥇 1st: Muhammad Abdullah
🥈 2nd: Cetin Mesum
🥉 3rd: Manish Kumar
Bubblemaps: Top Traders Bubblemaps ($4,000)
This bounty asked participants to use Bubblemaps’ visualization APIs to create a tool for connecting the top traders of specific tokens to reveal relationships between active trading wallets.
🥇 1st Place: https://github.com/0xmilarepa/top_traders_tool/
Meteora: Kelsier Ventures Blacklist ($3,850)
This bounty from Meteora offered rewards for creating a public blacklist of Solana wallet addresses associated with Kelsier Ventures.
🥇 1st: Submission Details - Issue #10 by Degenspy
🥈 2nd: Submission Details - Issue #6 by Dethective
🥉 3rd: Submission Details - Issue #22 by 0xbabushka
Dune: Data Storyteller ($3,000)
This bounty encouraged participants to use Dune dashboards to analyze and tell a story about a Solana-related subject or create a guide on analyzing Solana data with Dune.
🥇 1st: Adam_Tehc
🥈 2nd: Can We Rescue Trapped SOL from Pump.fun?
🥉 3rd: What Happens When Pump.fun Ditches Bonding Curves?
Sonic: Building Tools for the SVM Universe ($3,000)
This bounty focused on expanding Solana data analytics tools to Sonic and other SVM chains.
🥇 1st: Solar Bank App by Josephxu
🥈 2nd: Sonic Pulse GitHub Repository
LimeChain: Test and Give Feedback for Gimlet ($3,000)
This bounty invited developers and security researchers to test Gimlet, a new Solana step debugger. The goal was to gather feedback, find bugs, and propose improvements.
🥇 1st: Ubadineke Prince
🥈 2nd: David Luke
🥉 3rd: Pramath S
Token Metrics: Crypto Analysis Report ($3,000)
This bounty required participants to produce a crypto analysis report using Token Metrics' tools and methodologies.
🥇 1st: Arcaze
🥈 2nd: HogwartsofWeb3
🥉 3rd: @IamFantasy__
Nebula Node: Visualizing Solana Staking ($3,000)
This bounty from Nebula Node challenged participants to create a dashboard for visualizing Solana staking data such as validator performance, stake distribution, or node health.
🥇 1st: 4k_mira
Ded Monkes: Blockchain Visualization ($3,000)
This bounty from Ded Monkes focused on building an intuitive, interactive way to track protocols, wallets, transactions, and interactions on Solana.
🥇 1st: ShaunRiser
🥈 2nd: Dinesh_7rd
Civic: Integrate Civic Auth into Your Application ($2,800)
This bounty called for developers to integrate Civic Auth's Web3 SDK into their applications to enable embedded wallets for users.
🥇 1st: VersatileBeingX
🥈 2nd: Ge0frey_
🥉 3rd: Savin AjoSave Application
Flipside: Accelerate Data-Driven Insights into Solana's Growth ($2,500)
This bounty challenged participants to use Flipside's data to present insights that expose fraud, analyze liquidity movements, investigate user behavior, and investigate protocols and apps driving the most real economic value.
🥇 1st: Linking Validator Returns and Program Activity
🥈 2nd: Exit Liquidity Machines
🥉 3rd: Zkreum's X Post
DD.xyz: API Integration ($2,000)
This bounty involved integrating the DD.xyz API in apps by either displaying a DD score next to the asset or wallet in your UI or bot response, or to help control spam/sybil in your signup flow.
🥇 1st: Fystack
Phase Labs: Unpacking Solana's Economic Activity ($2,000)
This bounty from Phase Labs asked for research articles that unpack Solana's Real Economic Value (REV) and other economic activities.
🥇 1st: PineAnalytics
🥈 2nd: RalAndrewTalks
🥉 3rd: Suppvalen
Solscan: Monitoring Masters ($2,000)
This bounty encouraged participants to use Solscan's APIs to build a monitoring or scanning solution such as tracking DEX dynamics, whale activity, or correlating social sentiment with onchain activity.
🥇 1st: Vlad’s Solscan MCP
🥈 2nd: Swell’s doxdotfun
🥉 3rd: Rohan’s Solanautics
Artemis: Data Analytics ($2,000)
This bounty focused on developing SQL queries for MarginFi's key performance metrics (e.g., TVL, borrows, deposits, protocol fees, revenue) to be implemented on the Artemis platform.
At the time of publishing, no winners have been selected.
Note
The final deadline is Friday, May 16th at 11:59 pm UTC. As soon as we receive winners for this bounty, we will update this section of the blog.
Bubblemaps: Telegram Bot ($2,000)
This bounty asked for the development of a Telegram bot that, upon receiving a token contract address, would generate and return a Bubblemaps' screenshot and relevant token information.
🥇 1st: https://github.com/incryptomax/bubblemapstelegrambot
Validator.com: Malicious Validators ($750)
This bounty from Validator.com focused on identifying, analyzing, or creating tools to detect malicious Solana validator activity.
🥇 1st: Joshua Sunday
🥈 2nd: David Bassey
Validator.com: Sandwich Attack Shield ($750)
This bounty challenged participants to develop a "Sandwich Attack Shield," to protect users or protocols from sandwich attacks on Solana.
🥇 1st: Krystian Mejor
🥈 2nd: Faatih Mohammed
Supa Pump: Supa Sleuth Challenge ($500)
This bounty involved creating educational content or tools to uncover fake activity or fraud using Supa’s sleuthing features.
🥇 1st: Joshua Sunday
🥈 2nd: Evans Nwaozuzu
🥉 3rd: Nipheweb3 Emmanuel
Congratulations!
Congratulations once again to all the winners, and thank you to all of the sponsors and organizers!
Your contributions are invaluable to the growth and security of the Solana ecosystem.
Related Articles
Subscribe to Helius
Stay up-to-date with the latest in Solana development and receive updates when we post