redacted hackathon winners
/Updates

Announcing the [REDACTED] Hackathon Winners

10 min read

For the entire month of April, Solana’s research, forensics, and security ecosystems competed for over $175,000 in bounties for the [REDACTED] Hackathon.

In total, the hackathon attracted 38 bounties and 926 submissions!

Thank You

To every participant: thank you for your hard work and contributions to the Solana ecosystem. Your enthusiasm for research, writing, and securing the network inspires all of us.

To all of the sponsors: thank you for donating your time, energy, and money to make this hackathon a success. You keep Solana safe every day, and make it the best place for founders to build.

To our friends at Superteam Earn: this hackathon wouldn’t have been possible without you. Thank you for the countless evenings helping us plan and execute on such a fast timeline.

Now, let’s celebrate the winners!

Below is every bounty and the top three winners.

Some bounties awarded more than three prizes. To see those winners, visit the official hackathon page or the respective bounty listing which is linked in each section.

Arkham: X ICOs ($16,250)

Arkham sponsored four bounties totaling $35,000!

Their largest bounty centered on investigating Initial Coin Offerings (ICOs) conducted or promoted through X.

🥇 1st: X-Based ICOs within Solana Ecosystem
🥈 2nd: What Happens When You Give Six Clowns $101M in 4 Days?
🥉 3rd: ICO Submission Links Collection 

Range: War Games ($15,000)

This bounty from Range focused on mapping out routes bad actors might take to launder stolen funds off of Solana. Participants were tasked with creating a comprehensive report on exfiltration methods and labeling associated wallets.

🥇 1st: Aksusarya_eth's Research
🥈 2nd: Its0xRay's Analysis on Exfiltration Routes
🥉 3rd: Intel_nuel's Report

SolBlaze: Liquid Staking and Validator Ecosystem Data ($10,000)

This bounty encouraged the development of platforms or algorithms to provide insights into liquid staking and SolBlaze’s bSOL token.

🥇 1st: https://x.com/PineAnalytics/status/1916847235397992611
🥈 2nd: https://x.com/w3e_uk/status/1917629535450698185
🥉 3rd: https://x.com/tubaecci/status/1917633073673384186 

RugCheck: Onchain Analysis ($7,000)

This open-ended bounty invited participants to use RugCheck APIs to build projects focused on identifying suspicious trading patterns, visualizing wallet relationships, profiling risky behaviors, and implementing preventative measures against scams.

🥇 1st: https://x.com/Dev_Syrem/status/1913577188957315120
🥈 2nd: https://github.com/Ge0frey/chainprobe
🥉 3rd: Josh0007-sunday's Analytics DeFi Portfolio 

Arkham: Pump.fun ($6,250)

This bounty focused on using the Arkham Intel platform to identify and analyze activities related to serial Pump.fun deployers who make money by bundling and rugging tokens.

🥇 1st: Exit Liquidity Machines
🥈 2nd: OpenBook on Serial Deployers on Pumpfun
🥉 3rd: WarmPotato2070

Arkham: Solana Snipers ($6,250)

This bounty called for research into Solana sniper bots, their mechanisms, and impact.

🥇 1st: Milliseconds to Millions: Snipers
🥈 2nd: Justice for Jerome Powell or Justification for Snipers?
🥉 3rd: Solana Snipers Analysis

Arkham: Solana Mixers ($6,250)

This bounty aimed to identify and analyze mixer platforms on Solana, their growth patterns, transaction volumes, and obfuscation techniques. The goal was to understand how these mixers are used to anonymize activity within the ecosystem.

🥇 1st: Tracing the Untraceable
🥈 2nd: Investigating Privacy Tools and Instant Swap Platforms
🥉 3rd: The Shadow Economy

Helius & Pashov Audit Group: History of Solana Security Incidents ($6,000)

This joint bounty with Pashov Audit Group called for a data-driven analysis of Solana's history of bugs, hacks, and security incidents. Researchers were asked to examine root causes, repercussions, and lessons learned from past vulnerabilities.

🥇 1st: A Comprehensive Analysis of Solana’s Security History
🥈 2nd: History of Solana Security Incidents: A Deep Dive
🥉 3rd: The History of Solana Security Incidents

GoFundMeme: Memecrime Scene Investigation ($5,269)

This bounty from GoFundMeme involved creating a dashboard to investigate activities related to memecoins and suspicious trading.

🥇 1st: Peplock
🥈 2nd: Oladayo

Helius: Malicious MEV and Sandwiching ($5,000)

This bounty focused on identifying and analyzing malicious MEV activities and sandwich attacks.

🥇 1st: MostlyData_ — Sandwiches on Solana
🥈 2nd: Fknmarqu
🥉 3rd: Solstatz

Helius: Account Dusting and Address Poisoning ($5,000)

This bounty aimed to quantify and address the issue of account dusting and address poisoning, where attackers send tiny amounts of crypto to spam users or try to trick them into sending money to fake addresses.

🥇 1st: Solana Account Dusting and Address Poisoning
🥈 2nd: TheLaughingMan
🥉 3rd: Spam to Scams

Jito: Jito's Role in Solana Deep Dive ($5,000)

This bounty asked for a deep dive into Jito's role within Solana. Specific aspects of Jito's MEV infrastructure, staking solutions, or governance were areas of exploration.

🥇 1st: Pine Analytics

Solana Foundation: Solana Forensic Analysis Tool ($5,000)

This bounty from the Solana Foundation asked participants to build a tool for tracking and visualizing the onchain movement of funds on Solana. The ideal solution would offer sophisticated transaction flow mapping, wallet analysis, and entity identification.

🥇 1st: https://github.com/Ge0frey/chainprobe
🥈 2nd: https://github.com/pramaths/SolanaOnchainFE
🥉 3rd: https://github.com/Assylum-Labs/forensic-analysis-tool

Messari: Crime Fighting AI Toolkit ($5,000)

This bounty challenged participants to use Messari’s AI Toolkit to generate novel, actionable insights related to crypto crimes and market events.

🥇 1st: Detectives vs Shillers: An Engagement Race
🥈 2nd: MessariMCP GitHub Repo
🥉 3rd: Solana Sentiment Analysis GitHub Repo

Superteam India: Solana Security Dashboard ($5,000)

This bounty from Superteam India aimed to expand the original Superteam Security handbook into a live, open-source dashboard. The dashboard was expected to cover all major exploits in the Solana ecosystem with onchain data, analytics, and resources for users.

🥇 1st: ST Security Dashboard
🥈 2nd: Superteam Security Dashboard Variant
🥉 3rd: Solana Security Dashboard Teal

Asset Dash: New Smart Wallet List & Signal Feed Bounty ($5,000)

This bounty challenged participants to propose a concept for a new Asset Dash feed that generates onchain alpha by identifying specific wallets and transactions worth monitoring.

🥇 1st: GMGN $ AXIOM Top Traders
🥈 2nd: Tracking Top Crypto Wallets
🥉 3rd: Next-Gen Whale Monitoring Feed

Ottersec & Squads: Securing Squads ($5,000)

This joint bounty from Ottersec and Squads focused on improving the signing experience for high-value transactions using Squads.

🥇 1st: https://github.com/hogyzen12/squads-go
🥈 2nd: https://github.com/AdedejiAdetola/securing_squads
🥉 3rd: https://crates.io/crates/secure-squads 

Accretion: Reverse Engineering Closed Source Solana Programs ($5,000)

This bounty from the Solana security auditing firm Accretion, invited security experts to create of tools or guides for reverse engineering closed-source programs. Submissions could include tools to extract instructions, assist manual reverse engineering, or provide walkthroughs.

🥇 1st: IDLGuesser by @LeoQ7_
🥈 2nd: Lernean Lens by @bill_papas_12
🥉 3rd: MCP Solana Revving by @GSfilatino

Vybe: Vybe Telegram Bot Challenge ($5,000)

This bounty involved creating a Telegram bot that uses Vybe's APIs to deliver real-time, onchain analytics to crypto communities (e.g. wallet tracking, token metrics, or whale alerts).

🥇 1st: Scout by iamjoey.sol
🥈 2nd: mira4sol
🥉 3rd: Neeraj138

Guvenkaya: Web2 Security Issues in Web3 ($5,000)

This bounty from the Solana security auditing firm Guvenkaya focused on exploring how traditional web2 security vulnerabilities can lead to web3 vulnerabilities.

🥇 1st: Muhammad Abdullah
🥈 2nd: Cetin Mesum
🥉 3rd: Manish Kumar

Bubblemaps: Top Traders Bubblemaps ($4,000)

This bounty asked participants to use Bubblemaps’ visualization APIs to create a tool for connecting the top traders of specific tokens to reveal relationships between active trading wallets.

🥇 1st Place: https://github.com/0xmilarepa/top_traders_tool/ 

Meteora: Kelsier Ventures Blacklist ($3,850)

This bounty from Meteora offered rewards for creating a public blacklist of Solana wallet addresses associated with Kelsier Ventures.

🥇 1st: Submission Details - Issue #10 by Degenspy
🥈 2nd: Submission Details - Issue #6 by Dethective
🥉 3rd: Submission Details - Issue #22 by 0xbabushka

Dune: Data Storyteller ($3,000)

This bounty encouraged participants to use Dune dashboards to analyze and tell a story about a Solana-related subject or create a guide on analyzing Solana data with Dune.

🥇 1st: Adam_Tehc
🥈 2nd: Can We Rescue Trapped SOL from Pump.fun?
🥉 3rd: What Happens When Pump.fun Ditches Bonding Curves?

Sonic: Building Tools for the SVM Universe ($3,000)

This bounty focused on expanding Solana data analytics tools to Sonic and other SVM chains.

🥇 1st: Solar Bank App by Josephxu
🥈 2nd: Sonic Pulse GitHub Repository

LimeChain: Test and Give Feedback for Gimlet ($3,000)

This bounty invited developers and security researchers to test Gimlet, a new Solana step debugger. The goal was to gather feedback, find bugs, and propose improvements.

🥇 1st: Ubadineke Prince
🥈 2nd: David Luke
🥉 3rd: Pramath S

Token Metrics: Crypto Analysis Report ($3,000)

This bounty required participants to produce a crypto analysis report using Token Metrics' tools and methodologies.

🥇 1st: Arcaze
🥈 2nd: HogwartsofWeb3
🥉 3rd: @IamFantasy__

Nebula Node: Visualizing Solana Staking ($3,000)

This bounty from Nebula Node challenged participants to create a dashboard for visualizing Solana staking data such as validator performance, stake distribution, or node health.

🥇 1st: 4k_mira

Ded Monkes: Blockchain Visualization ($3,000)

This bounty from Ded Monkes focused on building an intuitive, interactive way to track protocols, wallets, transactions, and interactions on Solana.

🥇 1st: ShaunRiser
🥈 2nd: Dinesh_7rd

Civic: Integrate Civic Auth into Your Application ($2,800)

This bounty called for developers to integrate Civic Auth's Web3 SDK into their applications to enable embedded wallets for users. 

🥇 1st: VersatileBeingX
🥈 2nd: Ge0frey_
🥉 3rd: Savin AjoSave Application

Flipside: Accelerate Data-Driven Insights into Solana's Growth ($2,500)

This bounty challenged participants to use Flipside's data to present insights that expose fraud, analyze liquidity movements, investigate user behavior, and investigate protocols and apps driving the most real economic value.

🥇 1st: Linking Validator Returns and Program Activity
🥈 2nd: Exit Liquidity Machines
🥉 3rd: Zkreum's X Post

DD.xyz: API Integration ($2,000)

This bounty involved integrating the DD.xyz API in apps by either displaying a DD score next to the asset or wallet in your UI or bot response, or to help control spam/sybil in your signup flow.

🥇 1st: Fystack

Phase Labs: Unpacking Solana's Economic Activity ($2,000)

This bounty from Phase Labs asked for research articles that unpack Solana's Real Economic Value (REV) and other economic activities.

🥇 1st: PineAnalytics
🥈 2nd: RalAndrewTalks
🥉 3rd: Suppvalen

Solscan: Monitoring Masters ($2,000)

This bounty encouraged participants to use Solscan's APIs to build a monitoring or scanning solution such as tracking DEX dynamics, whale activity, or correlating social sentiment with onchain activity.

🥇 1st: Vlad’s Solscan MCP
🥈 2nd: Swell’s doxdotfun
🥉 3rd: Rohan’s Solanautics

Artemis: Data Analytics ($2,000)

This bounty focused on developing SQL queries for MarginFi's key performance metrics (e.g., TVL, borrows, deposits, protocol fees, revenue) to be implemented on the Artemis platform.

At the time of publishing, no winners have been selected.

Bubblemaps: Telegram Bot ($2,000)

This bounty asked for the development of a Telegram bot that, upon receiving a token contract address, would generate and return a Bubblemaps' screenshot and relevant token information. 

🥇 1st: https://github.com/incryptomax/bubblemapstelegrambot 

Validator.com: Malicious Validators ($750)

This bounty from Validator.com focused on identifying, analyzing, or creating tools to detect malicious Solana validator activity.

🥇 1st: Joshua Sunday
🥈 2nd: David Bassey

Validator.com: Sandwich Attack Shield ($750)

This bounty challenged participants to develop a "Sandwich Attack Shield," to protect users or protocols from sandwich attacks on Solana.

🥇 1st: Krystian Mejor
🥈 2nd: Faatih Mohammed

Supa Pump: Supa Sleuth Challenge ($500)

This bounty involved creating educational content or tools to uncover fake activity or fraud using Supa’s sleuthing features.

🥇 1st: Joshua Sunday
🥈 2nd: Evans Nwaozuzu
🥉 3rd: Nipheweb3 Emmanuel

Congratulations!

Congratulations once again to all the winners, and thank you to all of the sponsors and organizers! 

Your contributions are invaluable to the growth and security of the Solana ecosystem.

Related Articles

Funding Announcement

With a $21.75M raise led by Haun Ventures & Founders Fund, we're boosting developers' economic potential via crypto.

Subscribe to Helius

Stay up-to-date with the latest in Solana development and receive updates when we post