TRUST & TRANSPARENCY

Security Policy

At SOLANA DEADS, security is our top priority. This policy outlines our commitment to protecting our users and provides guidelines for responsible vulnerability disclosure.

Contact the team

Our Commitment to Security

SOLANA DEADS is committed to maintaining the highest standards of security for our on-chain programs, web applications, and infrastructure. We continuously monitor, test, and improve our security posture to protect our community and their assets.

We believe in transparency and work closely with security researchers to identify and address potential vulnerabilities. We appreciate the efforts of the security community in helping us maintain a secure ecosystem.

Security Measures

Smart Contract Security

All on-chain programs undergo rigorous testing and verification before deployment. We use Anchor framework best practices and follow Solana security guidelines.

Transparent Operations

All program addresses are publicly verifiable on Solana explorers. Fee distributions and reward calculations are fully transparent and auditable on-chain.

Access Controls

Administrative functions are protected by multi-signature requirements and role-based access controls to prevent unauthorized modifications.

Rate Limiting

Built-in rate limiting and cooldown periods protect against spam attacks and ensure fair distribution of rewards to all participants.

Retired Programs

The two programs below were operated by SOLANA DEADS and have since been closed on mainnet. They are out of scope for vulnerability disclosure and are listed only so the record is unambiguous. What they did — reward distribution and fee harvesting — was consolidated into the GraveStake program and still runs there today.

Solana Deads Harvester

Fee router and distribution program — superseded by GraveStake's harvest crank

DEADS3ucNHjN8iz3Cw65joYxgVdguNsjytHRqCs7QvzA

Program closed on mainnet — no longer operated, out of disclosure scope

Retired

CryptKeeper

Rewards distribution program — superseded by GraveStake

DEADZS7SrZMW5aGgXzgUis59iaQfjgdmnXMQuJJo7uAu

Program closed on mainnet — no longer operated, out of disclosure scope

Retired

Vulnerability Disclosure

We encourage responsible disclosure of security vulnerabilities. If you discover a potential security issue, please report it to us privately so we can investigate and address it before any public disclosure.

In Scope

  • •Smart contract vulnerabilities in deployed programs
  • •Logic errors that could lead to loss of funds
  • •Authentication or authorization bypasses
  • •Denial of service vulnerabilities
  • •Cross-site scripting (XSS) on web applications
  • •SQL injection or other injection attacks

Out of Scope

  • •Retired programs that are closed on mainnet (Harvester, CryptKeeper)
  • •Social engineering attacks
  • •Physical security issues
  • •Denial of service attacks that don't exploit vulnerabilities
  • •Issues in third-party dependencies (report to vendor)
  • •Theoretical vulnerabilities without proof of concept
  • •Issues already known or previously reported

Reporting Guidelines

  • 1.Provide a detailed description of the vulnerability
  • 2.Include steps to reproduce the issue
  • 3.Specify the affected program or component
  • 4.Include any relevant transaction signatures or logs
  • 5.Do not publicly disclose the vulnerability before resolution
  • 6.Allow reasonable time for investigation and remediation

How to Report

To report a security vulnerability, please use one of the following channels:

Response Timeline

24 hours
Initial acknowledgment of your report
72 hours
Preliminary assessment and severity classification
7 days
Detailed investigation and remediation plan
30 days
Target resolution for critical vulnerabilities
90 days
Public disclosure (coordinated with reporter)

Recognition

We value the contributions of security researchers who help us maintain a secure platform. Depending on the severity and impact of the vulnerability, we may offer:

  • Public acknowledgment in our security hall of fame (with permission)
  • Exclusive SOLANA DEADS NFTs or merchandise
  • Token rewards for critical vulnerabilities
  • Direct communication with the development team

Safe Harbor

We consider security research conducted in accordance with this policy to be:

  • Authorized and welcomed
  • Exempt from legal action by SOLANA DEADS
  • Conducted in good faith

We will not pursue legal action against researchers who follow this policy and act in good faith. However, we cannot authorize actions that violate laws or regulations, and researchers are responsible for ensuring their activities comply with applicable laws.

Last updated: July 2026

Questions about this policy? Contact us at [email protected]

We Value Your Privacy

We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Learn more