TRUST & TRANSPARENCY
Security Policy
At SOLANA DEADS, security is our top priority. This policy outlines our commitment to protecting our users and provides guidelines for responsible vulnerability disclosure.
Contact the teamOur Commitment to Security
SOLANA DEADS is committed to maintaining the highest standards of security for our on-chain programs, web applications, and infrastructure. We continuously monitor, test, and improve our security posture to protect our community and their assets.
We believe in transparency and work closely with security researchers to identify and address potential vulnerabilities. We appreciate the efforts of the security community in helping us maintain a secure ecosystem.
Security Measures
Smart Contract Security
All on-chain programs undergo rigorous testing and verification before deployment. We use Anchor framework best practices and follow Solana security guidelines.
Transparent Operations
All program addresses are publicly verifiable on Solana explorers. Fee distributions and reward calculations are fully transparent and auditable on-chain.
Access Controls
Administrative functions are protected by multi-signature requirements and role-based access controls to prevent unauthorized modifications.
Rate Limiting
Built-in rate limiting and cooldown periods protect against spam attacks and ensure fair distribution of rewards to all participants.
Retired Programs
The two programs below were operated by SOLANA DEADS and have since been closed on mainnet. They are out of scope for vulnerability disclosure and are listed only so the record is unambiguous. What they did — reward distribution and fee harvesting — was consolidated into the GraveStake program and still runs there today.
Solana Deads Harvester
Fee router and distribution program — superseded by GraveStake's harvest crank
DEADS3ucNHjN8iz3Cw65joYxgVdguNsjytHRqCs7QvzAProgram closed on mainnet — no longer operated, out of disclosure scope
CryptKeeper
Rewards distribution program — superseded by GraveStake
DEADZS7SrZMW5aGgXzgUis59iaQfjgdmnXMQuJJo7uAuProgram closed on mainnet — no longer operated, out of disclosure scope
Vulnerability Disclosure
We encourage responsible disclosure of security vulnerabilities. If you discover a potential security issue, please report it to us privately so we can investigate and address it before any public disclosure.
In Scope
- •Smart contract vulnerabilities in deployed programs
- •Logic errors that could lead to loss of funds
- •Authentication or authorization bypasses
- •Denial of service vulnerabilities
- •Cross-site scripting (XSS) on web applications
- •SQL injection or other injection attacks
Out of Scope
- •Retired programs that are closed on mainnet (Harvester, CryptKeeper)
- •Social engineering attacks
- •Physical security issues
- •Denial of service attacks that don't exploit vulnerabilities
- •Issues in third-party dependencies (report to vendor)
- •Theoretical vulnerabilities without proof of concept
- •Issues already known or previously reported
Reporting Guidelines
- 1.Provide a detailed description of the vulnerability
- 2.Include steps to reproduce the issue
- 3.Specify the affected program or component
- 4.Include any relevant transaction signatures or logs
- 5.Do not publicly disclose the vulnerability before resolution
- 6.Allow reasonable time for investigation and remediation
How to Report
To report a security vulnerability, please use one of the following channels:
Response Timeline
Recognition
We value the contributions of security researchers who help us maintain a secure platform. Depending on the severity and impact of the vulnerability, we may offer:
- Public acknowledgment in our security hall of fame (with permission)
- Exclusive SOLANA DEADS NFTs or merchandise
- Token rewards for critical vulnerabilities
- Direct communication with the development team
Safe Harbor
We consider security research conducted in accordance with this policy to be:
- Authorized and welcomed
- Exempt from legal action by SOLANA DEADS
- Conducted in good faith
We will not pursue legal action against researchers who follow this policy and act in good faith. However, we cannot authorize actions that violate laws or regulations, and researchers are responsible for ensuring their activities comply with applicable laws.
Last updated: July 2026
Questions about this policy? Contact us at [email protected]
