# Call For Proposals: Coinholder-Directed Retroactive Grants Program Q3

**URL:** <https://forum.zcashcommunity.com/t/call-for-proposals-coinholder-directed-retroactive-grants-program-q3/56885>\
**Category:** Retroactive Grants\
**Created:** [August 2, 2026, 11:29pm UTC](https://forum.zcashcommunity.com/t/call-for-proposals-coinholder-directed-retroactive-grants-program-q3/56885 "2026-08-02T23:29:25Z")\
**Posts on this page:** 8\
**Page:** 2

<div class="post-metadata">

**Author:** ![Connaugh](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/connaugh/32/47144_2.png) [@Connaugh](https://forum.zcashcommunity.com/u/Connaugh)\
**Post date:** [August 14, 2026, 2:51pm UTC](https://forum.zcashcommunity.com/t/call-for-proposals-coinholder-directed-retroactive-grants-program-q3/56885/22 "2026-08-14T14:51:22Z")

</div>

Hi everyone, I’m dropping a link to my proposal. I’m trying to boost my new account permissions so I can post in the main thread.

> <https://github.com/Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram/issues/55>
>
> \### Terms and Conditions
> 
> \- \[x\] I agree to the \[Grant Agreement\](https://9ba4718…c-5c73-47c3-a024-4fc4e5278803.usrfiles.com/ugd/9ba471\_6ff6db4095fd4c4ba21babec361e927e.pdf) terms if funded
> \- \[x\] I agree to \[Provide KYC information\](https://9ba4718c-5c73-47c3-a024-4fc4e5278803.usrfiles.com/ugd/9ba471\_7d9e73d16b584a61bae92282b208efc4.pdf) if funded above $50,000 USD
> \- \[x\] I agree to disclose conflicts of interest
> \- \[x\] I understand that this grant program is only eligible for completed work, as it is a retroactive grant program. Applications for planned or partially completed work will not be considered. All completed work will be verified and accepted by its intended users or their representatives, who will confirm that the outputs meet the required quality, functionality, and usability before the work is listed as an option for Coinholder voting.
> \- \[x\] I agree that for any new open-source software, I will create a CONTRIBUTING.md file that reflects the high standards of Zcash development, using the \[\`librustzcash\` style guides\](https://github.com/zcash/librustzcash/blob/main/CONTRIBUTING.md#styleguides) as a primary reference.
> \- \[x\] I understand when contributing to existing Zcash code, I am required to adhere to the project specific contribution guidelines, paying close attention to any \[merge\](https://github.com/zcash/librustzcash/blob/main/CONTRIBUTING.md#merge-workflow), \[branch\](https://github.com/zcash/librustzcash/blob/main/CONTRIBUTING.md#branch-history), \[pull request\](https://github.com/zcash/librustzcash/blob/main/CONTRIBUTING.md#pull-request-review), and \[commit\](https://github.com/zcash/librustzcash/blob/main/CONTRIBUTING.md#commit-messages) guidelines as exemplified in the librustzcash repository.
> \- \[x\] I understand all grants are valued in USD but will be disbursed in Shielded ZEC. I acknowledge and accept that disbursement amounts may fluctuate based on the ZEC/USD exchange rate at the time of payment.
> 
> \### Application Owners (@octocat, @octocat1)
> 
> @Connaugh
> 
> \### Organization or Individual Name
> 
> Connaugh
> 
> \### Additional Team Members
> 
> \`\`\`team-members.yaml
> My Background
> Six years in tech marketing across biotech, AI and crypto, the last two and a half in zero-knowledge cryptography at Mina Foundation and o1Labs. There I built the ecosystem content programme and ran it at a consistent cadence for over a year, the first time that had been sustained in that ecosystem. It held because of process rather than effort: a repeatable pipeline built around the constraints of the crypto industry. I produced many different types of videos including: thought leadership, Ecosystem highlights, protocol upgrades, whiteboard sessions, fundraising announcements, whitepaper announcements and more.
> I do research, scripting, editing, graphic design and distribution myself. That removes the handoffs that normally set the ceiling on how often a small team can publish, and it is the reason the cost per film and speed of delivery in this application is what it is.
> 
> My Responsibilities
> \- Sourcing and archiving video from across the Zcash ecosystem: co-founders, engineers, the ecosystem organisations, external advocates, and the institutional cohort
> \- Editorial. Finding the story inside each source, and threading claims across separate videos so speakers corroborate one another
> \- Verifying technical claims against primary sources
> \- Scripting and voiceover
> \- Editing, graphic design, sound design and packaging
> \- Publishing and distribution
> \- Series architecture and publishing cadence
> \`\`\`
> 
> \### How did you learn about the Lockbox: Coinholder Retroactive Grants Program?
> 
> Through conversations with the Cypherpunk Technologies team, who directed me to the Zcash Community Grants team.
> 
> \### Requested Grant Amount (USD)
> 
> $22,000
> 
> \### Category
> 
> Media
> 
> \### Project Summary
> 
> Zcash produces more high-quality video than almost any ecosystem its size, scattered across founders, engineers, the ecosystem organisations, external advocates and its institutional backers. I cut that footage and re-architect it into short, single-argument films designed for audiences who will never sit through a two-hour podcast: five films published between 28 July and 12 August 2026, reaching 45,811 impressions and 9,931 views from a standing start.
> 
> \### Project Description
> 
> \- Overview
> 
> Zcash has huge potential with its current video output. Every month the ecosystem produces a serious volume of video: protocol engineers explaining upgrades, co-founders on podcasts, the organisations building on Zcash, advocates from other ecosystems, and the institutional cohort that has arrived over the past year. The material is excellent. It is also long, spread across a dozen channels, and mostly reaching people who are already convinced.
> 
> I want to pull all the content into one place and re-edit it to tell the Zcash story with less friction. Each film pulls clips from across the ecosystem and threads them into a single argument, so that people who were recorded months apart, in different places, end up corroborating each other on camera. The technical claims stay in the mouths of the people who built the protocol. My job is the through-line.
> 
> \- Origin
> 
> The work started with Ironwood. The upgrade was significant, and the explanation of it was scattered, with different aspects covered by different people in different places. Nothing assembled them. I built the first film to do that and shipped it within a week.
> 
> \- Why the films are short
> 
> Each film carries one or two points, told once, properly. Three things follow.
> The archive compounds. Crypto content dates fast, whether through protocol changes or shifts in the political situation. A long film dies as a whole when one section goes stale. A short film making a single point stays publishable, which means every film I make adds to a library I can keep drawing on instead of a back catalogue that decays.
> 
> Fragmenting the case widens the reach. Zcash is not one story. It is an institutional story, an apolitical money story, a cypherpunk story, a technical story about what the protocol does, the people, etc. Different stories and viewpoints are critical for reaching different audiences. Cutting to the point level lets each audience find the argument aimed at them, and lets advocates share the exact claim they care about instead of a film that is three-quarters about something else.
> 
> The format is what distribution rewards. Short, fast-paced explainer video is the dominant form outside crypto and thinly served inside it, where most output is either long-form conversation or low-effort promotion. The video direction of travel is visible: Ethereum has committed to an in-house media team, and a16z's video output over the past six months has moved towards short documentary work at a production standard the rest of the industry has not matched.
> 
> \- Why this is worth funding
> 
> Having one person with a specialist background to run the entire video process will dramatically reduce costs and time. I want to commit to a cadence of 2 videos a week to really help grow the Zcash momentum. Because research, script, edit, design and distribution all sit with one person, these cost $3,000 each and ship published.
> 
> It multiplies work the ecosystem has already paid for. Every film is built from footage that already exists. This does not compete with the podcasts, talks, and engineering explainers being made across Zcash. It extends their reach to people who were never going to watch them in full.
> 
> It is already working. Five films, 16 days, no existing Zcash audience, and the numbers are set out below.
> 
> 
> \### Technical Approach (how you did it)
> 
> \- Process
> 
> Every film runs the same five stages.
> Research. I gather source material from across the ecosystem: podcast appearances, conference talks, engineering explainers, interviews. Each clip is logged against the claim it supports.
> Editorial. I build the narrative before I open the timeline. Claims are threaded so that speakers recorded independently corroborate one another. Anything technical is checked against primary sources.
> Scripting. I write voiceover into the gaps only. Source clips carry the mechanism, voiceover carries the consequence, which keeps the technical claims with the people who built the protocol and keeps me out of the way of them.
> Production. Editing, sound design, and music in Adobe Premiere Pro. Motion and graphic design in Figma.
> Distribution. Published to X, packaged and hooked for that feed specifically.
> 
> \- Tooling and position on AI
> 
> Premiere Pro for editing. Figma for design. Claude for research synthesis and script structure. ElevenLabs for generated video assets, including a generated likeness of myself used as an on-screen presenter.
> All narration is my own recorded voice. There is no voice cloning and no synthetic narration anywhere in this work.
> I use AI at the edges and keep it out of the center. The edit is done by hand in professional software, deliberately. Template-driven AI video tools produce output that is recognisable on sight, and in an ecosystem whose entire value proposition is credibility, content that looks automatically generated damages the argument it is making. That is an editorial decision before it is a technical one.
> 
> \- Equipment
> 
> Recording and production hardware, including a Shure SM7dB and mixing desk, is mine and self-funded. It is not claimed here.
> 
> 
> \### Time Period of Work Completion
> 
> 13 July 2026 to 12 August 2026 working full time, weekends and evenings. Five films published over 16 days.
> 
> \### Total Budget (USD)
> 
> $22,000
> 
> \### Budget Breakdown
> 
> \<b id="docs-internal-guid-9ca82308-7fff-cbd3-b6c2-8691135a86f8" style="font-style: normal; font-variant-caps: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0); font-weight: normal;"\>\<div dir="ltr" align="left" style="margin-left: 0pt;"\>
> Line | Amount | Justification
> \-- | -- | --
> Compensation | $22,000 | Time only, priced per film + research. Launch film $6,000, covering the longer build and the research base it established. Four subsequent films at $3,000 each. Initial research week $4,000.
> Technology / Software | $0 | Adobe, Figma and AI tooling subscriptions self-funded. Not claimed.
> Infrastructure / Hosting | $0 | None incurred.
> Services / Contractors | $0 | Sole producer. No third parties engaged.
> Other | $0 | Recording and production equipment owned and self-funded. Not claimed.
> Total | $22,000 |  
> 
> \</div\>\</b\>
> 
> 
> \### Previous Funding
> 
> No
> 
> \### Previous Funding Details
> 
> \_No response\_
> 
> \### Other Funding Sources
> 
> Yes
> 
> \### Other Funding Sources Details
> 
> I have received no funding for this work from any source. I intend to explore different funding options within the Zcash ecosystem for future work. I believe I can dramatically scale video content and reach in the Zcash ecosystem. 
> 
> \### Success Metrics
> 
> \<b id="docs-internal-guid-5272608b-7fff-9381-a6bf-a000cc713989" style="font-style: normal; font-variant-caps: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration: none; caret-color: rgb(0, 0, 0); color: rgb(0, 0, 0); font-weight: normal;"\>\<p dir="ltr" style="line-height: 1.38; margin-top: 0pt; margin-bottom: 7pt;"\>\<span style="font-size: 11pt; font-family: Calibri, sans-serif; color: rgb(0, 0, 0); background-color: transparent; font-weight: 400; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-variant-alternates: normal; font-variant-numeric: normal; font-variant-east-asian: normal; font-variant-position: normal; text-decoration: none; vertical-align: baseline; white-space: pre-wrap;"\>The account carried no Zcash audience when this started. Every figure below was built from a standing start. Snapshot taken 14 August 2026, 14:29 BST.\</span\>\</p\>\<div dir="ltr" align="left" style="margin-left: 0pt;"\>
> Film | Impressions | Views | Likes | Reposts | Replies
> \-- | -- | -- | -- | -- | --
> Ironwood launch | 5,479 | 1,483 | 87 | 17 | 8
> Scaling Zcash to Visa levels | 3,322 | 713 | 45 | 9 | 2
> Zcash never upgraded its privacy | 8,018 | 2,679 | 123 | 27 | 4
> You don't have a right to a bank account | 16,578 | 2,486 | 68 | 15 | 1
> Zcash is much better than Bitcoin | 12,414 | 2,570 | 133 | 37 | 10
> Total | 45,811 | 9,931 | 456 | 105 | 25
> 
> \</div\>\</b\>
> 
> Reach grew across the run. Each of the three most recent films reached more people than either of the first two, and the strongest took roughly three times the impressions of the opener. Views tracked the same curve.
> 
> Films three and five drew the heaviest engagement of the set. Film four reached the largest audience by some margin on lighter engagement. The full set is reported here, including the weakest performer.
> 
> Five films is an early signal rather than a proven programme, and the figures are presented as such.
> 
> \### Proof of completion
> 
> All five films published on X at @zkmarketer.
> 
> \- Ironwood launch: https://x.com/zkmarketer/status/2082103793253335140
> \- Scaling Zcash to Visa levels: https://x.com/zkmarketer/status/2082880148924190798
> \- Zcash has never upgraded its privacy: https://x.com/zkmarketer/status/2084651572529627618
> \- You don't have a right to a bank account: https://x.com/zkmarketer/status/2085691623367696612
> \- Zcash is much better than Bitcoin. Satoshi would agree: https://x.com/zkmarketer/status/2087188128561795464
> 
> Analytics snapshot for each film, taken 14 August 2026, 14:29 BST.
> 
> 
> 
> \### Conflict of Interest Disclosure
> 
> N/A
> 
> \### Community Forum Posting
> 
> \- \[x\] I understand it is my responsibility to post a link to this issue on the \[Zcash Community Forums\](https://forum.zcashcommunity.com/t/about-the-retroactive-grants-category/52106) after this application has been submitted so the community can give input. I understand this is required in order for the community to discuss and vote on this grant application. Note: If you are unable to post on the forum (for example, due to new user restrictions), please leave a comment below, and we will adjust your posting permissions.

---

<div class="post-metadata">

**Author:** ![scalar](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/scalar/32/43926_2.png) [@scalar](https://forum.zcashcommunity.com/u/scalar)\
**Post date:** [August 14, 2026, 5:23pm UTC](https://forum.zcashcommunity.com/t/call-for-proposals-coinholder-directed-retroactive-grants-program-q3/56885/23 "2026-08-14T17:23:00Z")

</div>

> [@Retroactive Grant Application - Temporary Detectable Unlimited mint and sell (Bug Bounty)](https://forum.zcashcommunity.com/t/retroactive-grant-application-temporary-detectable-unlimited-mint-and-sell-bug-bount/57033):
>
> Hello Zcashers, Submitted a retroactive grant application to the Coinholder Retroactive Grants Program for the vulnerability disclosures across zcashd and zebra in March–April 2026: a temporary detectable unlimited mint-and-sell exploit. GitHub issue: [Retroactive Grant Application - Temporary Detectable Unlimited mint and sell Exploit](https://github.com/Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram/issues/57) Requested amount: $400,000. Not a cost reimbursement, direct costs were about $30,000 in API spend (shame on me, I know) Prior funding: 600 ZEC, itemised in t…

---

<div class="post-metadata">

**Author:** ![sangsoo](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/sangsoo/32/44722_2.png) [@sangsoo](https://forum.zcashcommunity.com/u/sangsoo)\
**Post date:** [August 14, 2026, 5:32pm UTC](https://forum.zcashcommunity.com/t/call-for-proposals-coinholder-directed-retroactive-grants-program-q3/56885/26 "2026-08-14T17:32:24Z")

</div>

Hi zcasherrrs, sumbitted an application!

> [@Retroactive Grant Application - Five Critical Zebra Consensus Divergence Vulnerabilities](https://forum.zcashcommunity.com/t/retroactive-grant-application-five-critical-zebra-consensus-divergence-vulnerabilities/57034):
>
> Hello Zcash community, I have submitted a retroactive grant application to the Coinholder Retroactive Grants Program for five consensus-divergence vulnerabilities that I found and responsibly disclosed in Zebra during Q2 2026. Full application: [Financial Privacy Foundation / Coinholder Retroactive Grants Program issue #58](https://github.com/Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram/issues/58) Requested amount: $425,000. This is an opening proposal, not a fixed or non-negotiable demand. I am fully open to discussing and revising the amount through community feedb…

---

<div class="post-metadata">

**Author:** ![thowar2](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/thowar2/32/39745_2.png) [@thowar2](https://forum.zcashcommunity.com/u/thowar2)\
**Post date:** [August 14, 2026, 6:58pm UTC](https://forum.zcashcommunity.com/t/call-for-proposals-coinholder-directed-retroactive-grants-program-q3/56885/27 "2026-08-14T18:58:05Z")

</div>

> [@Retroactive Grant Application - Zcash Labs for zcashto.cash](https://forum.zcashcommunity.com/t/retroactive-grant-application-zcash-labs-for-zcashto-cash/57047):
>
> Zcash Labs has submitted a grant application for the creation of zcashto.cash. Application: [Retroactive Grant Application - zcashtocash via ZcashLabs · Issue #60 · Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram · GitHub](https://github.com/Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram/issues/60) Requested: $6000 This application follows our launch announcement, in which we outline a new mechanism for team to interact with the Coinholder-Directed Retroactive Grants Program. The [Funding Model](https://zcashlabs.org/funding-model) we are pioneering includes funding and working with promising ne…

---

<div class="post-metadata">

**Author:** ![zk\_nd3r](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/zk_nd3r/32/43927_2.png) [@zk\_nd3r](https://forum.zcashcommunity.com/u/zk_nd3r)\
**Post date:** [August 14, 2026, 7:13pm UTC](https://forum.zcashcommunity.com/t/call-for-proposals-coinholder-directed-retroactive-grants-program-q3/56885/28 "2026-08-14T19:13:16Z")

</div>

> [@Retroactive Grant Application: ZAP1 Attestation Protocol and Verification Tooling](https://forum.zcashcommunity.com/t/retroactive-grant-application-zap1-attestation-protocol-and-verification-tooling/55664/3):
>
> ZAP1 is listed in the Q3 Coinholder-Directed Retroactive Grants round. The application covers the completed March-May 2026 ZAP1 attestation protocol and verification tooling. The scope and category are unchanged. Full application and public verification links:

---

<div class="post-metadata">

**Author:** ![zk\_nd3r](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/zk_nd3r/32/43927_2.png) [@zk\_nd3r](https://forum.zcashcommunity.com/u/zk_nd3r)\
**Post date:** [August 14, 2026, 7:45pm UTC](https://forum.zcashcommunity.com/t/call-for-proposals-coinholder-directed-retroactive-grants-program-q3/56885/29 "2026-08-14T19:45:36Z")

</div>

**Retroactive Grant Application - Frontier Compute Zcash Security Research and Remediation Pack**

I submitted Frontier Compute’s Q3 Coinholder Retroactive Grant application:

> <https://github.com/Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram/issues/63>
>
> \### Terms and Conditions
> 
> \- \[x\] I agree to the \[Grant Agreement\](https://9ba4718…c-5c73-47c3-a024-4fc4e5278803.usrfiles.com/ugd/9ba471\_6ff6db4095fd4c4ba21babec361e927e.pdf) terms if funded
> \- \[x\] I agree to provide KYC information if funded above $50,000 USD
> \- \[x\] I agree to disclose conflicts of interest
> \- \[x\] I understand this program funds completed work only, and that the work must be verified and accepted by its intended users or their representatives before a Coinholder vote
> \- \[x\] I accept the applicable open-source contribution requirements
> \- \[x\] I understand grants are valued in USD but paid in Shielded ZEC
> 
> \### Application Owners (@octocat, @octocat1)
> 
> @Zk-nd3r
> 
> \### Organization or Individual Name
> 
> Frontier Compute LLC
> 
> \### Additional Team Members
> 
> \`\`\`team-members.yaml
> None. I am submitting this through Frontier Compute LLC.
> \`\`\`
> 
> \### How did you learn about the Lockbox: Coinholder Retroactive Grants Program?
> 
> Zcash Community Forum and Frontier Compute's existing participation in the Coinholder Retroactive Grants process.
> 
> \### Requested Grant Amount (USD)
> 
> $123,750
> 
> \### Category
> 
> Research & Development
> 
> \### Project Summary
> 
> I found concrete security failures in Zcash infrastructure and wallet code, disclosed them responsibly, stayed with the work through remediation, and verified what merged and shipped. This application claims only accepted, public, merged or released outcomes. Private, open, rejected, disputed, and partially unresolved work is excluded.
> 
> \### Project Description
> 
> I am Skander, founder of Frontier Compute. This was not a drive-by bug report. The operating loop was: define the security property, find and validate the failure path, report it privately, help make the required control precise, track remediation through review and merge, verify release ancestry, and re-read the fixed code for residual risk.
> 
> I am applying for one completed security-remediation pack because the work was run as one operation across infrastructure and wallet surfaces.
> 
> \#### 1. Accepted and shipped lightwalletd work - $43,750
> 
> \- \[GHSA-9p9r-mggr-8q9g\](https://github.com/zcash/lightwalletd/security/advisories/GHSA-9p9r-mggr-8q9g): a slow or non-reading \`GetMempoolTx\` client could hold the shared mempool mutex across streaming sends and block concurrent calls. I am the sole accepted reporter. The advisory is public and the fix shipped in lightwalletd 0.5.2. Valuation: $18,750.
> \- \[GHSA-x4m7-3gpp-xc36\](https://github.com/zcash/lightwalletd/security/advisories/GHSA-x4m7-3gpp-xc36): unauthenticated transparent-address RPC paths could force resource exhaustion. I authored and maintained the Frontier Compute report and preserve every additional public credit. This application claims only the two accepted paths fixed and released in lightwalletd 0.5.0. The remaining materialize-before-filter residual is expressly excluded. Valuation: $25,000, two-thirds of the former $37,500 Supporting Infrastructure High reference band.
> 
> These former ZCG bands are valuation benchmarks only, following the transparent benchmark approach used by other Q3 security applications. They are not evidence of an existing award.
> 
> \#### 2. Accepted and merged ZODL mobile-wallet remediation - $80,000
> 
> I delivered coordinated security reports covering transaction-review integrity, account and session binding, secret-export surfaces, and swap validation. ZODL maintainers independently implemented and reviewed the fixes. I am claiming my research, responsible disclosure, control specification, adversarial verification, and fix-to-release tracking-not authorship of their patches.
> 
> This application relies only on the following public, approved, merged work and public release evidence:
> 
> \- \[zodl-android #2299 - Swap Security Hardening\](https://github.com/zodl-inc/zodl-android/pull/2299), approved and merged 9 June 2026.
> \- \[zodl-android #2317 - Security hardening\](https://github.com/zodl-inc/zodl-android/pull/2317), approved and merged 12 June 2026.
> \- \[zodl-ios #1825 - remove hidden debug seed export without authentication\](https://github.com/zodl-inc/zodl-ios/pull/1825), approved and merged 16 June 2026.
> \- \[zodl-ios #1849 - fail closed on multi-recipient ZIP-321 payment requests\](https://github.com/zodl-inc/zodl-ios/pull/1849), approved and merged 26 June 2026.
> \- \[zodl-ios #1851 - enforce account/signing boundaries and end stale Flexa sessions\](https://github.com/zodl-inc/zodl-ios/pull/1851), approved and merged 26 June 2026.
> \- \[zodl-android 3.8.1-2027\](https://github.com/zodl-inc/zodl-android/releases/tag/3.8.1-2027), public release evidence for the relevant Android merge ancestry.
> 
> I ask ZODL, as the intended user and remediation owner, to confirm the report-to-fix linkage during review. Any item ZODL does not confirm must be removed from the funded scope rather than inferred in my favour.
> 
> \#### Explicit exclusions
> 
> \- No private advisory identifier, exploit detail, unreleased report, or confidential inventory is included.
> \- No open, draft, rejected, disputed, or unmerged work is valued.
> \- The unfixed \`x4m7\` residual is excluded.
> \- I do not claim maintainer-authored patches as my code.
> \- I do not claim an award, receivable, or payment that does not exist.
> 
> \### Technical Approach (how you did it)
> 
> 1. Define the property that must not fail: fund safety, review-to-signing equivalence, account binding, secret handling, availability, or bounded resource use.
> 2. Trace attacker-controlled inputs through validation, proposal, signing, streaming, and backend-RPC paths.
> 3. Reproduce locally or create regression-shaped evidence without stressing public services.
> 4. Disclose through controlled maintainer channels.
> 5. Map accepted work to exact public pull requests, review state, merge state, tests, and release ancestry.
> 6. Re-read the post-fix code and exclude every unresolved residual from the completed claim.
> 
> AI-assisted source analysis was part of the workflow. Human judgment controlled target selection, validation, severity restraint, disclosure, evidence admission, and remediation verification. Model output was never treated as proof by itself.
> 
> \### Time Period of Work Completion
> 
> April 2026 through July 2026.
> 
> \### Total Budget (USD)
> 
> $123,750
> 
> \### Budget Breakdown
> 
> \- Compensation: $123,750 - retroactive, outcome-based valuation of completed security research, responsible disclosure, control specification, regression evidence, and release verification.
> \- Technology/Software: $0 separately claimed.
> \- Infrastructure/Hosting: $0 separately claimed.
> \- Services/Contractors: $0 separately claimed.
> \- Other: $0.
> \- Total: $123,750.
> 
> \### Previous Funding
> 
> No
> 
> \### Previous Funding Details
> 
> Frontier Compute has not received Coinholder Retroactive Grants funding for this work. The separate ZAP1 application concerns unrelated attestation protocol and verification tooling.
> 
> \### Other Funding Sources
> 
> Yes
> 
> \### Other Funding Sources Details
> 
> Some public lightwalletd findings entered the former ZCG vulnerability process and may still be reviewed there. As of submission, I have no primary evidence of an award, receivable, or payment for any work claimed here.
> 
> I will not double collect. Any later ZCG bounty or other payment attributable to the same finding will be disclosed and deducted dollar-for-dollar before disbursement. If another route fully compensates an item, I will withdraw that item. This filing does not waive existing bounty eligibility.
> 
> \### Success Metrics
> 
> \- Two public lightwalletd advisories with accepted Frontier Compute reporter credit.
> \- Sole accepted reporter credit and a released 0.5.2 fix for GHSA-9p9r-mggr-8q9g.
> \- Only the two released \`x4m7\` paths claimed; the live residual excluded.
> \- Five approved and merged public ZODL security-hardening pull requests.
> \- Public Android release evidence.
> \- Zero private finding identifiers or unpublished exploit details disclosed.
> \- Dollar-for-dollar deduction or withdrawal prevents double recovery.
> 
> \### Proof of completion
> 
> \- \[GHSA-9p9r-mggr-8q9g\](https://github.com/zcash/lightwalletd/security/advisories/GHSA-9p9r-mggr-8q9g)
> \- \[GHSA-x4m7-3gpp-xc36\](https://github.com/zcash/lightwalletd/security/advisories/GHSA-x4m7-3gpp-xc36)
> \- \[zodl-android #2299\](https://github.com/zodl-inc/zodl-android/pull/2299)
> \- \[zodl-android #2317\](https://github.com/zodl-inc/zodl-android/pull/2317)
> \- \[zodl-ios #1825\](https://github.com/zodl-inc/zodl-ios/pull/1825)
> \- \[zodl-ios #1849\](https://github.com/zodl-inc/zodl-ios/pull/1849)
> \- \[zodl-ios #1851\](https://github.com/zodl-inc/zodl-ios/pull/1851)
> \- \[lightwalletd 0.5.0\](https://github.com/zcash/lightwalletd/releases/tag/0.5.0)
> \- \[lightwalletd 0.5.2\](https://github.com/zcash/lightwalletd/releases/tag/0.5.2)
> \- \[zodl-android 3.8.1-2027\](https://github.com/zodl-inc/zodl-android/releases/tag/3.8.1-2027)
> 
> \### Conflict of Interest Disclosure
> 
> Frontier Compute LLC and I would receive this grant. I am the reporter and applicant, not the author of maintainer-written patches. The unrelated ZAP1 application is separate. Potential ZCG overlap is disclosed and fenced through dollar-for-dollar deduction or withdrawal.
> 
> \### Community Forum Posting
> 
> \- \[x\] I understand this application must be mirrored on the Zcash Community Forum for review and voting.

Requested amount: $136,250

This application includes only security work that is accepted, public, merged, or released.

COMPLETED LIGHTWALLETD WORK - $56,250

1. GHSA-9p9r-mggr-8q9g

> **[lightwalletd GetMempoolTx holds shared mempool mutex across client-controlled...](https://github.com/zcash/lightwalletd/security/advisories/GHSA-9p9r-mggr-8q9g)**
>
> \## Summary
> 
> \`GetMempoolTx\` takes \`s.mutex\` near the start of the handler and defers unlock until the handler returns. The handler later streams filtered mempool compact transactions to the client...

I am the sole accepted reporter. I submitted it on 5 May 2026. The fix shipped in lightwalletd 0.5.2. Valuation: $18,750, the Supporting Infrastructure Medium base schedule then in force.

1. GHSA-x4m7-3gpp-xc36

> **[lightwalletd transparent-address gRPC resource-exhaustion DoS](https://github.com/zcash/lightwalletd/security/advisories/GHSA-x4m7-3gpp-xc36)**
>
> \# v2 update: lightwalletd transparent-address gRPC resource-exhaustion DoS
> 
> Advisory: \`GHSA-x4m7-3gpp-xc36\`
> Repository: \`zcash/lightwalletd\`
> Reporter: \`Zk-nd3r\` / Frontier Compute
> Current vali...

I authored and maintained the Frontier Compute report and preserve every additional public credit. I submitted it on 28 April 2026, after the VDI launch. I claim only the accepted paths fixed and released in lightwalletd 0.5.0. The unresolved residual is excluded. Valuation: $37,500, the Supporting Infrastructure High base schedule then in force.

I used the applicable bountyzcash-to-VDI process and the base VDI price grid in force on each disclosure date. I did not prorate an accepted severity band by path count, and I did not claim the discretionary 50 percent uplift. These are valuation benchmarks, not claims of an existing award.

COMPLETED ZODL WALLET-REMEDIATION WORK - $80,000

The public completion evidence consists of these approved and merged changes:

- Android #2299 - Swap Security Hardening  
[MOB-1340 & MOB-1345 Swap Security Hardening by nesence-m · Pull Request #2299 · zodl-inc/zodl-android · GitHub](https://github.com/zodl-inc/zodl-android/pull/2299)

- Android #2317 - Security hardening  
[Security hardening by nesence-m · Pull Request #2317 · zodl-inc/zodl-android · GitHub](https://github.com/zodl-inc/zodl-android/pull/2317)

- iOS #1825 - Remove unauthenticated debug seed export  
[[MOB-1386] Remove hidden debug menu that copied seed without auth by Chlup · Pull Request #1825 · zodl-inc/zodl-ios · GitHub](https://github.com/zodl-inc/zodl-ios/pull/1825)

- iOS #1849 - Fail closed on multi-recipient ZIP-321 requests  
[[MOB-1348] Fail closed on multi-recipient ZIP-321 payment requests by Chlup · Pull Request #1849 · zodl-inc/zodl-ios · GitHub](https://github.com/zodl-inc/zodl-ios/pull/1849)

- iOS #1851 - Enforce account and signing boundaries and end stale Flexa sessions  
[[MOB-1352] Guard Flexa against Keystone accounts; end Flexa session on account switch by Chlup · Pull Request #1851 · zodl-inc/zodl-ios · GitHub](https://github.com/zodl-inc/zodl-ios/pull/1851)

- Android release 3.8.1-2027  
[Release Release 3.8.1 (2027) · zodl-inc/zodl-android · GitHub](https://github.com/zodl-inc/zodl-android/releases/tag/3.8.1-2027)

ZODL maintainers wrote and reviewed the patches. I claim Frontier Compute’s security research, responsible disclosure, control specification, adversarial verification, and fix-to-release tracking. I do not claim authorship of maintainer code.

I ask ZODL to confirm the report-to-fix linkage. Any item they do not confirm should be removed from the funded scope.

DISCLOSURES

- No private advisory identifiers, exploit details, or confidential finding inventory are included.

- No open, draft, rejected, disputed, unmerged, or unresolved work is valued.

- All public credits are preserved.

- Frontier Compute LLC and I would receive the grant.

- Frontier Compute has received no Coinholder Retroactive Grant funding for this work.

- Our separate ZAP1 application concerns unrelated attestation tooling.

- Any overlapping bounty payment will be disclosed and deducted dollar-for-dollar before disbursement.

- There will be no double recovery.

I stayed with this work from discovery and responsible disclosure through remediation review, merge, release ancestry, and residual-risk verification.

---

<div class="post-metadata">

**Author:** ![FPF](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/fpf/32/30829_2.png) [@FPF](https://forum.zcashcommunity.com/u/FPF)\
**Post date:** [August 14, 2026, 7:49pm UTC](https://forum.zcashcommunity.com/t/call-for-proposals-coinholder-directed-retroactive-grants-program-q3/56885/31 "2026-08-14T19:49:25Z")

</div>

@zk_nd3r please post as a separate topic.

---

<div class="post-metadata">

**Author:** ![FPF](https://sea2.discourse-cdn.com/zcash/user_avatar/forum.zcashcommunity.com/fpf/32/30829_2.png) [@FPF](https://forum.zcashcommunity.com/u/FPF)\
**Post date:** [August 14, 2026, 8:01pm UTC](https://forum.zcashcommunity.com/t/call-for-proposals-coinholder-directed-retroactive-grants-program-q3/56885/32 "2026-08-14T20:01:05Z")

</div>

CDRGP Q3 submission window is closed! WOW 😅 We’ll post a summary shortly.

[Previous page](https://forum.zcashcommunity.com/t/call-for-proposals-coinholder-directed-retroactive-grants-program-q3/56885.md?page=1)
