Closing the ZCG Vulnerability Bounty Program

I had no insight or input into the ZCG Bounty program before its launch.

I did not evaluate your finding on Zaino.

Given that @AloeareV marked it “Moderate” severity and from the description, I believe that it was a valuable (though out-dated) finding.

That said, a bug that requires a malicious validator to cause a DOS in Zaino, doesn’t even meet the criteria of “vulnerability” if that criterion is intended to refer to a functional Zcash stack.

If you’re interested in contributing to the zaino project, it’s open source, and we accept thoughtful improvements to the codebase.

If you can produce a working demonstration of your bug that does NOT involve a malicious validator, I think that is more likely to qualify for a bounty. As I said, I had no input into the bounty program, so my opinion isn’t authoritative.

Thanks for your work on the Zcash ecosystem. I hope we can find ways to collaborate more efficiently going forward!

2 Likes