I submitted Frontier Compute’s Q3 Coinholder Retroactive Grant application. GitHub application #63: Retroactive Grant Application - Frontier Compute Zcash Security Research and Remediation Pack · Issue #63 · Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram · GitHub
Requested amount: $136,250
This application includes only security work that is accepted, public, merged, or released.
COMPLETED LIGHTWALLETD WORK - $56,250
- GHSA-9p9r-mggr-8q9g
I am the sole accepted reporter. I submitted it on 5 May 2026. The fix shipped in lightwalletd 0.5.2. Valuation: $18,750, the Supporting Infrastructure Medium base schedule then in force.
- GHSA-x4m7-3gpp-xc36
I authored and maintained the Frontier Compute report and preserve every additional public credit. I submitted it on 28 April 2026, after the VDI launch. I claim only the accepted paths fixed and released in lightwalletd 0.5.0. The unresolved residual is excluded. Valuation: $37,500, the Supporting Infrastructure High base schedule then in force.
I used the applicable bountyzcash-to-VDI process and the base VDI price grid in force on each disclosure date. I did not prorate an accepted severity band by path count, and I did not claim the discretionary 50 percent uplift. These are valuation benchmarks, not claims of an existing award.
COMPLETED ZODL WALLET-REMEDIATION WORK - $80,000
The public completion evidence consists of these approved and merged changes:
-
Android #2299 - Swap Security Hardening
MOB-1340 & MOB-1345 Swap Security Hardening by nesence-m · Pull Request #2299 · zodl-inc/zodl-android · GitHub -
Android #2317 - Security hardening
Security hardening by nesence-m · Pull Request #2317 · zodl-inc/zodl-android · GitHub -
iOS #1825 - Remove unauthenticated debug seed export
[MOB-1386] Remove hidden debug menu that copied seed without auth by Chlup · Pull Request #1825 · zodl-inc/zodl-ios · GitHub -
iOS #1849 - Fail closed on multi-recipient ZIP-321 requests
[MOB-1348] Fail closed on multi-recipient ZIP-321 payment requests by Chlup · Pull Request #1849 · zodl-inc/zodl-ios · GitHub -
iOS #1851 - Enforce account and signing boundaries and end stale Flexa sessions
[MOB-1352] Guard Flexa against Keystone accounts; end Flexa session on account switch by Chlup · Pull Request #1851 · zodl-inc/zodl-ios · GitHub -
Android release 3.8.1-2027
Release Release 3.8.1 (2027) · zodl-inc/zodl-android · GitHub
ZODL maintainers wrote and reviewed the patches. I claim Frontier Compute’s security research, responsible disclosure, control specification, adversarial verification, and fix-to-release tracking. I do not claim authorship of maintainer code.
I ask ZODL to confirm the report-to-fix linkage. Any item they do not confirm should be removed from the funded scope.
DISCLOSURES
-
No private advisory identifiers, exploit details, or confidential finding inventory are included.
-
No open, draft, rejected, disputed, unmerged, or unresolved work is valued.
-
All public credits are preserved.
-
Frontier Compute LLC and I would receive the grant.
-
Frontier Compute has received no Coinholder Retroactive Grant funding for this work.
-
Our separate ZAP1 application concerns unrelated attestation tooling.
-
Any overlapping bounty payment will be disclosed and deducted dollar-for-dollar before disbursement.
-
There will be no double recovery.
I stayed with this work from discovery and responsible disclosure through remediation review, merge, release ancestry, and residual-risk verification.