I strongly support this proposal.
Scalar is the researcher who set off the wave of security disclosures Zcash has seen this year. He disclosed a number of vulnerabilities in March and April. He was the inspiration for Shielded Labs hiring Taylor Hornby as a Security Consultant, which we said in our announcement at the time. Scalar’s findings convinced us that AI had changed the game for security research, that we were (as Zooko says) heading for an AIpocalypse, and that we needed to get ahead of it. If it weren’t for Scalar, we might never have engaged Taylor, and the Orchard vulnerability would have gone undiscovered, or worse, been found and exploited by an attacker. And as @sangsoo notes above, his work also inspired other researchers to start hunting for and reporting bugs in Zcash.
In March, a security engineer from another ecosystem put me in touch with Scalar. He had discovered that zcashd had been skipping Sprout proof verification since 2020, a critical bug that sat undetected for nearly six years and could have resulted in the counterfeiting of ZEC. Over the following weeks he reported a number of additional vulnerabilities in zcashd and Zebra, several of them high severity. I was his primary contact throughout, and worked closely with him. He handled everything professionally. He disclosed privately, reported promptly, and, at the time, had no expectation of being compensated.
Despite all that, his compensation to date has been modest. There was no bug bounty program in place when he made his disclosures, so Shielded Labs, ZODL, Bootstrap, and the Zcash Foundation put together a donation to thank him, and ZCG later contributed as well. In total he received 600 ZEC, worth less than $200K when he received it. ZCG tried to stand up a bounty program afterward, but it was shut down before Scalar could apply for anything more. The compensation he received is a fraction of what similar findings have paid out elsewhere in the industry.
There is a separate conversation happening right now about how Zcash should handle bug bounties in the AI era, and it’s worth having. ZCG’s program was a good-faith effort, but the flood of AI-generated reports overwhelmed the core engineers, and shutting it down was the right call. Whatever the community eventually lands on, the retroactive grants program is currently the only avenue a researcher has to be paid for protecting the network. Researchers like Scalar are rare, and how coinholders respond to applications like this one will determine whether the next one who finds a critical bug reports it, ignores it, or does something worse with it. Scalar did everything right, and his request is reasonable. I hope coinholders approve it.