### Terms and Conditions
- [x] I agree to the [Grant Agreement](https://9ba4718…c-5c73-47c3-a024-4fc4e5278803.usrfiles.com/ugd/9ba471_6ff6db4095fd4c4ba21babec361e927e.pdf) terms if funded
- [x] I agree to [Provide KYC information](https://9ba4718c-5c73-47c3-a024-4fc4e5278803.usrfiles.com/ugd/9ba471_7d9e73d16b584a61bae92282b208efc4.pdf) if funded above $50,000 USD
- [x] I agree to disclose conflicts of interest
- [x] I understand that this grant program is only eligible for completed work, as it is a retroactive grant program. Applications for planned or partially completed work will not be considered. All completed work will be verified and accepted by its intended users or their representatives, who will confirm that the outputs meet the required quality, functionality, and usability before the work is listed as an option for Coinholder voting.
- [x] I agree that for any new open-source software, I will create a CONTRIBUTING.md file that reflects the high standards of Zcash development, using the [`librustzcash` style guides](https://github.com/zcash/librustzcash/blob/main/CONTRIBUTING.md#styleguides) as a primary reference.
- [x] I understand when contributing to existing Zcash code, I am required to adhere to the project specific contribution guidelines, paying close attention to any [merge](https://github.com/zcash/librustzcash/blob/main/CONTRIBUTING.md#merge-workflow), [branch](https://github.com/zcash/librustzcash/blob/main/CONTRIBUTING.md#branch-history), [pull request](https://github.com/zcash/librustzcash/blob/main/CONTRIBUTING.md#pull-request-review), and [commit](https://github.com/zcash/librustzcash/blob/main/CONTRIBUTING.md#commit-messages) guidelines as exemplified in the librustzcash repository.
- [x] I understand all grants are valued in USD but will be disbursed in Shielded ZEC. I acknowledge and accept that disbursement amounts may fluctuate based on the ZEC/USD exchange rate at the time of payment.
### Application Owners (@octocat, @octocat1)
@aquietinvestor
### Organization or Individual Name
Jason McGee. I am recommending coinholders approve a bonus grant to Taylor Hornby, the sole recipient, in addition to the bug bounty he requested in application #51. I am submitting this in my personal capacity as a coinholder; no funds go to me or to Shielded Labs, where I serve as Executive Director.
### Additional Team Members
```team-members.yaml
None. Taylor did not request this nomination and had no role in preparing it.
```
### How did you learn about the Lockbox: Coinholder Retroactive Grants Program?
I helped create the Coinholder Retroactive Grants Program and helped administer its first rounds, and Shielded Labs is one of the keyholder organizations. This nomination was prompted by reading application #51 and concluding that Taylor asked for too little.
### Requested Grant Amount (USD)
$750000
### Category
Research & Development
### Project Summary
This is a bonus grant nomination, not a standard application. Taylor Hornby applied for a $750,000 bug bounty in [application #51](https://github.com/Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram/issues/51) for finding and responsibly disclosing the Orchard counterfeiting vulnerability, a bug that put roughly $2.3B of ZEC at risk. His ask is far below industry norms for a finding of this severity. This application adds $750,000, bringing the total to $1,500,000.
### Project Description
This application was inspired by [Zooko's forum post](https://forum.zcashcommunity.com/t/retroactive-grant-application-give-bigger-grants-to-taylor-and-tachyon/57012) suggesting we should be able to nominate people for retroactive grants rather than waiting for them to apply, and that Taylor asked for too little. I agree, and this application acts on it. Frank Braun also reached out to me separately to advocate for a bonus grant for both applicants, having come to the same conclusion on his own.
The work itself is described in [application #51](https://github.com/Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram/issues/51) and I won't restate it here. In short: Taylor found an undetectable counterfeiting vulnerability that had sat in the Orchard circuit for four years through every audit, reported it immediately, built the proofs of concept that established it was real and exploitable, and then spent weeks helping ZODL and the Zcash Foundation review and test the patches. Every ZEC holder benefited from that disclosure.
The reason for this application is the number. Taylor's own table makes the case better than I can: the smallest bounty-to-funds-at-risk ratio among the precedents he cites is 0.24%, and most are far higher. His request works out to 0.033%. Even with this bonus, the total of $1,500,000 is about 0.066% of the funds at risk, still roughly a quarter of the smallest precedent. He deliberately asked below industry norms. That restraint speaks well of him, but coinholders do not have to accept the discount, and there is a good reason not to.
The reason is incentives. Zcash has no formal bug bounty program; ZCG's closed days before Taylor found this bug. The retroactive grants program is currently the only mechanism that can pay a researcher for a catastrophic finding. What we pay here sets the reference point for the next person who finds a counterfeiting bug and weighs disclosure against the alternatives. A bounty that rounds up to industry norms, rather than down, is cheap insurance for a protocol whose entire value rests on the integrity of its supply.
One more point, because I am well placed to make it: Shielded Labs hired Taylor as a contractor to do AI-assisted security auditing, and that engagement is how the bug was found. Some might argue his consulting pay covers the discovery. I run Shielded Labs and I disagree. We paid for auditing effort at a standard consulting rate. We did not, and could not, pay for the outcome of preventing a multi-billion-dollar counterfeiting event. Bounties exist precisely because the value of a critical finding bears no relationship to the hourly cost of looking for it. His rate did not include a discovery premium, and no bounty program in the world nets out salary before paying an award.
### Technical Approach (how you did it)
Not applicable. This application adds no new work. The technical approach is documented in [application #51 ](https://github.com/Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram/issues/51)and in Shielded Labs' published account of the vulnerability.
### Time Period of Work Completion
May 2026 - June 2026 (the same period as application #51)
### Total Budget (USD)
$750000
### Budget Breakdown
Other: $750,000. Justification: a bonus to Taylor Hornby in recognition that his requested bounty sits far below the industry precedents cited in his own application. The figure is set so that the total bounty for the disclosure equals $1,500,000, which is about 0.066% of the funds at risk, still well under the lowest comparable ratio.
### Previous Funding
No
### Previous Funding Details
Not applicable
### Other Funding Sources
No
### Other Funding Sources Details
No funding source covers this bonus. Taylor's own funding history, including his Shielded Labs consulting engagement and the gifts he received after disclosure, is disclosed in [application #51](https://github.com/Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram/issues/51).
### Success Metrics
The success metrics for the underlying work are in [application #51](https://github.com/Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram/issues/51): the vulnerability was disclosed responsibly, patched without exploitation, and led directly to the formally verified Ironwood pool.
The success metric for this application is different: that coinholders establish, on the record, that a researcher who hands Zcash back billions of dollars of protected value will be paid at a level that makes honest disclosure the obvious choice next time.
### Proof of completion
All proof of completion is in [application #51:](https://github.com/Financial-Privacy-Foundation/ZcashCoinholderGrantsProgram/issues/51) Shielded Labs' blog post with the full writeup and Taylor's work log, and the accompanying posts from ZODL and the Zcash Foundation.
### Conflict of Interest Disclosure
1. I am the Executive Director of Shielded Labs, one of the keyholder organizations of this grants program. I also helped create the program and helped administer its first rounds. I am submitting this nomination in my personal capacity, and no funds go to me or to Shielded Labs.
2. Shielded Labs hired Taylor as an independent contractor for the AI-assisted auditing work that found the vulnerability, and funded the audit itself. I am his client. I believe this gives me direct knowledge of the work rather than a financial interest in this application: Shielded Labs gains nothing from the bonus, and his consulting engagement is unaffected by whether coinholders approve it.
3. Taylor did not request, review, or contribute to this application. He may decline the funds if he wishes.
4. I am a ZEC coinholder and participate in coinholder polls.
### Community Forum Posting
- [x] I understand it is my responsibility to post a link to this issue on the [Zcash Community Forums](https://forum.zcashcommunity.com/t/about-the-retroactive-grants-category/52106) after this application has been submitted so the community can give input. I understand this is required in order for the community to discuss and vote on this grant application. Note: If you are unable to post on the forum (for example, due to new user restrictions), please leave a comment below, and we will adjust your posting permissions.