We are incredibly grateful to the researchers who have submitted high-quality reports to the ZCG Security & Vulnerability Disclosure Initiative, and any reports submitted prior to this announcement will still be fully evaluated under the original terms. However, the rise of AI-assisted tools has flooded the program with speculative and duplicate submissions. Triaging these low-signal reports drains scarce engineering resources away from critical work. Because of this, effective today, the ZCG Vulnerability Bounty Program is officially closed.
While the monetary bounty is ending, the standard responsible disclosure process remains open for good-faith reports. Moving forward, ZCG will focus on proactive, structured security investments, including expert audits and AI-assisted analysis platforms. For a full explanation of this decision, please read our detailed closure announcement here. Thank you to everyone helping protect the Zcash ecosystem.