Security auditing for Large Language Models (LLMs) has long been a bottlenecked by the need for human ingenuity, but a new project called SolSecureAI is attempting to streamline the process using blockchain infrastructure. Developed by Hasan Abushamla for the Colosseum Hackathon, the platform combines crowdsourced red-teaming with Solana-based smart contracts to manage security rewards transparently. The core problem it addresses is the inability of traditional automated scanners to detect nuanced vulnerabilities like prompt injection, which require creative, human-led attacks to uncover.

Technical Architecture and Stack

The platform’s backend relies on a Node.js server that manages an isolated proxy architecture and live WebSocket sessions, routing prompt payloads directly into target LLMs. On the frontend, a Next.js interface provides a real-time playground where security researchers can craft injection payloads. The most critical component, however, is the smart contract layer written in Rust using the Anchor framework. This layer handles fund escrows and on-chain challenge verification, ensuring that the financial incentives for finding bugs are handled programmatically rather than through manual administrative overhead.

Automated Validation and Payouts

The workflow begins when a company launches an evaluation challenge by defining system guidelines and funding a Solana escrow contract. Researchers then attempt to bypass these guidelines in the web console. If a user successfully triggers a verifiable system-instruction bypass or data exfiltration, the validation layer communicates with the smart contract to instantly release the bounty to the researcher’s Web3 wallet. This automation removes the friction typically associated with verifying and paying out bug bounties, potentially accelerating the feedback loop between developers and security testers.

Key Takeaways

  • SolSecureAI is currently live on Solana Devnet and fully open-source, allowing community verification of its security tools.
  • The tech stack integrates Rust/Anchor smart contracts with a Node.js/Next.js application layer for real-time interaction.
  • Bounties are released automatically upon successful validation of prompt injection or exfiltration attacks.
  • The project was built for the Colosseum Hackathon and seeks community feedback on its verification model.

The Bottom Line

Using blockchain for simple payment escrow in dev tools is often overkill, but here it solves a real trust issue in decentralized security testing. If the validation layer is robust, this could lower the barrier for companies to run effective LLM security audits without heavy administrative costs.