@HackenProof Classic CEI violation leading to Reentrancy...
_safeMint triggers an external call before updating usedPass[msg.sender] = true;. An attacker can re-enter and bypass the single-use check completely.....
My latest Web3 audit:
🎯 5 Dups (radar works, speed doesn't).
❌ 2 Rejected (I see a flaw, devs see "defensive design").
💰 Payout: $0 & a headache.
Bug bounty is a masterclass in humility. We go again! ���️
#BugBounty #Web3Security
Nothing tests your sanity like 5 Duplicates on a massively complex project. 🤯
I almost gave up. But when the easy bugs are gone, you look at the math. Found a fatal time-logic flaw and pulled 2 NEW bugs 🕵️♂️⚡
Keep digging.
#SmartContracts#BugBounty
Let's wait for the result.
@MitchellAmador Huge milestone! Losing a report to an empty duplicate is frustrating. My high-severity report was closed & triggered an SNR autoban, despite a functional Mainnet-forked PoC for exact economic extraction. Eager for manual review to test this new era!
Nothing tests your sanity like 5 Duplicates on a massively complex project. 🤯
I almost gave up. But when the easy bugs are gone, you look at the math. Found a fatal time-logic flaw and pulled 2 NEW bugs 🕵️♂️⚡
Keep digging.
#SmartContracts#BugBounty
Let's wait for the result.
Echo Protocol was hacked for $76M, but the attacker only cashed out $820K. Why? Zero exit liquidity. You can mint infinite unbacked tokens, but you can't drain what isn't there.
The real tragedy? No Timelocks or Mint Caps. Don't build Web3 on Web2 security. 🛡️💻 #DeFi
@pawel_research Not dumb, just no exit liquidity. You can mint $76M from thin air, but you only drain the actual TVL in pools. The real tragedy? Missing basic on-chain guards: no Timelocks, no Mint Caps. A complete architecture failure
@arshadkazmi42@Hacker0x01 Platforms are drowning in AI spam, while researchers building functional Mainnet-fork PoCs pay the price—often facing unfair SNR autobans. Bounties must reward actual proof, not who clicked submit first. Great tip on tracking NA duplicates!
@VagnerAndrei98@immunefi 100% agreed. The disconnect between protocol specs and platform triage is a real issue. I just got hit with a strict SNR autoban immediately after a report closure, despite providing a fully functional Mainnet-forked PoC demonstrating exact economic extraction..good work
A reminder for DeFi developers: Relying on the frontend for slippage protection is NOT enough. If your smart contract lacks an explicit min_lamports_out guard during liquidity withdrawals, it leaves users completely exposed to MEV sandwich attacks on-chain.
@chameleon_jeff That’s exactly why Hyperliquid stands out it delivers what blockchain truly promised: verifiable transparency, not blind trust.
CEXs still sell "trust" as a feature instead of proving it onchain.
#DeFi#OnchainTransparency