1 months ago I've discovered a critical vulnerability in @MezoNetwork's AssetsBridge precompile which could have led to a direct theft of $1,753,958.4 ($40m if no ratelimit).
happy to share the security advisory (includes full report + PoC) and mezo post-mortem write-up.
https://t.co/HrwTU95Duj
I'm also planning to post soon an X article about this finding which will include much more context on my journey and this discovery.
> Actually reporting the vulnerability was more difficult for the researcher than we would prefer...
I feel you. Projects that don't host bounty programs usually have some hidden Criticals, and it's hard to contact them.
Great job by our fellow whitehat and by the team.
1 months ago I've discovered a critical vulnerability in @MezoNetwork's AssetsBridge precompile which could have led to a direct theft of $1,753,958.4 ($40m if no ratelimit).
happy to share the security advisory (includes full report + PoC) and mezo post-mortem write-up.
https://t.co/HrwTU95Duj
I'm also planning to post soon an X article about this finding which will include much more context on my journey and this discovery.
@WhiteHatMage Going outside bbp is very risky, as most of protocols just don't care about security, it even goes to a matter "am i going to get blocked" lol
Either way sometimes you get lucky and come across great protocol teams like @MezoNetwork etc.
@mhluongo@Tradus138519@MezoNetwork Exactly, this industry would be doing much better if there were more protocols that followed Mezo's example in the way they handle security and treat security researchers 🤝
@Tradus138519@fromeo_016@MezoNetwork there's way more context that would also justify a higher appropriate bounty but atleast the token airdrop paid off too.
Happy Monday.
Security researcher @DeltaXV_ just earned $20,000 for finding a High blockchain/dlt vulnerability.
We're sure they'll find their first crit soon. We'll be watching.
To help Delta get to the next level, you can pledge IMU behind them here: https://t.co/MUsBzmWgtk