Everything verifiable is redacted & archived — 49 bugs item-by-item, all 3 calls verbatim, full Telegram thread, 11 on-chain txns, CVE records.
Zero PoC. Zero reusable weapons. Own funds & own Pod only. No third-party loss.
Full write-up 👉 https://t.co/lyoA0eERC7
Blog: https://t.co/HJYM5S9CI0
I reported 49 security vulnerabilities to @DonutAI — a $22M-funded AI crypto project (BITKRAFT, Hack VC, Sky9).
One of them: open a single link, no prompt, and your wallet can be silently drained.
Their response wasn't a thank-you. It was a legal threat.
Here's what happened. 🧵
On the 2nd call, the product lead's verbatim words about my report (kept in original Chinese):
"比花了很多钱找的那个专业团队���的报告,有些角度是比较深的。"
(gist: deeper in places than the expensive pro team they hired)
When I prepared to publish as agreed, this is the reply I got 👇