professional bringer of bad news to security teams 💀
the bug's always in the code they forgot they shipped 👁
#1 week on @HackenProof 🩸
🇺🇦bug bounty hunter
5 weeks ago i wrote: "20 reports, 1 paid, one stuck 2 months." said the industry had a payout problem and went silent. spent every night in vendor code, chasing bugs nobody else did. today: 7 paid, #1 hacker of the week on @hackenproof as @redvision (me). we fucking earned this.
a signature proves a message wasn't changed. it does not prove the right message got signed 👁
my favorite class in anything crypto-adjacent. the server builds a blob, signs it, later verifies the signature is valid, and everyone reads "valid signature = trusted request." the real question nobody asks: which fields are actually inside the signed blob?
amount signed but recipient not? keep the signature, swap the recipient. nonce not covered? replay it. chain id missing? the same signed intent works on a second chain. EIP-712 made this worse, the struct looks exhaustive so devs stop checking what it actually commits to.
the bug is never the cryptography. it's the one critical field living outside the signed bytes. always ask: what does this signature NOT cover? 🔓
@HackenProof@immunefi@Hacker0x01 #infosec #cryptography #web3 #bugbounty #appsec #ethicalhacking #hacking
"3 business days." that's the reward SLA on paper 🩸
in reality it's weeks. months. sometimes silence you have to break yourself. in security we obsess over response times, incident SLAs, time-to-patch. apparently that discipline applies to incidents, not to invoices.
20 reports, a handful paid, one stuck two months with no status change. bug bounty has a payout problem the platforms don't put on the landing page, and the hunters grinding full-time already know it.
i still hunt. i just stopped believing the timeline and started building a runway for the real one. patience here isn't a virtue, it's the entry fee 🩸
@HackenProof@Hacker0x01@Bugcrowd@intigriti@yeswehack@immunefi #bugbounty #infosec #bugbountytips #cybersecurity #appsec #ethicalhacking #hacking #infosaccommunity
@AnthropicAI this is the access model the field actually needed. tying capability to verified authorization instead of one blanket safeguard is the right call, and honestly overdue.
one ask from the other side of the table: make sure solo researchers can reach the offensive tiers too, not just companies and red teams. a huge share of real bug bounty work is one person, one terminal, deep in vendor code at 3am. i run solo, finished #1 hacker of the week on @HackenProof, and claude is already the core of how i read bundles, reverse flows, and model trust boundaries.
the lone hunter is half of this industry. verify the person and the authorization, not just the org chart.
tip: when a finding dies, don't delete it. bank it with a note on what would bring it back ⏳
write the finding, the reason it's dead, and the exact condition that would revive it. "works if i get a second account." "needs a leaked token." "dead unless the cache behaves differently." then date it.
weeks later when you find that missing piece on another target, you've already got half a chain written. my best payouts started as two banked zeros that finally met.
dead findings are inventory, not trash 🩸
#bugbounty #bugbountytips #infosec #appsec #methodology
tip: a 403 or a 429 is not a wall, it's a hint 🔓
before you call an endpoint dead, vary the request one axis at a time. change the method. change the case. url-encode, then double-encode. move the param into a header or the body. swap the content-type.
a filter that blocks one shape of a request often waves through another. the block itself tells you something is being guarded, which means something is there worth guarding.
one rejection is one attempt, not a verdict 🩸
#bugbounty #bugbountytips #appsec #websecurity #infosec
tip: read the OUT of scope section before the in-scope one 🎯
the exclusions tell you what the program is scared of. a specific endpoint carved out, a subdomain marked off-limits, a technique they explicitly ban. that list is a map of where they think their soft spots are.
you can't hunt the excluded stuff, but it shows you how they think, and the in-scope asset sitting right next to an excluded one is often the same code with the guard rail forgotten.
scope is intel, not just rules 🩸
#bugbounty #bugbountytips #infosec #recon #appsec
tip most beginners skip: register a SECOND account before you test anything authz-related 👁
you cannot prove an IDOR or a cross-tenant bug with one account. account A reading account A's data is just using the app. you need A reading B's object for it to be a finding at all.
then run the negative control. prove a forged token gets a 401, prove a random id gets a 404. if the attack and the normal case look identical, you haven't shown impact, you've shown behavior.
two accounts and a negative control turn a maybe into a report 🩸
#bugbounty #bugbountytips #infosec #appsec #IDOR
bug bounty tip: before you send a single payload, check if the site shipped its sourcemaps to prod 🧵
open devtools, sources tab, look for .js.map files, or just append .map to a bundle url. if they're there, you now have their original un-minified source.
grep it for api base urls, internal route names, feature flags, role checks, and the occasional hardcoded key someone forgot. the client-side validation you find is a map of what the server might not be re-checking.
half my recon is reading code the target handed me for free 🩸
#bugbounty #bugbountytips #appsec #infosec #websecurity
one of my paid bounties this year was two dead findings stitched together 🔓
both got banked weeks apart. on their own, each one was a shrug. a weak info-leak nobody would pay a cent for, and a state quirk that did nothing by itself. i wrote both off, logged them, moved on, fully expected never to touch either again.
re-read them on a slow night with nothing better to do and realized the output of the first was exactly the input the second needed. the leak handed me the value, the quirk let me use it. two zeros became one real payout, and neither half would have paid alone.
this is the part people miss chasing the one clean critical. real severity is usually not one perfect bug. it's one low feeding another low feeding a third until the chain does something none of them could do separately. the triager doesn't pay for the pieces. they pay for what the pieces become together.
your banked findings are not corpses. they're ingredients. go read your own dead pile tonight, you've probably already found half of your next payout and forgotten it 🩸
@HackenProof@Hacker0x01@Bugcrowd@intigriti@yeswehack@immunefi #bugbounty #bugbountytips #infosec #appsec #cybersecurity #ethicalhacking #hacking #websecurity
my best lesson this year came from a report that paid zero 👁
got it back marked informative. no bounty, no rep, just a triager note explaining why the impact didn't hold up. i was annoyed for about a day, told myself the triager just didn't get it. then i actually sat down and read the note properly.
it pointed straight at where my thinking was lazy. i'd proven a property and called it an impact. exposure is not abuse. a value leaking somewhere is not the same as taking that value and moving another user's data, draining a balance, touching something that isn't mine. i'd stopped one step short of the thing that actually pays and dressed it up as a finding.
every accept just tells you that you were right about something. a good N/A tells you exactly how you were wrong, in detail, for free, from the person who decides what gets paid. that's the most valuable feedback in this whole game and most hunters rage-close the tab before reading it.
i keep a folder of those notes now. re-read them before i start a new target. it's worth more than the dashboard 🩸
@HackenProof@Bugcrowd@intigriti@Hacker0x01@yeswehack #bugbounty #infosec #bugbountytips #appsec #cybersecurity #ethicalhacking #websecurity #hacking
my first four-figure bounty came after three months of nothing 💀
three months of reports that went informative, N/A, duplicate, or just silence. no money, no rep, half the time no feedback at all. i genuinely thought i was bad at this and that everyone else had some trick i was missing. everyone posts the win. nobody posts the ninety days of dead submissions it took to get there, because a drought doesn't make a good screenshot.
then one landed. i refreshed the platform tab like an idiot, convinced they'd made a mistake and would claw it back. they didn't. the amount was right, the status said rewarded, and i just sat there staring at it.
it didn't feel like winning. it felt like the drought finally breaking after i'd half-decided to quit. the second one hit completely different, because by then i knew the first wasn't luck, it was the ninety days quietly compounding. if you're in your own drought right now, that isn't proof you're bad at this. it's the toll. everyone getting paid today paid it first 🩸
@HackenProof@Hacker0x01@Bugcrowd@intigriti@yeswehack #bugbounty #bugbountytips #infosec #cybersecurity #appsec #ethicalhacking #hacking
the signer trusting input it never actually validated. it checks the signature is well-formed and moves on, but the thing it signed, the recipient, the amount, the chain id, half of that was never covered by what it verifies.
you're not breaking the crypto. you're handing it a valid message the system assumed nobody would ever send. that's the whole class.
i stopped hunting smart contract bounties 💀
not because they don't pay. because the serious protocols ship after two audit firms, a Code4rena or Sherlock contest, and often a formal-verification pass. by the time the bounty opens you're the sixth set of eyes on code that's been read line by line for months.
the easy classes are already swept. reentrancy, unchecked external calls, basic access control, integer overflow. what's left is deep economic logic, and three whales are already parked on it.
so i moved to the code fewer people read 🩸
@HackenProof@immunefi@intigriti #bugbounty #web3 #smartcontract
@ChalupaBrock exactly. and it's not just the route names. a prod sourcemap hands you the client-side validation logic too, which is basically a map of what the server is probably not re-checking. the routes get you in the door. the validation gaps tell you what to try once you're in.
i read the target's own code before i send a single request 👁
js bundles, sourcemaps if they shipped them to prod by accident, the mobile app pulled straight from the store and run through jadx, any public repo or npm package with their name on it. half a target's attack surface is sitting in files they already handed you.
here's why it beats scanning: most bugs are an assumption the developer made on the client and never enforced on the server. a role check that only lives in react. a price validated in the browser and trusted on submit. an object id the frontend "knows" belongs to you. a feature flag gating an endpoint that's still live if you call it directly. the server trusts all of it until you prove it shouldn't.
you find those by reading intent, not by firing payloads blind. the sourcemap hands you the internal route names. the APK hands you hardcoded endpoints, exported activities, deeplink handlers, sometimes a key someone forgot to strip. the client-side validation tells you exactly what the server is probably NOT re-checking.
a scanner sees 200 and moves on. it never reads the comment that says "TODO: add authz here". that line is the bug.
read first. fire second 🔓
@HackenProof@Bugcrowd@intigriti@Hacker0x01@yeswehack #bugbounty #appsec #infosec #bugbountytips #websecurity #cybersecurity #ethicalhacking #hacking #OSINT
mostly web and api honestly. auth and oauth flows, dashboards, the internal endpoints behind these crypto platforms. client-side too, xss, postmessage, the dom stuff people stopped checking.
then the crypto layer, mpc libs, oracle feeds, signer services offchain. the contract gets four audits, the machine around it gets none.
so not one lane. web is the bread and butter, the crypto infra is where it gets interesting.
a report sat in triage for two months once ⏳
i checked the status every morning like it was a lab result. new, then triaged, then accepted, then nothing for weeks while the fix crawled through their internal release cycle. the bounty landed the day i'd stopped looking.
nobody tells you this when you start: the payout clock and the validation clock are not the same clock, and neither one is the "3 business days" the platform advertises. "accepted" means they agree it's real. it does not mean money. a critical can sit accepted-but-unpaid for a month while finance, legal, and the vendor's patch schedule each take their turn.
the hunters who burn out are the ones who read every silent week as a rejection. the ones who last read it as the shape of the job. you bank the finding, you log it, you move to the next target, and you let the queue resolve in the background. your attention is the scarce resource, not your reports.
patience here isn't a virtue, it's a filter. most people don't have it, and that's exactly why the lane stays worth hunting 🩸
@HackenProof@Hacker0x01@Bugcrowd@intigriti@yeswehack@immunefi #bugbounty #infosec #bugbountytips #cybersecurity #appsec #ethicalhacking #hacking #web3
bridges and oracles are where the money actually moved in crypto ⚡
not the token contracts everyone audits. the infrastructure under them. the logic lives off-chain in a relayer or a signer service, the trust assumptions are mostly undocumented, and far fewer people hunt them because it isn't a tidy verified solidity file you can read in an afternoon.
think about where the nine-figure losses came from. price oracles reading a spot reserve a flash loan can move in one block. message-passing bridges where the proof is validated on the destination chain but the source event was never really final. signer committees where one key off, one stale validator set, one replayed signature, is enough to forge a withdrawal. none of that is a missing SafeMath.
the hybrid surface is the richest and the quietest. a dapp frontend that builds swap calldata a signer blindly signs. an RPC that trusts a client-supplied chainId. an EIP-712 struct that doesn't actually cover the field that matters, so the same signed intent replays for a different recipient. these are logic bugs. you find them by modeling the system, not by running a tool.
the gap between "everyone audits the contract" and "almost nobody audits the machine around it" is the entire reason i went there 🩸
@HackenProof@immunefi@Hacker0x01@Bugcrowd #web3 #web3security #DeFi #DeFiSecurity #smartcontract #blockchainsecurity #cryptography #infosec #bugbounty
reported a high last month. got paid a medium 🩸
the severity you submit and the severity you get paid are two different numbers, set by two different people. you bring your CVSS vector. the triager brings their internal matrix, their budget, and their last 50 dupes. the two almost never line up.
here's the part nobody tells you: CVSS 8.1 on paper means nothing if the attack path needs a victim click, a stale cache, and a config most tenants never enable. AV, AC, PR, UI, those four metrics quietly set your payout before anyone reads your writeup. high attack complexity plus required user interaction drags a "critical" down to a medium every single time.
impact you can't demonstrate against a non-self target gets downgraded, period. exposure is not impact. a leaked value is a property. moving another user's object, reading another tenant's data, draining a balance on a fork, that's impact.
so now i calibrate my own claim before triage does it for me. negative control first. forged token gets a 401. another user's id gets a 404. then i prove the cross-tenant read on a real second identity. if it doesn't survive that, i file it a tier lower and say so.
lose the headline, keep the trust. the triager who catches you under-claim once reads your next report first 💀
@HackenProof@Hacker0x01@Bugcrowd@intigriti@yeswehack #bugbounty #bugbountytips #infosec #appsec #cybersecurity #websecurity #ethicalhacking #pentesting
most of what i call recon is reading the scope and the asset list for an hour before i touch anything 🎯
wildcard or single host. which apex is in, which subdomain is explicitly out. whether staging counts. whether the mobile app and its API are separate assets. what's out of scope on its own but allowed as a chain.
a lot of hunters skip this and burn a week on an asset that was out of scope the whole time. then the report closes N/A and the rep takes the hit.
the boring hour is the part that pays 🩸
@Bugcrowd@HackenProof@intigriti@Hacker0x01@immunefi #bugbountytips #infosec
this is exactly what i told you. 2 informative and 1 oos on a codebase two audit firms already combed isn't you missing anything. the valid bugs were gone before you cloned the repo. smart contract bounties on the serious protocols are the most picked-over code in crypto.
the systematic process you built is the real takeaway, that transfers to any target. but if you want valid findings, the room is in the layer under the contracts, not in them. keep going.