Today we're releasing @bountyvision
Here we aggregate bug bounty insights across platforms to:
1. Show the state of bug bounties across the ecosystem
2. Assess bounty sizes relative to funds at risk
3. Aid whitehats in finding bounty information (including in-scope assets)
Security is the #1 problem we need to solve for crypto and DeFi to reach their potential
That's why I couldn't be more proud to have @nascentxyz co-lead this round for @phylaxsystems
We have looked at a lot of security solutions, but here's why we believe this team is unique 🧵
🚨 "Recent Updates" is live! 🚨
We aggregate bounties across every platform and showcase those with the latest changes 🎯
Spot fresh code in bounties—prime targets for new bugs 🐛🔍
Stay up to date on Twitter and in our new Telegram channel 📢
https://t.co/rnRf1T0sNo
The onchain game @kamigotchiworld has pulled me in like none before
It's both a fun game and an onchain way to prove your hacker skills
Here's how I've used my technological superiority to dominate 🧵👇
Morpho's massive new max bounty of $2.5M makes them leapfrog 3 other protocols in the lending space.
Here's the new lending leaderboard 🏆💵👀
1. @fraxfinance ($10M)
2. @sparkdotfi ($5M)
3. @MorphoLabs ($2.5M) ⬆️⬆️⬆️
4. (tied) @aave ($1M) ⬇️
4. (tied) @solendprotocol ($1M) ⬇️
4. (tied) @SovrynBTC ($1M) ⬇️
Find where you stack up at https://t.co/nSOrh319SM
When starting on a new bounty, one of the first thing to do is find which contracts hold funds.
Usually this requires opening every explorer page in the bounty and making a mental note of the high-value contracts.
We make it easy!
Protocol pages are live!
Our goal for BV is to be great at both:
1. Providing insights into the overall bug bounty landscape
2. Giving security researchers what they need to quickly find bugs in live contracts
Protocol pages will be our main hub for #2
Bounty-size / TVL tracks how a protocol incentivizes whitehats or blackhats
Bounty-size / LoC tracks the reward vs effort of digging
LoC in scope / Total LoC tracks if a bounty is bullshit or real
With the release of https://t.co/x9YY4i9Xv7 from @NascentSecurity, something has popped into my head:
does "Bigger Number == Better Security"?
and I've come to the conclusion: a resounding NO*
*in isolation
let explore what makes a good bug bounty 👇
No one outside of North Korea is happy with the current state of DeFi security
Fortunately, there is something we can do about it:
SPEND MORE ON SECURITY!
Strap in for a discussion of security budgets, bounty flywheels, and a new tool from @NascentSecurity...
Pleased to release the beta version of our bounty aggregator, @BountyVision!
Quoted is a great explainer on our goals for the platform - however, I wanted to comment a bit on the benefits for security researchers:
🪅 🙌
Excited to announce the release of @BountyVision built by our team @NascentSecurity
If you are a bug huntoor this tool should be super helpful for you to find next interesting and valuable project to work on
https://t.co/AqgEJQj9Lt
Today we're releasing @bountyvision
Here we aggregate bug bounty insights across platforms to:
1. Show the state of bug bounties across the ecosystem
2. Assess bounty sizes relative to funds at risk
3. Aid whitehats in finding bounty information (including in-scope assets)