@MitchellAmador what of bug bounty reports requiring people to pay? there should be a refund policy for duplicates since i would be competing against magnus, other ai's so immunefi always wins. the firedancer comp should be evidence it doesnt stop spam. what are your thoughts?
This is becoming stupid. Just tried to submit a bug and says pay $100. If it’s a duplicate you don’t get your money back??? What are we doing. In contests it makes sense that duplicate rewards get paid. But this is just insanity.
Just shipped on Immunefi: Priority Mediation.
For a while now, security researchers have been telling us the same thing: when you've put real work into a report and you believe in it, waiting weeks for a mediator to pick it up is brutal.
Priority Mediation now lets researchers who are confident in their submission pay to get faster resolution with a hard commitment: resolution within 30 business days, mediator status updates at least every 7 business days along the way.
A couple things I want to be explicit about, because they matter:
1) Free mediation requests are reviewed by the same trained mediators, using the exact same decision framework.
2) The tier you choose affects the queue, not the verdict. A paid mediation does not buy you a favorable outcome. It buys you speed and additional hands-on activity. Every case gets the same impartial review, full stop. If we ever blurred that line, the whole system would be worthless.
This is one of several changes we're shipping based on direct researcher feedback.
Keep it coming so we can usher in SR Summer.
@WhiteHatMage@DadeKuma yeah theres insane frontrunning on all sides. immunefi has an ai service that can flag bugs and if you exploit uses the bugs to reach an exploit it would be duped. they also started charging for reports and funds go to immunefi as well. its gonna be really interesting.
@ZeroK_____ I use Claude code opus 4.7 there is also 4.6 which is good, it’s way cheaper than using apis since pricing is fixed. I give it a scope and an impact and tell it to find an exploit chain since the scope is narrowed it won’t get fatigued. You can also have it threatmodel for you.