Bug bounty triage is wild: report a real staging bug, retest days later, behavior changed.
Lesson: record video at submission; truth expires fast. @0xPira
Opus 4.8 + Ultra Code mode.
48 hours later: 3.3B tokens burned. Almost $1,000 gone.
I’ve been using the plan for 8 months and had never managed to hit anything like this.
I barely even used it properly on day two.
It was beautiful to watch, but painfully expensive.
Hacking tip 😎
Don't assume that something is secure just because the feature exists.
We saw a bug recently where an application had custom auth. The user entered their password, if it was correct they had to enter a 6 digit code that was sent to their email address. The endpoint had throttling enabled.
Most hackers would stop there. This one didn't! They worked out that the password step could be skipped completely, and then they worked out that the throttling on the 2FA endpoint was throttled by IP.
They found a full ATO on any account by rotating their IP address on every request and simply brute forcing the 6 digit code.
If you're a hacker, don't assume anything!
Valeu demais pelo retorno, equipe @arkanisgg / @ostracontent!
Feliz em saber que parte dos pontos já foi implementada. Sempre que eu encontrar algo relevante em análise de segurança, vou ficar à disposição para reportar com e ajudar no que puder.
Tamo junto 🤝 #Arkanis
Of the 4 bugs I found, 2 were duplicate medium-level bugs and 1 was a duplicate high-level bug; the other is still marked as critical and will probably go to triage, do you think I'll get my first bounty?
BUG BOUNTY é um jogo de gato e rato MUITO engraçado
> eh o hacker tentando justificar que o bagulho tem o maior impacto possivel
> e o triager tentando provar que essa merda eh inutil
FACILMENTE um tribunal de MINÚSCULAS causas