@mrhamzoz @immunefi If someone uses AI to submit slop, then sure - ban them.
But if AI is used to produce valid findings, with real PoCs that actually prove the issue, why would you ban someone for that?
I think this might be the largest bounty so far for an AI-assisted finding.
And yes, confession time: I used the AI tools I’ve been working on over the past few months to help find this bug. I’d love to say it was all me, but that wouldn’t be honest. The world is changing, and AI is clearly becoming a big part of it.
I think this might be the largest bounty so far for an AI-assisted finding.
And yes, confession time: I (@ControlZ_1337) used the AI tools I’ve been working on over the past few months to help find this bug. I’d love to say it was all me, but that wouldn’t be honest. The world is changing, and AI is clearly becoming a big part of it.
How did I do on my 2025 New Year’s resolutions?
❌ $1M in revenue -> Failed
Total revenue this year across all platforms + audits: $907K
❌ $1M in a single bounty -> Failed
Biggest single bounty: $250K on Immunefi
✅ Top #30 on @immunefi -> Success
Reached rank #22 just yesterday
✅ Full planche -> Success
Can hold a full planche for ~4 seconds
Some accomplishments that weren’t on my original list:
✅ Top #10 on @HackenProof
At the start of the year I’d never even tried HackenProof, but after @WhiteHatMage went on a journey to other realms, I decided to give it a shot. Had a lot of fun and reached #7 all-time.
✅ Snowboarded for 4 months
Took a much-needed break at the start of 2025 to snowboard. Best trip of my life.
✅ Had fun
Beat Silksong, E33, and generally learned to slow down a bit. This year taught me that taking breaks and enjoying life actually matters.
So while I technically failed most of my 2025 resolutions, it was still a great year overall. Here’s hoping 2026 will be just as good -
and that I’ll do a better job sticking to my resolutions this time 😄
Ok, here are the statistics for confirmed and paid findings from the past ~2 months, assisted by the AI tools I’ve been working on:
@immunefi :
2 Criticals
1 High
1 Low (marked as Critical but should be downgraded due to default configuration restraints)
@HackenProof :
1 High
@Hacker0x01:
1 High
Private Bug Bounties:
2 Critical
1 Low
Total payouts are expected to be roughly ~$400K. Payouts tend to move slowly, so more of the results should become public over time.
Assume you find a High/Critical vuln in a library forked by many projects. The bug exists in their code right now, and can be exploited against them.
Who should pay the bounty?
I think it’s fair to say me and @Schnilch share the first place, only $800 difference, now that’s a close one!
Great job my friend! And thanks to @HackenProof and @Somnia_Network
So apparently I won the @Somnia_Network contest on @HackenProof - which honestly came as a surprise 😅
I joined only in the last 10 days of a month-and-a-half-long contest, so I thought I didn't have enough time to cover everything (huge codebase) while others had a head start. When the contest ended, I was kinda mad at myself for joining so late and not finishing my TODO list.
But I gave it everything I had in those 10 days - and apparently, that was enough to win 😁
I'm really glad I did, but it's still not enough - next time, I'll make sure to give myself enough time to finish my TODO list 😅
Stablecoins are now at $200b, Wall Street is ready, and trillions are waiting to come onchain, but they’re SCARED.
This is why the Immunefi Foundation (@immunefiFdn) just launched today.
Visit the Foundation site below to watch the upcoming livestream announcement that will fundamentally change Web3.
📅 Date: Sept 30
🌴 Location: Immunefi Alpha Night, Token2049, or online
Ok, just wrapped up @expedition33 by @SandfallGames (yes, including Simon), and here’s where I’m at:
1. Easily the best game I’ve played in a while - my heart is broken.
2. Esquie is my spirit animal.
3. Y’all had your chance to find bugs. Now that I’m back, it’s over and I’m about to cook.
I’m feeling Wheee