๐Another win for Mjolnir: our autonomous agentic pentesting agent just earned $2,000 bounty from https://t.co/bz4xIxRZds!
The bug: reflected XSS through the /api/vault/meta endpoint on the https://t.co/bz4xIxRZds frontend.
Because wallets are often already connected on the webapp, the impact could have been severe; including potential loss of funds.
Frontend security in crypto is not optional.
Thanks to @yearnfi for a smooth dialogue and quick mitigation! Issue has been fixed, ref: https://t.co/de6hiVAk4C
PDF-based security reports are where findings go to die.
They slow down engineering, bury context, and turn remediation into archaeology.
Odin brings findings, tickets, integrations, and retesting into one workflow.
@_jensec i think adding a deposit would help.
basically if report = valid, deposit refunded. Would reduce LQ noise and AI slop. Some BB platforms have done this already.
@mydoom1337@fomo โHigh Riskโ is doing a lot of cardio here.
Useful hardening notes, sure. But the public framing feels a lot more like pressure posting than responsible disclosure.