The biggest bug bounty in history is now live. @Uniswap just raised the standard of building in public πͺ
With $15.5M on the line, it's an unprecedented testament to the rigorous security of v4. Think you can find a critical bug? Give it a shot.
π Bounty link below
**Swell** expands with 28 new bounty targets! **Inverse Finance** adds 1, while **thUSD** adds 2. Dive into the details at https://t.co/aCzZSSWKNz! πππΎ #bugbounty#cybersecurity#Swell#InverseFinance#thUSD
Bounty update! π― dlcBTC appeared then vanished on Rxyz. Inverse Finance adds 4 new targets on Immunefi. SafeTech Labs posts new bounties on Hackenproof. MAIA joins Immunefi! Details at https://t.co/aCzZSSWKNz π #bugbounty#cybersecurity
π Tokemak launches a new bounty on Rxyz π‘ ZetaChain adds 2 new targets on Hackenproof: https://t.co/NgEctBSXC1 and https://t.co/xmd4bDyMr9. Check all updates at https://t.co/aCzZSSWKNz! πβ¨ #BountyBuzz#Tokemak#ZetaChain
Eclipse and Firedancer have launched new bounties on Immunefi! Meanwhile, Metis has removed its bounty from Rxyz. Check out all updates on https://t.co/aCzZSSWKNz! ππ #BugBounties#Eclipse#Firedancer#Metis
Babylon Labs shifts its start date, zkSync Era adds 19 new targets, Ethereum Foundation launches a new bounty, Aevo flexes with 2 more addresses, C3 removes its bounty, and TruFin boosts payouts with 7 new targets. Check updates on https://t.co/aCzZSSWKNz ππ₯
Superfluid exits Hackenproof, while StakeStone, Babylon Labs, and Light Protocol launch new Immunefi bounties! π Check all updates at πhttps://t.co/aCzZSSWKNz
π¨ "Recent Updates" is live! π¨
We aggregate bounties across every platform and showcase those with the latest changes π―
Spot fresh code in bountiesβprime targets for new bugs ππ
Stay up to date on Twitter and in our new Telegram channel π’
https://t.co/rnRf1T0sNo
Also included some performance updates and improved mobile support. Please let us know here or via the feedback form if you encounter any issues (especially on mobile!)
Upgrading to another JSON API for a major platform now.
We are grateful - scraping bounty pages is a pain, and only one of the sites we support had a public API before we started this site.
Not saying the wave is ENTIRELY because of us, but... ππ
This was a major pain point for us as bounty hunters as well - we put together some internal tooling to address it.
Would a basic bulk download of the source for all in-scope contracts be sufficiently useful here?
Simplest version (ready ~now) would just be a .zip organized like:
<contractname>_<address>_<chain>/<*.sol>
Better version would include smart path resolution + file deduplication, etc. for IDE go-to-definition. We have a hacky version of this internally right now, but getting it ready for public use will take a bit.
Best version would just be a compilable foundry project (the dream)
One of the big pains with @immunefi is that you have to open each smart contract in scope.
They should require the project to create an ad hoc and always in sync GitHub repo that mimics the deployed source code; otherwise, it's pretty challenging to manage it.
Signal has:
- No bug bounty as far as I can tell
- No proper public disclosure after critical vulnerabilities are fixed
- Uses weirdly insecure email that governments can likely read for their vuln inbox
- On (at a minimum their desktop app), messages werenβt deleted for years
Morpho's massive new max bounty of $2.5M makes them leapfrog 3 other protocols in the lending space.
Here's the new lending leaderboard ππ΅π
1. @fraxfinance ($10M)
2. @sparkdotfi ($5M)
3. @MorphoLabs ($2.5M) β¬οΈβ¬οΈβ¬οΈ
4. (tied) @aave ($1M) β¬οΈ
4. (tied) @solendprotocol ($1M) β¬οΈ
4. (tied) @SovrynBTC ($1M) β¬οΈ
Find where you stack up at https://t.co/nSOrh319SM