@HackenProof Classic CEI violation leading to Reentrancy...
_safeMint triggers an external call before updating usedPass[msg.sender] = true;. An attacker can re-enter and bypass the single-use check completely.....
My latest Web3 audit:
๐ฏ 5 Dups (radar works, speed doesn't).
โ 2 Rejected (I see a flaw, devs see "defensive design").
๐ฐ Payout: $0 & a headache.
Bug bounty is a masterclass in humility. We go again! ๐ก๏ธ
#BugBounty#Web3Security
Nothing tests your sanity like 5 Duplicates on a massively complex project. ๐คฏ
I almost gave up. But when the easy bugs are gone, you look at the math. Found a fatal time-logic flaw and pulled 2 NEW bugs ๐ต๏ธโโ๏ธโก
Keep digging.
#SmartContracts#BugBounty
Let's wait for the result.
@MitchellAmador Huge milestone! Losing a report to an empty duplicate is frustrating. My high-severity report was closed & triggered an SNR autoban, despite a functional Mainnet-forked PoC for exact economic extraction. Eager for manual review to test this new era!
Nothing tests your sanity like 5 Duplicates on a massively complex project. ๐คฏ
I almost gave up. But when the easy bugs are gone, you look at the math. Found a fatal time-logic flaw and pulled 2 NEW bugs ๐ต๏ธโโ๏ธโก
Keep digging.
#SmartContracts#BugBounty
Let's wait for the result.
Echo Protocol was hacked for $76M, but the attacker only cashed out $820K. Why? Zero exit liquidity. You can mint infinite unbacked tokens, but you can't drain what isn't there.
The real tragedy? No Timelocks or Mint Caps. Don't build Web3 on Web2 security. ๐ก๏ธ๐ป #DeFi
@pawel_research Not dumb, just no exit liquidity. You can mint $76M from thin air, but you only drain the actual TVL in pools. The real tragedy? Missing basic on-chain guards: no Timelocks, no Mint Caps. A complete architecture failure
@arshadkazmi42@Hacker0x01 Platforms are drowning in AI spam, while researchers building functional Mainnet-fork PoCs pay the priceโoften facing unfair SNR autobans. Bounties must reward actual proof, not who clicked submit first. Great tip on tracking NA duplicates!
@VagnerAndrei98@immunefi 100% agreed. The disconnect between protocol specs and platform triage is a real issue. I just got hit with a strict SNR autoban immediately after a report closure, despite providing a fully functional Mainnet-forked PoC demonstrating exact economic extraction..good work
A reminder for DeFi developers: Relying on the frontend for slippage protection is NOT enough. If your smart contract lacks an explicit min_lamports_out guard during liquidity withdrawals, it leaves users completely exposed to MEV sandwich attacks on-chain.
@chameleon_jeff Thatโs exactly why Hyperliquid stands out it delivers what blockchain truly promised: verifiable transparency, not blind trust.
CEXs still sell "trust" as a feature instead of proving it onchain.
#DeFi#OnchainTransparency