@nickemmons@X Hi Nick. We found 2 critical vulnerabilities within @AlloraNetwork and disclosed through the github's security advisory. However your team hasn't been active nor have they responded to the issue for a while now. Kindly look into this.
✅ [New bug bounty] Earn up to $50,000 with @hyperbridge
You will be rewarded based on these tiers:
Critical: $30,000 - $50,000
High: $5,000 - $15,000
Medium: $2,000 - $5,000
Low: $200 - $1,000
Start the #bugbounty hunt right now!
Every bug found in April is an exploit that never happened. Our whitehats earned $1,523,988 for exactly that.
Shoutout to everyone who put in the work.
Next payout could have your name on it.
Currently investigating this exploit. Our initial diagnosis is the attacker constructed a sophisticated malicious proof to fool our merkle tree verifier.
Damage is so far limited to just the DOT token. Other applications unaffected.
Bridge has been paused pending the upgrade.
I Saved Injective's $500M. They Pay Me $50K.
I like hunting bugs on @immunefi . I'm decent at it.
- #1 — Attackathon | Stacks
- #2 — Attackathon | Stacks II
- #1 — Attackathon | XRPL Lending Protocol
- 1 Critical and 1 High from bug bounties (not counting this one)
Life was good. Then I found a Critical vulnerability in @injective .
This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk.
I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity.
Then — silence. For 3 months. No follow up. No technical discussion. Nothing.
A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either.
I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten.
I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve.
Full Technical Report: https://t.co/lki2tL9bxw
Sad! I got drained of all my Monad allocation. I don't know how this happened, but I'm very sure that my primary key wasn't compromised, as the attacker didn't steal any other assets, though they are very small compared to my Monad. I don't really know how this happened @monad . https://t.co/t7784b1ICL