Bug bounty these days is very interesting.
You’ll spend hours finding an issue, building a PoC, and writing detailed reports, making sure you haven’t missed anything that could cause the report to be marked invalid.
Then you also have to think about the possibility of a duplicate.
After all that, you may end up paying $100+ just to submit reports because of submission fees. And even after paying, an AI triager can spend 10–20 minutes on the report and close it with an unnecessary reason without actually understanding the core issue.
Of course, once the report is closed, you can’t properly discuss or demonstrate the issue further. Then you may have to pay another ~$200 for mediation, after which they might escalate the issue if it is eventually confirmed.
And there’s still no guarantee that you’ll be rewarded or even get your money back.
So you can end up paying $300+ just to make sure your issue gets properly validated.
At this point, it feels less like bug bounty and more like gambling.
And here I am, having reported vulnerabilities throughout my career that could have resulted in a total of several billions (yes, with a B, > $2B) being *stolen*, while my total earnings are around $2M.
So what's the lesson the industry is teaching researchers?
That next time we should steal the funds first, then negotiate a "responsible disclosure," return 80–90%, and walk away with 10–20%?
Obviously, no. But it's insane that the incentives can make that rhetorical question even possible.
The bounty world is broken.
Blackhats exploit a protocol and get treated like kings in negotiations. Meanwhile, whitehats disclose the exact same kind of vulnerability privately, prevent any damage from happening, and then spend months arguing with projects that try to downgrade the finding and pay the bare minimum.
I'm fighting several cases like this right now. Millions of dollars protected, vulnerabilities responsibly disclosed, and yet projects still don't want to pay the amounts they themselves advertised.
We should be making responsible disclosure the overwhelmingly obvious choice.
Instead, the current state of Web3 is doing its absolute best to discourage whitehats while creating increasingly attractive incentives for blackhats and "grayhats".
Those incentives are backwards, and eventually the ecosystem pays the price.
🚨Critical security update for LEDGER hardware wallets
A critical vulnerability has been identified in the Ethereum app on Ledger hardware wallets. It could allow a malicious application to alter the details of a transaction during signing, without this being visible on the device screen.
This has been fixed in Ethereum app version 1.22.2. If you use a Ledger device, please update ASAP
While you're in there, it's also good practice to make sure Ledger Live and your device firmware are fully up to date.