I Saved Injective's $500M. They Pay Me $50K.
I like hunting bugs on @immunefi . I'm decent at it.
- #1 — Attackathon | Stacks
- #2 — Attackathon | Stacks II
- #1 — Attackathon | XRPL Lending Protocol
- 1 Critical and 1 High from bug bounties (not counting this one)
Life was good. Then I found a Critical vulnerability in @injective .
This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk.
I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity.
Then — silence. For 3 months. No follow up. No technical discussion. Nothing.
A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either.
I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten.
I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve.
Full Technical Report: https://t.co/lki2tL9bxw
nobody accidentally swaps $50M into a pool with $36K of liquidity lol. fresh wallet, $50.4M from Binance, zero slippage protection, routed through the jankiest Sushiswap path possible. and then an MEV bot just happens to flash borrow $29M from Morpho in the same block and pocket $9.9M?
cmon. 0xngmi called this exact play a year ago - construct a deliberately terrible swap, let a friendly bot extract the value, dirty money comes out the other side as "legit MEV profit."
$154K per AAVE isn't a fat finger. it's a laundering fee
prediction markets vs. the casinos is a very interesting battle to watch
prediction markets are creating a lobbying group to escape gambling regulations
meanwhile legacy casinos are lobbying to get them regulated.
never could've imagined I'd agree with the casinos
The United States did not attend the G20 in South Africa, because the South African Government refuses to acknowledge or address the horrific Human Right Abuses endured by Afrikaners, and other descendants of Dutch, French, and German settlers. To put it more bluntly, they are killing white people, and randomly allowing their farms to be taken from them. Perhaps, worst of all, the soon to be out of business New York Times and the Fake News Media won’t issue a word against this genocide. That’s why all the Liars and Pretenders of the Radical Left Media are going out of business! At the conclusion of the G20, South Africa refused to hand off the G20 Presidency to a Senior Representative from our U.S. Embassy, who attended the Closing Ceremony. Therefore, at my direction, South Africa will NOT be receiving an invitation to the 2026 G20, which will be hosted in the Great City of Miami, Florida next year. South Africa has demonstrated to the World they are not a country worthy of Membership anywhere, and we are going to stop all payments and subsidies to them, effective immediately. Thank you for your attention to this matter!
1/2 In June 2024 a victim was brutally robbed for $4.3M+ of crypto assets at gunpoint via home invasion in the UK after the attackers posed as delivery drivers.
I am proud to share that Faris & his two other accomplices were just sentenced and nearly the full amount of stolen funds was seized by MET Police.
I previously published my investigation identifying Faris and worked closely with the victim to communicate all findings to law enforcement.
Due to minor protection laws certain details about the case remain sealed.
Court: Sheffield Crown Court
Case reference number: 01GD1223024
> be Adobe, 40-year-old PDF jockey
> 2025, stock doing a perfect -33% swan dive
> “We’ll pivot to AI” says exec on 7-figure retention bonus
> can’t ship a model because legal says every pixel needs a 12-page EULA
> Midjourney drops v7, makes our Firefly look like MS Paint with a hangover
> OpenAI drops GPT-Image, Google drops nano-banana, both free
> our response: “Please login with your Adobe ID, install Creative Cloud, update 47 GB, restart, then pay $53.99/month”
> users collectively Alt-F4 into orbit
> watch in horror as ChatGPT/Gemini reads any PDF you give it for free
> enterprise cancels 10k seats overnight
> try to counter with Sora killer video model
> training cluster catches fire after someone uploads a 1998 clipart library
> PR tweet: “We are re-imagining creativity”
> quote-tweet ratio hits 1:9k, gif of dumpster bonfire tops replies
> premiere pro is now just a bloated launcher for 15 different subscription prompts
> 20-something with a phone and CapCut is making better edits
> our flagship feature: “Generative fill but now 3% slower”
> board meeting: “Let’s raise prices again”
> stock drops another 8% during the Zoom call
> our most innovative feature in 5 years is a "subscribe to annual plan" button that clicks itself