@obezumiya "$50,000 USD, for a vulnerability that lets a threat actor read or modify another Vercel tenant's data"
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
@labelblueice not the repo, claude code isn't open source. i go after whatever anthropic ships: the npm packages, the js inside the compiled binary, and the native services in the desktop app.
Almost $10k in bug bounties in 2 months. Still have 11 reports pending — if a few of those turn into $10k+ too, this month’s gonna be insane. Grind continues 🔥