I don’t understand their approach specifically, why the internal teams of some programs seem unable to properly assess certain vulnerabilities and their actual security impact.
Furthermore, the triager who validated my reports on @hackenproof seemed to align with the program’s internal assessment rather than independently evaluating the vulnerability based on its actual technical impact.
To @hackenproof: this is simply feedback from me. I hope greater emphasis can be placed on ensuring objective and technically sound assessments, particularly for mobile wallet vulnerabilities.
I have faith that the platform will continue to improve the quality and consistency of its vulnerability assessment process.
I truly appreciate the support and triage @HackenProof teams for their engagement on this case. Even though @coin98_wallet continues to regard this as a non issue.
- open in-app browser
poc:
https://t.co/Fr0IgN8Upx
silent connect - Call getkeypair - ATO Solana
#bugbounty
🚨 SCAM ALERT: Fake Bug Bounty Program!!! Beware of Atomic Mail’s bug bounty program🚨
Refuse to pay when a Critical Vulnerability is reported.They claimed it was a documentation error and expect critical security research for free.
I invested time and waited quite a while to report a critical-severity vulnerability to Atomic Mail, acting in accordance with Section (9.2 Bug Bounty Program) of their official Security Whitepaper.
https://t.co/jS03tYPDII
After the report was submitted, they claimed the Whitepaper was "erroneous" and refused to provide a reward (bounty), treating the critical vulnerability instead as a standard, unpaid bug report.
Dear Bug bounty hunters:
Do not waste your time hunting for vulnerability for them until they rectify that misleading policy.
Massive red flag for a privacy-first platform. 🚩🚩Check the receipts below. 👇 #infosec #bugbounty #cybersecurity #scamalert #bugbountytips @atomic_mail
@milmi28nm@EFFERCETAMOL@bayualphaone Hahaha, you look pretty panicked, my friend. Now you're calling in more of your friends. Looks like the monkeys are showing up one after another. Alright, I'm gonna run away nowwww.
@milmi28nm@EFFERCETAMOL@bayualphaone It's funny watching a fool laugh at his own stupidity. Haha. I thought you were smart, but it turns out you're just clueless. Let's leave it at that. You don't even know something as basic as RAM. Haha. You're only exposing your own ignorance, my friend. Hahaha.
@milmi28nm@EFFERCETAMOL@bayualphaone The more you reply to this message, the more you expose your own stupidity. Keep laughing at your own ignorance. Haha.
Or you could just email your friend who owns that PC: [[email protected]](mailto:[email protected]). The HWID already makes it crystal clear.