$300,000 from a single bounty.
Also yes, it was Move related.
Move helps, but it doesn’t magically make protocols safe.
The real bugs still live in assumptions, invariants, and integrations.
Proud of what VulSight has been doing too. We’ve cleared over $500k in bounties in the last 2 months.
If you’re a founder and you want an audit team that consistently finds criticals, we’re a DM away.
Big congratulations to @VulsightSec for scoring their very first paid report on Immunefi.
And it's huge, huge payout.
Well done!
You can pledge behind them here to earn IMU when they find bugs:
https://t.co/D5bSZTEWUb
@GalloDaSballo Quite interesting stuff. I am curious on how likely do you think there are some extreme edge case critical vulnerabilities in smart contracts that neither manual auditing or LLM based auditing can find?
🌴 The @VulsightSec team has landed in Miami for @consensus2026!
May 5–7 | Miami Beach Convention Center
If you're building in Web3, let's talk:
🔐 Smart Contract Audits
🛡️ Protocol/Infra Security Audits
🤝 Security Partnerships
DM us to grab coffee or meet up on the beach. ☀️
#consensus2026 #Miami #web3 #Security
Wild thought:
When you train for lucid dreaming, you learn to check things like your hands or the time on a clock because dreams mess those up.
AI image/video models make very similar mistakes (extra fingers, broken text, inconsistent details).
Feels like AI is mimicking human consciousness on a level.
After doing extensive Bug Bounty and interacting with dozens of protocols. In the Infra Space among the major blockchains, I believe only these protocols (currently) actually care about security:
1. Solana
2. Ethereum
3. Monad
4. Sei
Most of the other blockchains don't care about either security or respecting whitehats.
Suppose we have a critical drain vulnerability that two whitehats find at the same time.
One reports it to the bbp.
Meanwhile when the report is being reviewed, the other whitehat executes a whitehat attack to secure the funds.
Who gets the bounty 👀