Live data from Hacker News

Sei pays out $2M bug bounty

usmannkhan.com

11–20 of 133 posts

Re: Sei pays out $2M bug bounty

#12
post #9

Did they get paid 2M in USD, or did they get paid 2M in magic-bean tokens, where is so little market depth that selling 30k of it would tank the market, so they will have to bleed it out slowly and hope the price doesn't tank before they exit

[I was wrong, see below]

Re: Sei pays out $2M bug bounty

#13
post #9

Did they get paid 2M in USD, or did they get paid 2M in magic-bean tokens, where is so little market depth that selling 30k of it would tank the market, so they will have to bleed it out slowly and hope the price doesn't tank before they exit

Magic-bean tokens. I think most on that bug-bounty site are done like that.

Re: Sei pays out $2M bug bounty

#14
post #8

I worked nearly 10 years in tech and this is all gobbledygook to me. That's scary.

On the blockchain, accounts have a certain amount of currency. You can issue a command to transfer currency from your account to somebody else's, as that is a primary use case of a cryptocurrency. There was a code path where you could send someone negative amounts of the currency and it would happily pay them a negative amount of currency and charge you a negative amount of currency, thus transferring their account b…

> There was a code path where you could send someone negative amounts of the currency and it would happily pay them a negative amount of currency and charge you a negative amount of currency, thus transferring their account balance to your against their will.

This is a bug I remember from the Apple II game "Taipan" (in which you play an 1800s opium-and-silk trader in East Asia). You could borrow negative amounts of money from a lender who charges extremely high interest. As a result, the lender would quickly end up owing you tremendous sums, without your having to do anything else. Wikipedia mentions this:

> Note: A bug in the original game allows the player to overpay the moneylender, acquiring "negative debt". This "negative debt" will accumulate interest very quickly, and will count towards the player's net worth. As the game's vocabulary of number words ends at "trillion", this can cause the game to display garbage instead of the player's correct net worth. This has been fixed in the online "for browsers" version of the game.

Re: Sei pays out $2M bug bounty

#15
post #9

Did they get paid 2M in USD, or did they get paid 2M in magic-bean tokens, where is so little market depth that selling 30k of it would tank the market, so they will have to bleed it out slowly and hope the price doesn't tank before they exit

[I was wrong, see below]

This one was actually USDC! Regulated, unmagic, dollar-backed beans.

Re: Sei pays out $2M bug bounty

#17

I worked nearly 10 years in tech and this is all gobbledygook to me. That's scary.

Not scary at all! The nice thing about blockchain stuff is that you can safely ignore it and it will have absolutely zero impact on your life now or at any point in the future.

Re: Sei pays out $2M bug bounty

#18
post #11

Cool writeup! This has got to be one of the biggest security bounties ever paid out, right?

It's up there but not singularly so. Twice there have been $10M! You can see the leaderboard where the majority of crypto bounties are represented here (https://immunefi.com/leaderboard/) but you have to search around for the actual reports.

Re: Sei pays out $2M bug bounty

#19
post #10

For whom it seems surprising, that's actually rather small, considering hacks can end up in an irreversible $100M+ transfer to the malicious party. You can check Immunefi's Bounty-Board for reference, currently paying up to $15M per find. Another good source is rekt.news, creating post-mortems about all the DEFI-hacks and an own leaderboard, $624M for #1.

Sure, but you get to enjoy your bounty payout. Having $2M legally vs. having to become a money launderer?

Re: Sei pays out $2M bug bounty

#20
post #2

Honest question: Was the $2M figure advertised in advance? Where does one go about discovering bug bounties of this size? It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.

Yes, that is actually worth it. This seems comparable to what a third party might pay. I have always wondered why the payouts are capped at the trillion dollar corps at such low figures. It appears like $75k max and MS and $100k max at Apple. Meanwhile shady 3rd party groups will pay you 10x that, won't they?

Cryptocurrency bug bounty programs perhaps have an advantage in that the risks of classes of bugs are often concrete, financially quantifiable, immediate, and catastrophic. A bad RCE in a mainstream OS could do untold damage to users, reputational damage to the company, and so on, but even if severe, those risks have to be estimated. But in this case, for example, it seems like the $2m bounty was for a bug that, if exploited, would have made $1b in market cap disappear. I expect it's just much simpler to convince a skeptic businessperson when the risks are so clear.
Post reply on HN