Sei pays out $2M bug bounty
111–120 of 133 posts
Re: Sei pays out $2M bug bounty
#112Re: Sei pays out $2M bug bounty
#113Re: Sei pays out $2M bug bounty
#114Pardon my crypto ignorance, but if someone took over the entire SEI platform, wouldn't the value of SEI coin drop to zero?
This is actually why "proof of stake" blockchains are fundamentally flawed. They only make sense if the value of the system is denominated in the currency of the system. It's self referential and prone to negative feedback loops. They are secure because the token is expensive, the token is expensive because it provides a secure platform. Short the token, take a loan out, compromise the security, tank the value, profit. All the mechanisms to prevent that are built into the system, like delaying the validator pool entry, but the only real backstop is a hard fork and spinning up a new copy.
Re: Sei pays out $2M bug bounty
#115Earlier quoted context omitted.
Definitely not true. My last company had the finance department phished and they never recovered the funds. It was about $50k I believe. See also all the people pissed at zelle.
Nothing is true in absolute terms but banks care about loss percentages and that’s much better in the real banking sector. For example, the national bank of Bangladesh was compromised in 2016, believed to be a well-resourced attack by North Korea, and the attacker was able to attempt to transfer $1B. That’s about as severe as it gets, but the U.S. Federal Reserve blocked 85% of the transferred funds and of the remain…
The only way you are recovering the bulk of losses if you don't notice the theft very quickly is if the amount is high enough that a prosecutor is interested and it hasn't all been withdrawn as cash yet.
Re: Sei pays out $2M bug bounty
#116Re: Sei pays out $2M bug bounty
#117Re: Sei pays out $2M bug bounty
#118Re: Sei pays out $2M bug bounty
#119Earlier quoted context omitted.
What sort of crime are you envisioning that exploiting this would fall under? It's not always fraud to satisfy a poorly written contract, although that is commonly the case.
Everything is wire fraud / securities fraud