Live data from Hacker News

Sei pays out $2M bug bounty

usmannkhan.com

121–130 of 133 posts

Re: Sei pays out $2M bug bounty

#121
post #16

Hey OP here, thanks for posting. Happy to answer any questions.

1. Roughly how many hours did you spend on the two bug reports (from recon to publication) that you have posted on your blog? 2. How extensive is your background in networking, blockchain programming and pen testing? 3. How many other bounties did you commit recon time to before the two successful disclosures?

1. This is really hard to enumerate. I basically am always doing recon and don't do it 1 target at a time either. I'd been looking at Sei's V2 upgrade code on and off for months, and made my report when they merged the v2 branch to master (this action put the code in-scope for a bounty). I'd found a handful of other critical bugs on the way but they were fixed eventually either in the course of normal development or audits. I definitely spent upwards of 40 very focused hrs in total investigating this codebase along with its dependencies Cosmos/Tendermint. Probably much more time less focused. Cosmos&TM are quite big. But those dependencies are used in many other projects too, so it can't be purely accounted towards time on Sei.

2. I am a very experienced security researcher/pentester/whatever we want to call it, specifically in the blockchain niche. I'm OK at the other stuff (reversing, cryptography, web, mobile, etc). Networking probably alright? I'm comfortable saying I have a good mind for security and a wide knowledge of the basics in many fields, then a very deep knowledge of a select few areas.

3. Idk, a lot! Upwards of 20 for sure.

Re: Sei pays out $2M bug bounty

#122
post #66

Earlier quoted context omitted.

Yes, that is actually worth it. This seems comparable to what a third party might pay. I have always wondered why the payouts are capped at the trillion dollar corps at such low figures. It appears like $75k max and MS and $100k max at Apple. Meanwhile shady 3rd party groups will pay you 10x that, won't they?

I wonder if very large bounties create incentives to create bugs...

There could also be a reverse bounty paid as a salary bonus to the devs if there is no security bug found in N months. A "code quality bonus", if you will. Though only to encourage quality control.

Intentional bug creation should probably result in firing, unless it was done under duress.

Re: Sei pays out $2M bug bounty

#129
post #94

Earlier quoted context omitted.

"Online TV" that requires payment in crypto, and doesn't take card... without more info, it's pretty safe to assume that service is not provided legally.

It may just be a matter of where they live. I got used to sending money in btc to my grandmother because the countries we live in currently happened to be at war with each other and bank transfers were not an option.

Yes, that's the reason. I am happy that I helped him back then, because he suddenly died just a few months later.

Re: Sei pays out $2M bug bounty

#130

Earlier quoted context omitted.

Not true. My father (71) always was the same, anti-bitcoin etc. Until he needed to pay for online TV (do nt ask, but it was impossible to pay w card)

"Online TV" that requires payment in crypto, and doesn't take card... without more info, it's pretty safe to assume that service is not provided legally.

There were no legal option due to political circumstances. I am happy I helped him back then, cause he suddently died several months later.
Post reply on HN