Live data from Hacker News

Sei pays out $2M bug bounty

usmannkhan.com

21–30 of 133 posts

Re: Sei pays out $2M bug bounty

#21
post #2

Honest question: Was the $2M figure advertised in advance? Where does one go about discovering bug bounties of this size? It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.

It was advertised in advance, but the real gamble is on if they'll pay. If you go to my other blogpost linked in OP, you can see a case where I was owed 500k and paid 60k.

You're right though that it's a lot of risk. It's not something that most of the leaderboard works full time on, though some of us do. The immunefi homepage has a list of all the bounties on offer.

Re: Sei pays out $2M bug bounty

#22
post #19
post #10

For whom it seems surprising, that's actually rather small, considering hacks can end up in an irreversible $100M+ transfer to the malicious party. You can check Immunefi's Bounty-Board for reference, currently paying up to $15M per find. Another good source is rekt.news, creating post-mortems about all the DEFI-hacks and an own leaderboard, $624M for #1.

Sure, but you get to enjoy your bounty payout. Having $2M legally vs. having to become a money launderer?

Right, yeah. I estimated that a savvy attacker might have been able to get out with 50 or even 100m from this, but they would also go to jail. So...

Re: Sei pays out $2M bug bounty

#24
post #16

Hey OP here, thanks for posting. Happy to answer any questions.

1. For the 2nd issue you found, was the amount you redeemed after being paid really up to $2m USD?

2. From your other comments elsewhere in this thread, it sounds like you are a full-time bounty hunter, correct?

Re: Sei pays out $2M bug bounty

#25
post #8

I worked nearly 10 years in tech and this is all gobbledygook to me. That's scary.

On the blockchain, accounts have a certain amount of currency. You can issue a command to transfer currency from your account to somebody else's, as that is a primary use case of a cryptocurrency. There was a code path where you could send someone negative amounts of the currency and it would happily pay them a negative amount of currency and charge you a negative amount of currency, thus transferring their account b…

it really shouldnt be referred to as currency as a whole anymore.

well i guess anything can be a currency but its too misleading even though that was by design.

if its designed to be a stock then should be called so. poker chips? in game currency? money laundering token? reward points? purchase receipt? jpeg? just think it would help

Re: Sei pays out $2M bug bounty

#26
post #17

I worked nearly 10 years in tech and this is all gobbledygook to me. That's scary.

Not scary at all! The nice thing about blockchain stuff is that you can safely ignore it and it will have absolutely zero impact on your life now or at any point in the future.

Unless you're a security researcher, in which case by ignoring blockchain you may be missing out on some juicy bounties.

Re: Sei pays out $2M bug bounty

#28
post #24
post #16

Hey OP here, thanks for posting. Happy to answer any questions.

1. For the 2nd issue you found, was the amount you redeemed after being paid really up to $2m USD? 2. From your other comments elsewhere in this thread, it sounds like you are a full-time bounty hunter, correct?

1. Yes, they sent me 2,000,000 USDC.

2. Well, I'm currently not employed full time and I do spend a lot of time bounty hunting. But I mix it in with other things as well, like competitive security reviews on https://sherlock.xyz or https://cantina.xyz and private contracted security reviews.

Re: Sei pays out $2M bug bounty

#29
See. These crypto bounties pay as much or even more than big tech bug bounties.

This bounty prize is the equivalent of finding a Chrome zero day bug or an iPhone zero day RCE jailbreak. There are lots of >$1M bug bounties in crypto.

The question is, would you rather target Chrome/Safari or iPhones and find and chain-up 5 - 10 zero days for $1M+ or target crypto projects instead for $2M per project?

You're really missing out.

Re: Sei pays out $2M bug bounty

#30
post #20

Earlier quoted context omitted.

Yes, that is actually worth it. This seems comparable to what a third party might pay. I have always wondered why the payouts are capped at the trillion dollar corps at such low figures. It appears like $75k max and MS and $100k max at Apple. Meanwhile shady 3rd party groups will pay you 10x that, won't they?

Cryptocurrency bug bounty programs perhaps have an advantage in that the risks of classes of bugs are often concrete, financially quantifiable, immediate, and catastrophic. A bad RCE in a mainstream OS could do untold damage to users, reputational damage to the company, and so on, but even if severe, those risks have to be estimated. But in this case, for example, it seems like the $2m bounty was for a bug that, if e…

That's a very solid point, as sad as it is.

I suppose the argument for OS makers to raise their rates might be that they are paying 10x below market rates, and the rates were set by the actual freaking market that exists.

If I was a congressional aide, I would definitely write something up about this when my boss was going to drag a Microsoft exec across the coals in public. I would imagine that billions in gov contracts are at risk for MS right now due to lax security. A $2M bug bounty could have prevented that.

Post reply on HN