Earlier quoted context omitted.
The company doesn't need a "hack" to not pay money. If they don't have a published bug bounty program then they owe nothing. They also have contact email addresses listed at the bottom of https://a16z.com/connect , which the researcher conveniently missed. They were looking for clout, not responsible disclosure.
> not responsible disclosure. The researcher found an email address, tried it, it bounced, then reached out over Twitter with: > someone from @a16z get in touch, now. its bad. security related. https://x.com/xyz3va/status/1807330215955177937 That doesn't seem irresponsible to me. Sure they could have searched the bottom of a connect page for the office emails to try, but I don't see any significant issue with what th…
It’s obviously not safe to publicly announce the existence of a security vulnerability, and there was no barrier to alerting them privately via the same platform.