Live data from Hacker News

Sei pays out $2M bug bounty

usmannkhan.com

31–40 of 133 posts

Re: Sei pays out $2M bug bounty

#33
post #8

Earlier quoted context omitted.

On the blockchain, accounts have a certain amount of currency. You can issue a command to transfer currency from your account to somebody else's, as that is a primary use case of a cryptocurrency. There was a code path where you could send someone negative amounts of the currency and it would happily pay them a negative amount of currency and charge you a negative amount of currency, thus transferring their account b…

it really shouldnt be referred to as currency as a whole anymore. well i guess anything can be a currency but its too misleading even though that was by design. if its designed to be a stock then should be called so. poker chips? in game currency? money laundering token? reward points? purchase receipt? jpeg? just think it would help

'Token' is the generic term people have settled on. 'Currency' is rare.

A stock would be a 'tokenized equity', in the same way there's 'tokenised real estate', 'tokenised metals', 'tokenised bonds', whatever the real world asset is.

'In-game currency' is indeed used by gaming people, since that was their term from before blockchain.

Re: Sei pays out $2M bug bounty

#34
post #28
post #24

Earlier quoted context omitted.

1. For the 2nd issue you found, was the amount you redeemed after being paid really up to $2m USD? 2. From your other comments elsewhere in this thread, it sounds like you are a full-time bounty hunter, correct?

1. Yes, they sent me 2,000,000 USDC. 2. Well, I'm currently not employed full time and I do spend a lot of time bounty hunting. But I mix it in with other things as well, like competitive security reviews on https://sherlock.xyz or https://cantina.xyz and private contracted security reviews.

> .. . and private contracted security reviews.

How you find those? Or this type of work finds you based on your activity on competitive security review sites?

Re: Sei pays out $2M bug bounty

#35
post #6

The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through…

Everything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.

Re: Sei pays out $2M bug bounty

#36
post #19
post #10

For whom it seems surprising, that's actually rather small, considering hacks can end up in an irreversible $100M+ transfer to the malicious party. You can check Immunefi's Bounty-Board for reference, currently paying up to $15M per find. Another good source is rekt.news, creating post-mortems about all the DEFI-hacks and an own leaderboard, $624M for #1.

Sure, but you get to enjoy your bounty payout. Having $2M legally vs. having to become a money launderer?

Not so sure it is that clear cut. A few infamous stories of bug bounties not getting paid for even trivial amounts

So it is $2 million x probability payment vs $100 million x probability escape without getting caught.

Even with the threat of non-payment, not sure I could ever feel at ease with a multimillion bounty hanging over my head.

Re: Sei pays out $2M bug bounty

#37
post #17

I worked nearly 10 years in tech and this is all gobbledygook to me. That's scary.

Not scary at all! The nice thing about blockchain stuff is that you can safely ignore it and it will have absolutely zero impact on your life now or at any point in the future.

Could suddenly come into the picture like LLMs

Re: Sei pays out $2M bug bounty

#38
post #19
post #10

For whom it seems surprising, that's actually rather small, considering hacks can end up in an irreversible $100M+ transfer to the malicious party. You can check Immunefi's Bounty-Board for reference, currently paying up to $15M per find. Another good source is rekt.news, creating post-mortems about all the DEFI-hacks and an own leaderboard, $624M for #1.

Sure, but you get to enjoy your bounty payout. Having $2M legally vs. having to become a money launderer?

Taking advantage of bad contracts can be legal depending on various nuanced circumstances. If the potential payout is lucrative, then it makes sense to consult with legal counsel first.

I am not making a judgement about this specific case.

Re: Sei pays out $2M bug bounty

#39
post #17

I worked nearly 10 years in tech and this is all gobbledygook to me. That's scary.

Not scary at all! The nice thing about blockchain stuff is that you can safely ignore it and it will have absolutely zero impact on your life now or at any point in the future.

Not true. My father (71) always was the same, anti-bitcoin etc. Until he needed to pay for online TV (do nt ask, but it was impossible to pay w card)
Post reply on HN