Live data from Hacker News

Sei pays out $2M bug bounty

usmannkhan.com

41–50 of 133 posts

Re: Sei pays out $2M bug bounty

#41
post #38
post #19

Earlier quoted context omitted.

Sure, but you get to enjoy your bounty payout. Having $2M legally vs. having to become a money launderer?

Taking advantage of bad contracts can be legal depending on various nuanced circumstances. If the potential payout is lucrative, then it makes sense to consult with legal counsel first. I am not making a judgement about this specific case.

tell that to avraham eisenberg https://www.axios.com/2024/04/18/avi-eisenberg-convicted-cry...

Re: Sei pays out $2M bug bounty

#42
post #29

See. These crypto bounties pay as much or even more than big tech bug bounties. This bounty prize is the equivalent of finding a Chrome zero day bug or an iPhone zero day RCE jailbreak. There are lots of >$1M bug bounties in crypto. The question is, would you rather target Chrome/Safari or iPhones and find and chain-up 5 - 10 zero days for $1M+ or target crypto projects instead for $2M per project? You're really miss…

I’m not a crypto hater (I used to work security at coinbase) but I think that while a chrome or iPhone zeroday might be worth less in bug bounty it’s worth more for a security engineers career long term.

Having the iPhone bug and the accompanying conference talk and blog post will allow you get hired by nearly any good security or tech company. No one cares about blockchain bugs except other crypto companies. When I and a bunch of other coinbase engineers were looking for jobs we were looked down at for even working in crypto. And weren’t even in the blockchain team! Just regular engineers.

I myself have dedicated a couple of months to testing gnosis and curve that each have $2 million bounties but turned up short. Last year I switched to a ML based fuzzing research and was able to speak at defcon and got crazy offers after publication.

Re: Sei pays out $2M bug bounty

#43
post #9

Did they get paid 2M in USD, or did they get paid 2M in magic-bean tokens, where is so little market depth that selling 30k of it would tank the market, so they will have to bleed it out slowly and hope the price doesn't tank before they exit

Magic-bean tokens. I think most on that bug-bounty site are done like that.

Regarding the downvotes, the company says the below in their Immunefi page. It seems (as the OP responded) that they paid out differently in this case. I am unsure why that happened or if the page is outdated.

"Payouts are handled by the Sei Foundation team directly and are denominated in USD. However, payments are done in SEI." [1]

The other part of my comment is correct according to the various Immunefi listings. Again, I could be incorrect if they do something differently behind closed doors.

[1] https://immunefi.com/bug-bounty/sei/

Re: Sei pays out $2M bug bounty

#44
post #38

Earlier quoted context omitted.

Taking advantage of bad contracts can be legal depending on various nuanced circumstances. If the potential payout is lucrative, then it makes sense to consult with legal counsel first. I am not making a judgement about this specific case.

tell that to avraham eisenberg https://www.axios.com/2024/04/18/avi-eisenberg-convicted-cry...

That person committed fraud. My point wasn't even about cryptocurrency or DeFi.

Here's a simplified hypothetical example to help you understand the legal nuance: I offer all of my money to the first person that can solve 5x5, and I errantly believe that it's a difficult problem to solve.

Re: Sei pays out $2M bug bounty

#45
post #42
post #29

See. These crypto bounties pay as much or even more than big tech bug bounties. This bounty prize is the equivalent of finding a Chrome zero day bug or an iPhone zero day RCE jailbreak. There are lots of >$1M bug bounties in crypto. The question is, would you rather target Chrome/Safari or iPhones and find and chain-up 5 - 10 zero days for $1M+ or target crypto projects instead for $2M per project? You're really miss…

I’m not a crypto hater (I used to work security at coinbase) but I think that while a chrome or iPhone zeroday might be worth less in bug bounty it’s worth more for a security engineers career long term. Having the iPhone bug and the accompanying conference talk and blog post will allow you get hired by nearly any good security or tech company. No one cares about blockchain bugs except other crypto companies. When I…

Can you share more about ML based fuzzing? I do pretty basic fuzzing and that's been pretty useful at work for testing, and am keen to learn about better more modern approaches than mine!

Re: Sei pays out $2M bug bounty

#46

Earlier quoted context omitted.

Magic-bean tokens. I think most on that bug-bounty site are done like that.

Regarding the downvotes, the company says the below in their Immunefi page. It seems (as the OP responded) that they paid out differently in this case. I am unsure why that happened or if the page is outdated. "Payouts are handled by the Sei Foundation team directly and are denominated in USD. However, payments are done in SEI." [1] The other part of my comment is correct according to the various Immunefi listings. A…

Daily volume is > $100m, there's liquidity and the payout is pegged to USD so trade quick and run.

But OP was paid in USD anyway.

Re: Sei pays out $2M bug bounty

#47
post #46

Earlier quoted context omitted.

Regarding the downvotes, the company says the below in their Immunefi page. It seems (as the OP responded) that they paid out differently in this case. I am unsure why that happened or if the page is outdated. "Payouts are handled by the Sei Foundation team directly and are denominated in USD. However, payments are done in SEI." [1] The other part of my comment is correct according to the various Immunefi listings. A…

Daily volume is > $100m, there's liquidity and the payout is pegged to USD so trade quick and run. But OP was paid in USD anyway.

Sure, but we are talking about a token that (almost) had a bug that allowed people to steal from cold-wallets. No amount of fancy words makes that concern go away.

Re: Sei pays out $2M bug bounty

#48
post #22
post #19

Earlier quoted context omitted.

Sure, but you get to enjoy your bounty payout. Having $2M legally vs. having to become a money launderer?

Right, yeah. I estimated that a savvy attacker might have been able to get out with 50 or even 100m from this, but they would also go to jail. So...

What sort of crime are you envisioning that exploiting this would fall under? It's not always fraud to satisfy a poorly written contract, although that is commonly the case.

Re: Sei pays out $2M bug bounty

#49
post #45
post #42

Earlier quoted context omitted.

I’m not a crypto hater (I used to work security at coinbase) but I think that while a chrome or iPhone zeroday might be worth less in bug bounty it’s worth more for a security engineers career long term. Having the iPhone bug and the accompanying conference talk and blog post will allow you get hired by nearly any good security or tech company. No one cares about blockchain bugs except other crypto companies. When I…

Can you share more about ML based fuzzing? I do pretty basic fuzzing and that's been pretty useful at work for testing, and am keen to learn about better more modern approaches than mine!

Fuzzing is a massive field now. I don't know what you are doing specifically but this is a collection of good related papers: https://github.com/wcventure/FuzzingPaper.

I would find what is most like your problem domain and dig in :).

Re: Sei pays out $2M bug bounty

#50
post #6

The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through…

> And there just aren't enough security people yet that market forces have commoditized bounty finding.

I have the opposite conclusion there, crypto organization sponsored bug bounties are far more accurately valued than Web 2.0’s arbitrary adversarial bug bounties, and have attracted tons of developer talent to crypto bug bounties and the crypto ecosystem as a whole

Post reply on HN