Earlier quoted context omitted.
Right, yeah. I estimated that a savvy attacker might have been able to get out with 50 or even 100m from this, but they would also go to jail. So...
What sort of crime are you envisioning that exploiting this would fall under? It's not always fraud to satisfy a poorly written contract, although that is commonly the case.
Sei pays out $2M bug bounty
51–60 of 133 posts
Re: Sei pays out $2M bug bounty
#52Earlier quoted context omitted.
Right, yeah. I estimated that a savvy attacker might have been able to get out with 50 or even 100m from this, but they would also go to jail. So...
What sort of crime are you envisioning that exploiting this would fall under? It's not always fraud to satisfy a poorly written contract, although that is commonly the case.
Re: Sei pays out $2M bug bounty
#53Earlier quoted context omitted.
Can you share more about ML based fuzzing? I do pretty basic fuzzing and that's been pretty useful at work for testing, and am keen to learn about better more modern approaches than mine!
Fuzzing is a massive field now. I don't know what you are doing specifically but this is a collection of good related papers: https://github.com/wcventure/FuzzingPaper . I would find what is most like your problem domain and dig in :).
Re: Sei pays out $2M bug bounty
#54Earlier quoted context omitted.
Magic-bean tokens. I think most on that bug-bounty site are done like that.
Regarding the downvotes, the company says the below in their Immunefi page. It seems (as the OP responded) that they paid out differently in this case. I am unsure why that happened or if the page is outdated. "Payouts are handled by the Sei Foundation team directly and are denominated in USD. However, payments are done in SEI." [1] The other part of my comment is correct according to the various Immunefi listings. A…
Re: Sei pays out $2M bug bounty
#55Hey OP here, thanks for posting. Happy to answer any questions.
Re: Sei pays out $2M bug bounty
#56Earlier quoted context omitted.
Sure, but you get to enjoy your bounty payout. Having $2M legally vs. having to become a money launderer?
Not so sure it is that clear cut. A few infamous stories of bug bounties not getting paid for even trivial amounts So it is $2 million x probability payment vs $100 million x probability escape without getting caught. Even with the threat of non-payment, not sure I could ever feel at ease with a multimillion bounty hanging over my head.
Re: Sei pays out $2M bug bounty
#57The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through…
Everything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.
Re: Sei pays out $2M bug bounty
#58Earlier quoted context omitted.
Sure, but you get to enjoy your bounty payout. Having $2M legally vs. having to become a money launderer?
Not so sure it is that clear cut. A few infamous stories of bug bounties not getting paid for even trivial amounts So it is $2 million x probability payment vs $100 million x probability escape without getting caught. Even with the threat of non-payment, not sure I could ever feel at ease with a multimillion bounty hanging over my head.
Re: Sei pays out $2M bug bounty
#59The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through…
> And there just aren't enough security people yet that market forces have commoditized bounty finding. I have the opposite conclusion there, crypto organization sponsored bug bounties are far more accurately valued than Web 2.0’s arbitrary adversarial bug bounties, and have attracted tons of developer talent to crypto bug bounties and the crypto ecosystem as a whole
Re: Sei pays out $2M bug bounty
#60Hey OP here, thanks for posting. Happy to answer any questions.
Did you have to specify that it was a critical bug or haggle with them? On the immunefi site, their max bounty is set at $1M but you clearly got 2x that.
There's an unofficial project that tracks bounty programs, you can see the change here: https://github.com/infosec-us-team/Immunefi-Bug-Bounty-Progr...