Live data from Hacker News

Sei pays out $2M bug bounty

usmannkhan.com

51–60 of 133 posts

Re: Sei pays out $2M bug bounty

#51
post #48
post #22

Earlier quoted context omitted.

Right, yeah. I estimated that a savvy attacker might have been able to get out with 50 or even 100m from this, but they would also go to jail. So...

What sort of crime are you envisioning that exploiting this would fall under? It's not always fraud to satisfy a poorly written contract, although that is commonly the case.

Everything is wire fraud / securities fraud

Re: Sei pays out $2M bug bounty

#52
post #48
post #22

Earlier quoted context omitted.

Right, yeah. I estimated that a savvy attacker might have been able to get out with 50 or even 100m from this, but they would also go to jail. So...

What sort of crime are you envisioning that exploiting this would fall under? It's not always fraud to satisfy a poorly written contract, although that is commonly the case.

Wire fraud, at minimum. This would constitute direct theft. Very similar cases have been tried and convicted several times now.

Re: Sei pays out $2M bug bounty

#53
post #45

Earlier quoted context omitted.

Can you share more about ML based fuzzing? I do pretty basic fuzzing and that's been pretty useful at work for testing, and am keen to learn about better more modern approaches than mine!

Fuzzing is a massive field now. I don't know what you are doing specifically but this is a collection of good related papers: https://github.com/wcventure/FuzzingPaper . I would find what is most like your problem domain and dig in :).

I've been doing the simplest possible things to URL parameters and POST bodies but even that's been effective! Thanks for the link!

Re: Sei pays out $2M bug bounty

#54

Earlier quoted context omitted.

Magic-bean tokens. I think most on that bug-bounty site are done like that.

Regarding the downvotes, the company says the below in their Immunefi page. It seems (as the OP responded) that they paid out differently in this case. I am unsure why that happened or if the page is outdated. "Payouts are handled by the Sei Foundation team directly and are denominated in USD. However, payments are done in SEI." [1] The other part of my comment is correct according to the various Immunefi listings. A…

Projects are free to change their terms and the page you link has been updated since I submitted my reports. The maximum was lowered to $1M and payment currency changed from USDC to SEI.

Re: Sei pays out $2M bug bounty

#56
post #19

Earlier quoted context omitted.

Sure, but you get to enjoy your bounty payout. Having $2M legally vs. having to become a money launderer?

Not so sure it is that clear cut. A few infamous stories of bug bounties not getting paid for even trivial amounts So it is $2 million x probability payment vs $100 million x probability escape without getting caught. Even with the threat of non-payment, not sure I could ever feel at ease with a multimillion bounty hanging over my head.

I think there is another factor that some people would pay every penny they have to not go to prison for a meaningful length of time.

Re: Sei pays out $2M bug bounty

#57
post #6

The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through…

Everything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.

You could say that about anything that is critical.

Re: Sei pays out $2M bug bounty

#58
post #19

Earlier quoted context omitted.

Sure, but you get to enjoy your bounty payout. Having $2M legally vs. having to become a money launderer?

Not so sure it is that clear cut. A few infamous stories of bug bounties not getting paid for even trivial amounts So it is $2 million x probability payment vs $100 million x probability escape without getting caught. Even with the threat of non-payment, not sure I could ever feel at ease with a multimillion bounty hanging over my head.

Yeah, I think stealing that kind of money pretty much guarantees that you'll need to be paranoid for the rest of your life. I wouldn't take that for any amount.

Re: Sei pays out $2M bug bounty

#59
post #6

The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through…

> And there just aren't enough security people yet that market forces have commoditized bounty finding. I have the opposite conclusion there, crypto organization sponsored bug bounties are far more accurately valued than Web 2.0’s arbitrary adversarial bug bounties, and have attracted tons of developer talent to crypto bug bounties and the crypto ecosystem as a whole

Crypto bug bounties require specialized low level knowledge. Web 2 pentesting is akin to a qa checklist. Imo op is right that web2 bounties are commoditized.

Re: Sei pays out $2M bug bounty

#60
post #16

Hey OP here, thanks for posting. Happy to answer any questions.

Did you have to specify that it was a critical bug or haggle with them? On the immunefi site, their max bounty is set at $1M but you clearly got 2x that.

The project changed to a 1 million dollar bounty after usmannk's report on May 18th..

There's an unofficial project that tracks bounty programs, you can see the change here: https://github.com/infosec-us-team/Immunefi-Bug-Bounty-Progr...

Post reply on HN