Live data from Hacker News

Sei pays out $2M bug bounty

usmannkhan.com

61–70 of 133 posts

Re: Sei pays out $2M bug bounty

#61
post #21
post #2

Honest question: Was the $2M figure advertised in advance? Where does one go about discovering bug bounties of this size? It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.

It was advertised in advance, but the real gamble is on if they'll pay. If you go to my other blogpost linked in OP, you can see a case where I was owed 500k and paid 60k. You're right though that it's a lot of risk. It's not something that most of the leaderboard works full time on, though some of us do. The immunefi homepage has a list of all the bounties on offer.

Couldn’t there be a smart contract for this? I’ve no idea how.

Re: Sei pays out $2M bug bounty

#62
post #34
post #28

Earlier quoted context omitted.

1. Yes, they sent me 2,000,000 USDC. 2. Well, I'm currently not employed full time and I do spend a lot of time bounty hunting. But I mix it in with other things as well, like competitive security reviews on https://sherlock.xyz or https://cantina.xyz and private contracted security reviews.

> .. . and private contracted security reviews. How you find those? Or this type of work finds you based on your activity on competitive security review sites?

Typically networking. I spent some time working at a reputable firm in this space as well.

One way to do this is to show some chops on the competition sites and then move to one of the organized freelance firms like Spearbit or yAudit. In doing all of these things you'll inevitably meet more people, build a specialty, get some reputation, etc.

Re: Sei pays out $2M bug bounty

#63
post #44

Earlier quoted context omitted.

tell that to avraham eisenberg https://www.axios.com/2024/04/18/avi-eisenberg-convicted-cry...

That person committed fraud. My point wasn't even about cryptocurrency or DeFi. Here's a simplified hypothetical example to help you understand the legal nuance: I offer all of my money to the first person that can solve 5x5, and I errantly believe that it's a difficult problem to solve.

Can you provide a more real-world example? I don't understand what point you are making, if it isn't about making money via cryptocurrency. When you say "bad contracts", I assume you are talking about smart contracts. Is that not the case?

Re: Sei pays out $2M bug bounty

#64
post #17

Earlier quoted context omitted.

Not scary at all! The nice thing about blockchain stuff is that you can safely ignore it and it will have absolutely zero impact on your life now or at any point in the future.

Not true. My father (71) always was the same, anti-bitcoin etc. Until he needed to pay for online TV (do nt ask, but it was impossible to pay w card)

"Online TV" that requires payment in crypto, and doesn't take card... without more info, it's pretty safe to assume that service is not provided legally.

Re: Sei pays out $2M bug bounty

#65
post #57

Earlier quoted context omitted.

Everything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.

You could say that about anything that is critical.

Not really - a bug bounty gives you some type of currency.

Jacking a database and trying to sell it on a DLS or dark web is a massive process.

Re: Sei pays out $2M bug bounty

#66
post #2

Honest question: Was the $2M figure advertised in advance? Where does one go about discovering bug bounties of this size? It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.

Yes, that is actually worth it. This seems comparable to what a third party might pay. I have always wondered why the payouts are capped at the trillion dollar corps at such low figures. It appears like $75k max and MS and $100k max at Apple. Meanwhile shady 3rd party groups will pay you 10x that, won't they?

I wonder if very large bounties create incentives to create bugs...

Re: Sei pays out $2M bug bounty

#67
post #66

Earlier quoted context omitted.

Yes, that is actually worth it. This seems comparable to what a third party might pay. I have always wondered why the payouts are capped at the trillion dollar corps at such low figures. It appears like $75k max and MS and $100k max at Apple. Meanwhile shady 3rd party groups will pay you 10x that, won't they?

I wonder if very large bounties create incentives to create bugs...

Oh yeah, the old cobra effect. However, you could only pull it off once. I am sure a postmortem of all related design and commits would be done, correct?

Also, FAANG level salaries are pretty high for anyone involved with that type of code, right?

Re: Sei pays out $2M bug bounty

#68

Earlier quoted context omitted.

Not so sure it is that clear cut. A few infamous stories of bug bounties not getting paid for even trivial amounts So it is $2 million x probability payment vs $100 million x probability escape without getting caught. Even with the threat of non-payment, not sure I could ever feel at ease with a multimillion bounty hanging over my head.

Yeah, I think stealing that kind of money pretty much guarantees that you'll need to be paranoid for the rest of your life. I wouldn't take that for any amount.

People keep saying that, but not even one case is documented.

These chains are created by startups with VC money, they are not going to hire hitmans.

Re: Sei pays out $2M bug bounty

#69
post #48
post #22

Earlier quoted context omitted.

Right, yeah. I estimated that a savvy attacker might have been able to get out with 50 or even 100m from this, but they would also go to jail. So...

What sort of crime are you envisioning that exploiting this would fall under? It's not always fraud to satisfy a poorly written contract, although that is commonly the case.

Despite what many programmers think, code is not law.

Just like a bug in a smart lock does not allow you to enter a house because "you were allowed in".

Re: Sei pays out $2M bug bounty

#70
post #68

Earlier quoted context omitted.

Yeah, I think stealing that kind of money pretty much guarantees that you'll need to be paranoid for the rest of your life. I wouldn't take that for any amount.

People keep saying that, but not even one case is documented. These chains are created by startups with VC money, they are not going to hire hitmans.

North Korea might. Silk Road went under due to attempting to hire one.

The more likely concern is that someone will sell you out to any of the numerous governments who feel you wronged them. Leading to decades of life in prison.

Post reply on HN