Earlier quoted context omitted.
Everything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.
You could say that about anything that is critical.
Sei pays out $2M bug bounty
71–80 of 133 posts
Re: Sei pays out $2M bug bounty
#72The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through…
[1] https://bittrap.com/resources/defis-growing-pains:-as-tvl-ra...
Re: Sei pays out $2M bug bounty
#73See. These crypto bounties pay as much or even more than big tech bug bounties. This bounty prize is the equivalent of finding a Chrome zero day bug or an iPhone zero day RCE jailbreak. There are lots of >$1M bug bounties in crypto. The question is, would you rather target Chrome/Safari or iPhones and find and chain-up 5 - 10 zero days for $1M+ or target crypto projects instead for $2M per project? You're really miss…
I’m not a crypto hater (I used to work security at coinbase) but I think that while a chrome or iPhone zeroday might be worth less in bug bounty it’s worth more for a security engineers career long term. Having the iPhone bug and the accompanying conference talk and blog post will allow you get hired by nearly any good security or tech company. No one cares about blockchain bugs except other crypto companies. When I…
Vendor bounties for these kinds of vulnerabilities are going to tend to be sharply lower than this crypto bounty, which was for a directly monetizable vulnerability. But there's a lot going into that vendor bounty price point.
Re: Sei pays out $2M bug bounty
#74Earlier quoted context omitted.
> And there just aren't enough security people yet that market forces have commoditized bounty finding. I have the opposite conclusion there, crypto organization sponsored bug bounties are far more accurately valued than Web 2.0’s arbitrary adversarial bug bounties, and have attracted tons of developer talent to crypto bug bounties and the crypto ecosystem as a whole
Crypto bug bounties require specialized low level knowledge. Web 2 pentesting is akin to a qa checklist. Imo op is right that web2 bounties are commoditized.
when Apple is going to fight tooth and nail to not pay you $10,000 while the black hat government contractor will pay $1,000,000 for the same exploit, the market is saying what the real price is and its at parity with what Web 3 is paying
Re: Sei pays out $2M bug bounty
#75Hey OP here, thanks for posting. Happy to answer any questions.
2. How extensive is your background in networking, blockchain programming and pen testing?
3. How many other bounties did you commit recon time to before the two successful disclosures?
Re: Sei pays out $2M bug bounty
#76Earlier quoted context omitted.
Yeah, I think stealing that kind of money pretty much guarantees that you'll need to be paranoid for the rest of your life. I wouldn't take that for any amount.
People keep saying that, but not even one case is documented. These chains are created by startups with VC money, they are not going to hire hitmans.
Re: Sei pays out $2M bug bounty
#77The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through…
Everything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.
Re: Sei pays out $2M bug bounty
#78Earlier quoted context omitted.
Everything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.
One just happens to be more legal than the other.
Re: Sei pays out $2M bug bounty
#79Re: Sei pays out $2M bug bounty
#80Earlier quoted context omitted.
One just happens to be more legal than the other.
Depends, it's not clear yet that "code is law" or is not.
Aren't there quite a few cases already where attackers stealing funds from smart contracts were considered just that: thieves. And where their "code is law" defense didn't amuse the judge?
IIRC we recently even saw two sent to jail for manipulating smart contract prices: it's not even clear they used a bug in a smart contract.
I already posted it but Uncle Sam cannot have it both ways: if Uncle Sam asks people making money with cryptocurrencies to pay taxes, Uncle Sam goes after those who steal from the taxpayers. And... Oh boy, does Uncle Sam tax gains.