Live data from Hacker News

Sei pays out $2M bug bounty

usmannkhan.com

71–80 of 133 posts

Re: Sei pays out $2M bug bounty

#71
post #57

Earlier quoted context omitted.

Everything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.

You could say that about anything that is critical.

No, you can't.

Re: Sei pays out $2M bug bounty

#72
post #6

The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through…

The problem is that at certain level of TVL you cannot scale your security measures [1]. So, no silver bullet to security in crypto.

[1] https://bittrap.com/resources/defis-growing-pains:-as-tvl-ra...

Re: Sei pays out $2M bug bounty

#73
post #42
post #29

See. These crypto bounties pay as much or even more than big tech bug bounties. This bounty prize is the equivalent of finding a Chrome zero day bug or an iPhone zero day RCE jailbreak. There are lots of >$1M bug bounties in crypto. The question is, would you rather target Chrome/Safari or iPhones and find and chain-up 5 - 10 zero days for $1M+ or target crypto projects instead for $2M per project? You're really miss…

I’m not a crypto hater (I used to work security at coinbase) but I think that while a chrome or iPhone zeroday might be worth less in bug bounty it’s worth more for a security engineers career long term. Having the iPhone bug and the accompanying conference talk and blog post will allow you get hired by nearly any good security or tech company. No one cares about blockchain bugs except other crypto companies. When I…

Serious Chrome and iPhone bug chains can be worth this much on the market, but the amount of engineering effort that goes into supporting that kind of pricing (across all the buyers, aggregated) is extreme. The subthread that unfolds from this comment is about fuzzing, but finding a vulnerability is a small part of actually selling it on the market.

Vendor bounties for these kinds of vulnerabilities are going to tend to be sharply lower than this crypto bounty, which was for a directly monetizable vulnerability. But there's a lot going into that vendor bounty price point.

Re: Sei pays out $2M bug bounty

#74
post #59

Earlier quoted context omitted.

> And there just aren't enough security people yet that market forces have commoditized bounty finding. I have the opposite conclusion there, crypto organization sponsored bug bounties are far more accurately valued than Web 2.0’s arbitrary adversarial bug bounties, and have attracted tons of developer talent to crypto bug bounties and the crypto ecosystem as a whole

Crypto bug bounties require specialized low level knowledge. Web 2 pentesting is akin to a qa checklist. Imo op is right that web2 bounties are commoditized.

More commoditized but vastly mispriced, especially consequential ones. but there are many laymen and seasoned programmers that would consider web 2 bug bounties to be very specialized, at the same time cosmos and EVMs have been around for at least 7 years now and many devs have only done that work - which is actually a problem in recruiting as many of these specialized crypto devs are quite junior

when Apple is going to fight tooth and nail to not pay you $10,000 while the black hat government contractor will pay $1,000,000 for the same exploit, the market is saying what the real price is and its at parity with what Web 3 is paying

Re: Sei pays out $2M bug bounty

#75
post #16

Hey OP here, thanks for posting. Happy to answer any questions.

1. Roughly how many hours did you spend on the two bug reports (from recon to publication) that you have posted on your blog?

2. How extensive is your background in networking, blockchain programming and pen testing?

3. How many other bounties did you commit recon time to before the two successful disclosures?

Re: Sei pays out $2M bug bounty

#76
post #68

Earlier quoted context omitted.

Yeah, I think stealing that kind of money pretty much guarantees that you'll need to be paranoid for the rest of your life. I wouldn't take that for any amount.

People keep saying that, but not even one case is documented. These chains are created by startups with VC money, they are not going to hire hitmans.

I wouldn't expect there to be documented cases yet. The hypothetical case in question is a hacker taking hundreds of millions of dollars, not being caught initially, but then being caught years later. Crypto as a whole is just 15 years old, and it's only really been hot for under a decade. There have only been a handful of cases with such large dollar amounts, and most occurred in the last 5 years. And I expect most of the people who pull this off will be properly paranoid.

Re: Sei pays out $2M bug bounty

#77
post #6

The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through…

Everything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.

One just happens to be more legal than the other.

Re: Sei pays out $2M bug bounty

#78
post #77

Earlier quoted context omitted.

Everything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.

One just happens to be more legal than the other.

Depends, it's not clear yet that "code is law" or is not.

Re: Sei pays out $2M bug bounty

#80
post #77

Earlier quoted context omitted.

One just happens to be more legal than the other.

Depends, it's not clear yet that "code is law" or is not.

> Depends, it's not clear yet that "code is law" or is not.

Aren't there quite a few cases already where attackers stealing funds from smart contracts were considered just that: thieves. And where their "code is law" defense didn't amuse the judge?

IIRC we recently even saw two sent to jail for manipulating smart contract prices: it's not even clear they used a bug in a smart contract.

I already posted it but Uncle Sam cannot have it both ways: if Uncle Sam asks people making money with cryptocurrencies to pay taxes, Uncle Sam goes after those who steal from the taxpayers. And... Oh boy, does Uncle Sam tax gains.

Post reply on HN