Earlier quoted context omitted.
One just happens to be more legal than the other.
Depends, it's not clear yet that "code is law" or is not.
Sei pays out $2M bug bounty
81–90 of 133 posts
Re: Sei pays out $2M bug bounty
#82Re: Sei pays out $2M bug bounty
#83The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through…
> And there just aren't enough security people yet that market forces have commoditized bounty finding. I have the opposite conclusion there, crypto organization sponsored bug bounties are far more accurately valued than Web 2.0’s arbitrary adversarial bug bounties, and have attracted tons of developer talent to crypto bug bounties and the crypto ecosystem as a whole
And yet: "Both issues were caught after the code had been audited, merged, and slated for release"
I wonder who did those audits?
Re: Sei pays out $2M bug bounty
#84Earlier quoted context omitted.
Yeah, I think stealing that kind of money pretty much guarantees that you'll need to be paranoid for the rest of your life. I wouldn't take that for any amount.
People keep saying that, but not even one case is documented. These chains are created by startups with VC money, they are not going to hire hitmans.
It's not so much the projects themselves who are a threat, but the thousands (?) of random individuals whose value is stolen.
Re: Sei pays out $2M bug bounty
#85Earlier quoted context omitted.
> And there just aren't enough security people yet that market forces have commoditized bounty finding. I have the opposite conclusion there, crypto organization sponsored bug bounties are far more accurately valued than Web 2.0’s arbitrary adversarial bug bounties, and have attracted tons of developer talent to crypto bug bounties and the crypto ecosystem as a whole
> and have attracted tons of developer talent to crypto And yet: "Both issues were caught after the code had been audited, merged, and slated for release" I wonder who did those audits?
Re: Sei pays out $2M bug bounty
#86Earlier quoted context omitted.
> And there just aren't enough security people yet that market forces have commoditized bounty finding. I have the opposite conclusion there, crypto organization sponsored bug bounties are far more accurately valued than Web 2.0’s arbitrary adversarial bug bounties, and have attracted tons of developer talent to crypto bug bounties and the crypto ecosystem as a whole
> and have attracted tons of developer talent to crypto And yet: "Both issues were caught after the code had been audited, merged, and slated for release" I wonder who did those audits?
Re: Sei pays out $2M bug bounty
#87Earlier quoted context omitted.
Depends, it's not clear yet that "code is law" or is not.
Is there any hint of the legal system accepting that? They certainly don’t accept “locks are law” or “finders keepers.”
The MEV and Sandwicher attackers are legal, increase the transaction costs for everyone, skim profits from everyone and annoy everyone, the exploiter of a MEV bot gets charged and convicted.
I don't have any problem with that, I've analyzed the sentiment of discussion though.
I don't think anyone got charged and said code is law. Its more about who gets charged at all.
Re: Sei pays out $2M bug bounty
#88Re: Sei pays out $2M bug bounty
#89Cool writeup! This has got to be one of the biggest security bounties ever paid out, right?
Re: Sei pays out $2M bug bounty
#90Earlier quoted context omitted.
Depends, it's not clear yet that "code is law" or is not.
> Depends, it's not clear yet that "code is law" or is not. Aren't there quite a few cases already where attackers stealing funds from smart contracts were considered just that: thieves. And where their "code is law" defense didn't amuse the judge? IIRC we recently even saw two sent to jail for manipulating smart contract prices: it's not even clear they used a bug in a smart contract. I already posted it but Uncle S…