Live data from Hacker News

Sei pays out $2M bug bounty

usmannkhan.com

1–10 of 133 posts

Re: Sei pays out $2M bug bounty

#2
Honest question: Was the $2M figure advertised in advance? Where does one go about discovering bug bounties of this size?

It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.

Re: Sei pays out $2M bug bounty

#3
post #2

Honest question: Was the $2M figure advertised in advance? Where does one go about discovering bug bounties of this size? It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.

> Was the $2M figure advertised in advance?

https://blog.sei.io/bug-bounty/

> Where does one go about discovering bug bounties of this size?

- SECURITY.txt for individual projects.

- https://immunefi.com for blockchain in general.

- BugCrowd and HackerOne for wider tech.

I'm an infrastructure engineer though and may not be the best person to answer.

> It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.

https://www.hackerone.com/ethical-hacker/meet-six-hackers-ma...

Note: I work at a foundation for another blockchain. This doesn't affect anything I wrote above, just disclosing potential CoI.

Re: Sei pays out $2M bug bounty

#5
post #2

Honest question: Was the $2M figure advertised in advance? Where does one go about discovering bug bounties of this size? It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.

You can see lots more here:

https://immunefi.com/bug-bounty/

Re: Sei pays out $2M bug bounty

#6
The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding.

Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty!

Almost all crypto bug bounties run through Immunefi. [1] There are lots of > one million dollar bounties. You can see SEI's current bounty page here.[2] The company I work (a different company) for has a one million dollar bounty listed on immunefi.com and median response time of six hours.

[1] https://immunefi.com/bug-bounty/

[2] https://immunefi.com/bug-bounty/sei/

Re: Sei pays out $2M bug bounty

#7
post #2

Honest question: Was the $2M figure advertised in advance? Where does one go about discovering bug bounties of this size? It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.

Yes, that is actually worth it. This seems comparable to what a third party might pay.

I have always wondered why the payouts are capped at the trillion dollar corps at such low figures. It appears like $75k max and MS and $100k max at Apple. Meanwhile shady 3rd party groups will pay you 10x that, won't they?

Re: Sei pays out $2M bug bounty

#8

I worked nearly 10 years in tech and this is all gobbledygook to me. That's scary.

On the blockchain, accounts have a certain amount of currency.

You can issue a command to transfer currency from your account to somebody else's, as that is a primary use case of a cryptocurrency. There was a code path where you could send someone negative amounts of the currency and it would happily pay them a negative amount of currency and charge you a negative amount of currency, thus transferring their account balance to your against their will.

There were several transfer paths and I think not all of them were vulnerable, but only one has to be. There's a bit of indirection that made it somewhat less obvious than my description makes it sound, though it amounts to the same thing in the end.

Re: Sei pays out $2M bug bounty

#9
Did they get paid 2M in USD, or did they get paid 2M in magic-bean tokens, where is so little market depth that selling 30k of it would tank the market, so they will have to bleed it out slowly and hope the price doesn't tank before they exit

Re: Sei pays out $2M bug bounty

#10
For whom it seems surprising, that's actually rather small, considering hacks can end up in an irreversible $100M+ transfer to the malicious party.

You can check Immunefi's Bounty-Board for reference, currently paying up to $15M per find.

Another good source is rekt.news, creating post-mortems about all the DEFI-hacks and an own leaderboard, $624M for #1.

Post reply on HN