Wednesday, June 18, 2025
No Result
View All Result
The Crypto HODL
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Marketcap
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
No Result
View All Result
The Crypto HODL
No Result
View All Result

A silent security scandal or dying profession? DeFi Bug Bounty Wall of Shame has millions in unpaid bounties

August 17, 2023
in Ethereum
Reading Time: 4 mins read
0 0
A A
0
Home Ethereum
Share on FacebookShare on Twitter


The crypto group is grappling with points surrounding bug bounty applications, an important mechanism for locating and addressing system vulnerabilities.

Usmann Khan, a web3 safety auditor, posted on Aug. 17, “Keep in mind that tasks can merely not pay, whitehat,” with a screenshot of a message from Immunefi indicating a challenge had been faraway from its bug bounty downside for failure to pay a minimal of $500,000 in bounties.

Supply: X

In response, safety researcher Marc Weiss shared the ‘Bug Bounty Wall of Disgrace’ (BBWoS), a listing documenting unpaid rewards allegedly owed to white hat hackers in web3. The information from BBWoS seems to sign a major lack of accountability and belief throughout the crypto ecosystem that can not be ignored.

The BBWoS signifies {that a} bug bounty for the Arbitrum exploit of Sep. 2022 had a $2 million reward. But, the white hate was awarded simply $780,000 for figuring out an exploit that uncovered over $680 million.

Additional, BBWoS states the CRV borrowing/lending exploit on Aave from Nov. 2022 led to the lack of $1.5 million, with $40 million in danger, and no bounty was paid to the white hat who recognized the assault path “days earlier than.”

Lastly, in April this yr, simply $500 was paid to a white hat who reportedly recognized a manner for managers to steal as much as $14 million value of “tokens from customers utilizing malicious swap paths” after being informed by dHEDGE that the difficulty was “well-known.”

The checklist was created by whitehat hackers “uninterested in spending sleepless nights discovering bugs in protocols solely to have a payout of $500 when the financial harm totals within the hundreds of thousands,” with the creator stating,

“I created this leaderboard to assist inform the safety group as to the tasks that don’t take safety severely so we are able to keep away from them and spend time on the tasks that do.”

The necessity for in-house auditors in DeFi.

In his presentation on the DeFi Safety Summit in July, Weiss highlighted auditors’ crucial function at varied phases of protocol improvement. By integrating auditors and researchers in-house, he pressured their potential to make insightful architectural choices, design efficient codebases, and undertake a security-focused method to protocol improvement.

Consequently, it’s regarding when platforms fail to acknowledge and adequately reward the efforts of those safety professionals when engaged on a contract foundation.

Auditors Gogo and MiloTruck highlighted that non-payment for recognized vulnerabilities is a widespread concern. Their posts underscore the pressing want for these platforms to reinforce their accountability and trustworthiness and guarantee due recognition for white hat hackers.

Extra transparency is required in dealing with vulnerabilities. Excessive-profile instances listed on BBWoS, just like the compromised deposit contract of Arbitrum, the financial exploit of Aave, and the malicious swap paths in dHEDGE, amplify this want.

Trusted Execution Environments in DeFi.

In response to Weiss’s points about belief, Danny Ki from Tremendous Protocol emphasised the potential of “decentralized confidential computing” to bolster belief in Web3 tasks and mitigate vulnerabilities. Ki is referencing the choice to run DeFi in Trusted Execution Environments (TEE), one thing inherent in Tremendous Protocol.

A TEE is a safe space of a processor that ensures code and knowledge loaded inside be protected for confidentiality and integrity. Nevertheless, one drawback of utilizing TEEs inside DeFi dApps is counting on proprietary structure from centralized corporations akin to Intel, AMD, and ARM. There are efforts within the open-source group to develop open requirements and implementations for TEE, akin to Open-TEE and OP-TEE tasks.

Ki argues that ought to “Web3 tasks function inside confidential enclaves, there could also be no must pay out for vulnerabilities, because the safety can be inherently fortified.”

Whereas a fusion of blockchain and confidential computing might present a formidable safety layer for future tasks, the transfer to interchange bug bounties and safety auditors with TEEs appears complicated, to say the least.

Points with bug bounties in DeFi.

Nonetheless, there are further considerations for white hat hackers, akin to improper bug disclosures from safety corporations on social media. A put up from Peckshield figuring out a bug in July merely mentioned, “Hello @JPEGd_69, it’s your decision to have a look,” with a hyperlink to an Ethereum transaction.

Gogo lambasted the put up stating, “If this vulnerability had been responsibly disclosed as an alternative of exploited, PEGd’s customers wouldn’t have misplaced $11 million, No reputational harm would have been brought about, The man would have gotten a strong bug bounty as an alternative of been front-run by an MEV bot.”

Gogo shared their bug bounty expertise with Immunefi, an organization they described as ‘past improbable,’ the place the payout required a mediation course of, finally resulting in a passable payout of $5k for a crucial bug.

These insights from the web3 safety group underscore the crucial function of auditors and the significance of efficient bug bounty applications to the crypto ecosystem’s safety, belief, and progress.

As some have recognized, hacks are lined extensively within the information and on X, however what for individuals who uncover the exploits and are by no means adequately compensated? Practically $2.5 million in allegedly unpaid bounties is listed on BBWoS alone, but, as Ki highlighted, might the longer term embrace a web3 that’s innately safe without having for bounties?



Source link

Tags: bountiesBountyBugDeFidyingmillionsprofessionscandalSecurityShamesilentunpaidWall
Previous Post

Crypto Futures Liquidations Hit $150M As Bitcoin Plummets

Next Post

Binance to Delist LTC/BUSD and DOGE/BUSD Perpetual Contracts

Related Posts

Ethereum Whale Buying Frenzy Hits Scale Unseen Since 2017
Ethereum

Ethereum Whale Buying Frenzy Hits Scale Unseen Since 2017

June 18, 2025
Deutsche Bank unveils institutional tokenization stack to fast-track regulated funds
Ethereum

Deutsche Bank unveils institutional tokenization stack to fast-track regulated funds

June 18, 2025
Analyst Says Ethereum Is Ready To Surge With Higher Lows Against Bitcoin, But There’s A Caveat
Ethereum

Analyst Says Ethereum Is Ready To Surge With Higher Lows Against Bitcoin, But There’s A Caveat

June 18, 2025
Bitcoin’s slide below $104k liquidates over $500M as war tensions escalate
Ethereum

Bitcoin’s slide below $104k liquidates over $500M as war tensions escalate

June 18, 2025
Bitcoin gives up rally after Trump denies Iran-Israel ceasefire role, calls Tehran to evacuate
Ethereum

Bitcoin gives up rally after Trump denies Iran-Israel ceasefire role, calls Tehran to evacuate

June 17, 2025
Ethereum Eye Potential Parabolic Upsurge – Here’s The Short-Term Target
Ethereum

Ethereum Eye Potential Parabolic Upsurge – Here’s The Short-Term Target

June 17, 2025
Next Post
Binance to Delist LTC/BUSD and DOGE/BUSD Perpetual Contracts

Binance to Delist LTC/BUSD and DOGE/BUSD Perpetual Contracts

Crypto market participation continues to dip

Crypto market participation continues to dip

Best Bitcoin (BTC) Wallets of 2023

Best Bitcoin (BTC) Wallets of 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Twitter Instagram LinkedIn Telegram RSS
The Crypto HODL

Find the latest Bitcoin, Ethereum, blockchain, crypto, Business, Fintech News, interviews, and price analysis at The Crypto HODL

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Mining
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Videos
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Bitcoin
  • Crypto Updates
    • Altcoin
    • Ethereum
    • Crypto Updates
    • Crypto Mining
    • Crypto Exchanges
  • Blockchain
  • NFT
  • DeFi
  • Web3
  • Metaverse
  • Regulations
  • Scam Alert
  • Analysis
  • Videos
Crypto Marketcap

Copyright © 2023 The Crypto HODL.
The Crypto HODL is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In