TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Sei pays out $2M bug bounty

230 点作者 sygma11 个月前

11 条评论

danielvf11 个月前
The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren&#x27;t enough security people yet that market forces have commoditized bounty finding.<p>Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty!<p>Almost all crypto bug bounties run through Immunefi. [1] There are lots of &gt; one million dollar bounties. You can see SEI&#x27;s current bounty page here.[2] The company I work (a different company) for has a one million dollar bounty listed on immunefi.com and median response time of six hours.<p>[1] <a href="https:&#x2F;&#x2F;immunefi.com&#x2F;bug-bounty&#x2F;" rel="nofollow">https:&#x2F;&#x2F;immunefi.com&#x2F;bug-bounty&#x2F;</a><p>[2] <a href="https:&#x2F;&#x2F;immunefi.com&#x2F;bug-bounty&#x2F;sei&#x2F;" rel="nofollow">https:&#x2F;&#x2F;immunefi.com&#x2F;bug-bounty&#x2F;sei&#x2F;</a>
评论 #40710861 未加载
评论 #40711232 未加载
评论 #40712057 未加载
usmannk11 个月前
Hey OP here, thanks for posting. Happy to answer any questions.
评论 #40712242 未加载
评论 #40711013 未加载
评论 #40710621 未加载
评论 #40710617 未加载
评论 #40711433 未加载
4hg4ufxhy11 个月前
I was impressed by the fast payouts. I almost couldn&#x27;t believe how easy the second one was going to be, but it turned out a bit trickier than I thought. No wonder it flew under the radar.
ohy11 个月前
For whom it seems surprising, that&#x27;s actually rather small, considering hacks can end up in an irreversible $100M+ transfer to the malicious party.<p>You can check Immunefi&#x27;s Bounty-Board for reference, currently paying up to $15M per find.<p>Another good source is rekt.news, creating post-mortems about all the DEFI-hacks and an own leaderboard, $624M for #1.
评论 #40710596 未加载
bcherny11 个月前
Cool writeup! This has got to be one of the biggest security bounties ever paid out, right?
评论 #40710589 未加载
评论 #40713001 未加载
rvz11 个月前
See. These crypto bounties pay as much or even more than big tech bug bounties.<p>This bounty prize is the equivalent of finding a Chrome zero day bug or an iPhone zero day RCE jailbreak. There are lots of &gt;$1M bug bounties in crypto.<p>The question is, would you rather target Chrome&#x2F;Safari or iPhones and find and chain-up 5 - 10 zero days for $1M+ or target crypto projects instead for $2M per project?<p>You&#x27;re <i>really</i> missing out.
评论 #40711101 未加载
suzzer9911 个月前
Pardon my crypto ignorance, but if someone took over the entire SEI platform, wouldn&#x27;t the value of SEI coin drop to zero?
评论 #40719364 未加载
评论 #40716814 未加载
dheera11 个月前
Honest question: Was the $2M figure advertised in advance? Where does one go about discovering bug bounties of this size?<p>It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.
评论 #40710349 未加载
评论 #40710606 未加载
评论 #40710407 未加载
评论 #40710370 未加载
malux8511 个月前
Did they get paid 2M in USD, or did they get paid 2M in magic-bean tokens, where is so little market depth that selling 30k of it would tank the market, so they will have to bleed it out slowly and hope the price doesn&#x27;t tank before they exit
评论 #40710512 未加载
评论 #40710514 未加载
latchkey11 个月前
<p><pre><code> &quot; Cosmos uses go panics for error handling. Transaction runs out of gas? panic. Try to spend more coins than you have? panic. Invalid inputs? panic. ... For safety, later on the panic was removed entirely. &quot; </code></pre> Next time someone suggests using panic&#x27;s as exceptions in golang... I&#x27;m going to point them at a nice $75k reason not to do that.
brcmthrowaway11 个月前
I worked nearly 10 years in tech and this is all gobbledygook to me. That&#x27;s scary.
评论 #40710416 未加载
评论 #40710580 未加载