11 ms·
Sei pays out $2M bug bounty
- dheera 2y agoHonest question: Was the $2M figure advertised in advance? Where does one go about discovering bug bounties of this size? It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.
- nailer 2y ago> Was the $2M figure advertised in advance? https://blog.sei.io/bug-bounty/ https://blog.sei.io/bug-bounty/ > Where does one go about discovering bug bounties of this size? - SECURITY.txt for individual projects. - https://immunefi.com https://immunefi.com for blockchain in general. - BugCrowd and HackerOne for wider tech. I'm an infrastructure engineer though and may not be the best person to answer. > It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size. https://www.hackerone.com/ethical-hacker/meet-six-hackers-making-seven-figures https://www.hackerone.com/ethical-hacker/meet-six-hackers-ma... Note: I work at a foundation for another blockchain. This doesn't affect anything I wrote above, just disclosing potential CoI.
- danielvf 2y agoYou can see lots more here: https://immunefi.com/bug-bounty/ https://immunefi.com/bug-bounty/
- consumer451 2y agoYes, that is actually worth it. This seems comparable to what a third party might pay. I have always wondered why the payouts are capped at the trillion dollar corps at such low figures. It appears like $75k max and MS and $100k max at Apple. Meanwhile shady 3rd party groups will pay you 10x that, won't they?
- cge 2y agoCryptocurrency bug bounty programs perhaps have an advantage in that the risks of classes of bugs are often concrete, financially quantifiable, immediate, and catastrophic. A bad RCE in a mainstream OS could do untold damage to users, reputational damage to the company, and so on, but even if severe, those risks have to be estimated. But in this case, for example, it seems like the $2m bounty was for a bug that, if exploited, would have made $1b in market cap disappear. I expect it's just much simpler to convince a skeptic businessperson when the risks are so clear.
- consumer451 2y agoThat's a very solid point, as sad as it is. I suppose the argument for OS makers to raise their rates might be that they are paying 10x below market rates, and the rates were set by the actual freaking market that exists. If I was a congressional aide, I would definitely write something up about this when my boss was going to drag a Microsoft exec across the coals in public. I would imagine that billions in gov contracts are at risk for MS right now due to lax security. A $2M bug bounty could have prevented that.
- stevage 2y agoI wonder if very large bounties create incentives to create bugs...
- consumer451 2y agoOh yeah, the old cobra effect. However, you could only pull it off once. I am sure a postmortem of all related design and commits would be done, correct? Also, FAANG level salaries are pretty high for anyone involved with that type of code, right?
- dheera 2y agoThere could also be a reverse bounty paid as a salary bonus to the devs if there is no security bug found in N months. A "code quality bonus", if you will. Though only to encourage quality control. Intentional bug creation should probably result in firing, unless it was done under duress.
- tptacek 2y agoApple outbids bottom- and mid-tier buyers, and top-tier buyers are extremely finicky about what they're buying: exploits, not vulnerabilities, for reliable bugs, with a variety of additional constraints. Apple and Google will buy exploits top-tier IC buyers won't, with less negotiation and less risk. The major parties to this market are aware of each other and are calibrating against each other; Apple and Google aren't blowing this off. It's complicated and counterintuitive in a bunch of ways.
- usmannk 2y agoIt was advertised in advance, but the real gamble is on if they'll pay. If you go to my other blogpost linked in OP, you can see a case where I was owed 500k and paid 60k. You're right though that it's a lot of risk. It's not something that most of the leaderboard works full time on, though some of us do. The immunefi homepage has a list of all the bounties on offer.
- teyc 2y agoCouldn’t there be a smart contract for this? I’ve no idea how.
- brcmthrowaway 2y agoI worked nearly 10 years in tech and this is all gobbledygook to me. That's scary.
- jerf 2y agoOn the blockchain, accounts have a certain amount of currency. You can issue a command to transfer currency from your account to somebody else's, as that is a primary use case of a cryptocurrency. There was a code path where you could send someone negative amounts of the currency and it would happily pay them a negative amount of currency and charge you a negative amount of currency, thus transferring their account balance to your against their will. There were several transfer paths and I think not all of them were vulnerable, but only one has to be. There's a bit of indirection that made it somewhat less obvious than my description makes it sound, though it amounts to the same thing in the end.
- schoen 2y ago> There was a code path where you could send someone negative amounts of the currency and it would happily pay them a negative amount of currency and charge you a negative amount of currency, thus transferring their account balance to your against their will. This is a bug I remember from the Apple II game "Taipan" (in which you play an 1800s opium-and-silk trader in East Asia). You could borrow negative amounts of money from a lender who charges extremely high interest. As a result, the lender would quickly end up owing you tremendous sums, without your having to do anything else. Wikipedia mentions this: > Note: A bug in the original game allows the player to overpay the moneylender, acquiring "negative debt". This "negative debt" will accumulate interest very quickly, and will count towards the player's net worth. As the game's vocabulary of number words ends at "trillion", this can cause the game to display garbage instead of the player's correct net worth. This has been fixed in the online "for browsers" version of the game.
- pennybanks 2y agoit really shouldnt be referred to as currency as a whole anymore. well i guess anything can be a currency but its too misleading even though that was by design. if its designed to be a stock then should be called so. poker chips? in game currency? money laundering token? reward points? purchase receipt? jpeg? just think it would help
- danielvf 2y agoThe bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding. Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty! Almost all crypto bug bounties run through Immunefi. [1] There are lots of > one million dollar bounties. You can see SEI's current bounty page here.[2] The company I work (a different company) for has a one million dollar bounty listed on immunefi.com and median response time of six hours. [1] https://immunefi.com/bug-bounty/ https://immunefi.com/bug-bounty/ [2] https://immunefi.com/bug-bounty/sei/ https://immunefi.com/bug-bounty/sei/
- strictnein 2y agoEverything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.
- j0hnyl 2y agoYou could say that about anything that is critical.
- wepple 2y agoNot really - a bug bounty gives you some type of currency. Jacking a database and trying to sell it on a DLS or dark web is a massive process.
- tptacek 2y agoNo, you can't.
- CyberDildonics 2y agoI can and I do, I say it all the time.
- 2y ago
- malux85 2y agoDid they get paid 2M in USD, or did they get paid 2M in magic-bean tokens, where is so little market depth that selling 30k of it would tank the market, so they will have to bleed it out slowly and hope the price doesn't tank before they exit
- danielvf 2y ago[I was wrong, see below]
- usmannk 2y agoThis one was actually USDC! Regulated, unmagic, dollar-backed beans.
- pennybanks 2y agocongrats. take your mama out for a nice dinner. get some flowers as well you know she deserves it
- nobrains 2y ago$8,333 monthly on a 5% return. Congrats!
- bangaladore 2y agoMagic-bean tokens. I think most on that bug-bounty site are done like that.
- bangaladore 2y agoRegarding the downvotes, the company says the below in their Immunefi page. It seems (as the OP responded) that they paid out differently in this case. I am unsure why that happened or if the page is outdated. "Payouts are handled by the Sei Foundation team directly and are denominated in USD. However, payments are done in SEI." [1] The other part of my comment is correct according to the various Immunefi listings. Again, I could be incorrect if they do something differently behind closed doors. [1] https://immunefi.com/bug-bounty/sei/ https://immunefi.com/bug-bounty/sei/
- ohy 2y agoFor whom it seems surprising, that's actually rather small, considering hacks can end up in an irreversible $100M+ transfer to the malicious party. You can check Immunefi's Bounty-Board for reference, currently paying up to $15M per find. Another good source is rekt.news, creating post-mortems about all the DEFI-hacks and an own leaderboard, $624M for #1.
- crest 2y agoSure, but you get to enjoy your bounty payout. Having $2M legally vs. having to become a money launderer?
- usmannk 2y agoRight, yeah. I estimated that a savvy attacker might have been able to get out with 50 or even 100m from this, but they would also go to jail. So...
- _940h 2y agoWhat sort of crime are you envisioning that exploiting this would fall under? It's not always fraud to satisfy a poorly written contract, although that is commonly the case.
- avarun 2y agoEverything is wire fraud / securities fraud
- baobabKoodaa 2y agoSomeone has been reading Matt Levine
- usmannk 2y agoWire fraud, at minimum. This would constitute direct theft. Very similar cases have been tried and convicted several times now.
- bcherny 2y agoCool writeup! This has got to be one of the biggest security bounties ever paid out, right?
- usmannk 2y agoIt's up there but not singularly so. Twice there have been $10M! You can see the leaderboard where the majority of crypto bounties are represented here (https://immunefi.com/leaderboard/ https://immunefi.com/leaderboard/) but you have to search around for the actual reports.
- yieldcrv 2y agonope, not at all! the crypto sector has been the most lucrative thing you can be doing in software for a decade straight now, especially with the lowest CapEx - AI doesn't even come close when factoring that in - bug bounties have been larger and only a subset are through these bug bounty brokers.
- usmannk 2y agoHey OP here, thanks for posting. Happy to answer any questions.
- teschmitt 2y agoWhat are you doing with all that dough?
- ayewo 2y ago1. For the 2nd issue you found, was the amount you redeemed after being paid really up to $2m USD? 2. From your other comments elsewhere in this thread, it sounds like you are a full-time bounty hunter, correct?
- usmannk 2y ago1. Yes, they sent me 2,000,000 USDC. 2. Well, I'm currently not employed full time and I do spend a lot of time bounty hunting. But I mix it in with other things as well, like competitive security reviews on https://sherlock.xyz https://sherlock.xyz or https://cantina.xyz https://cantina.xyz and private contracted security reviews.
- ayewo 2y ago> .. . and private contracted security reviews. How you find those? Or this type of work finds you based on your activity on competitive security review sites?
- usmannk 2y agoTypically networking. I spent some time working at a reputable firm in this space as well. One way to do this is to show some chops on the competition sites and then move to one of the organized freelance firms like Spearbit or yAudit. In doing all of these things you'll inevitably meet more people, build a specialty, get some reputation, etc.
- kubb 2y ago
- rvz 2y agoSee. These crypto bounties pay as much or even more than big tech bug bounties. This bounty prize is the equivalent of finding a Chrome zero day bug or an iPhone zero day RCE jailbreak. There are lots of >$1M bug bounties in crypto. The question is, would you rather target Chrome/Safari or iPhones and find and chain-up 5 - 10 zero days for $1M+ or target crypto projects instead for $2M per project? You're really missing out.
- yao420 2y agoI’m not a crypto hater (I used to work security at coinbase) but I think that while a chrome or iPhone zeroday might be worth less in bug bounty it’s worth more for a security engineers career long term. Having the iPhone bug and the accompanying conference talk and blog post will allow you get hired by nearly any good security or tech company. No one cares about blockchain bugs except other crypto companies. When I and a bunch of other coinbase engineers were looking for jobs we were looked down at for even working in crypto. And weren’t even in the blockchain team! Just regular engineers. I myself have dedicated a couple of months to testing gnosis and curve that each have $2 million bounties but turned up short. Last year I switched to a ML based fuzzing research and was able to speak at defcon and got crazy offers after publication.
- zEddSH 2y agoCan you share more about ML based fuzzing? I do pretty basic fuzzing and that's been pretty useful at work for testing, and am keen to learn about better more modern approaches than mine!
- digital_sawzall 2y agoFuzzing is a massive field now. I don't know what you are doing specifically but this is a collection of good related papers: https://github.com/wcventure/FuzzingPaper https://github.com/wcventure/FuzzingPaper. I would find what is most like your problem domain and dig in :).
- 2y ago
- 4hg4ufxhy 2y agoI was impressed by the fast payouts. I almost couldn't believe how easy the second one was going to be, but it turned out a bit trickier than I thought. No wonder it flew under the radar.
- deleted 2y ago[deleted]
- suzzer99 2y agoPardon my crypto ignorance, but if someone took over the entire SEI platform, wouldn't the value of SEI coin drop to zero?
- ffpip 2y agoYes, there would be no liquidity.
- javier123454321 2y agoWell, like Soros on the Bank of England or the attack on Terra luna, you can short SEI before the attack as well. This is actually why "proof of stake" blockchains are fundamentally flawed. They only make sense if the value of the system is denominated in the currency of the system. It's self referential and prone to negative feedback loops. They are secure because the token is expensive, the token is expensive because it provides a secure platform. Short the token, take a loan out, compromise the security, tank the value, profit. All the mechanisms to prevent that are built into the system, like delaying the validator pool entry, but the only real backstop is a hard fork and spinning up a new copy.
- latchkey 2y ago" Cosmos uses go panics for error handling. Transaction runs out of gas? panic. Try to spend more coins than you have? panic. Invalid inputs? panic. ... For safety, later on the panic was removed entirely. " Next time someone suggests using panic's as exceptions in golang... I'm going to point them at a nice $75k reason not to do that.
- patriciapatp 2y ago[flagged]
- patriciapatp 2y ago[flagged]
- patriciapatp 2y ago[flagged]
- menasjerri 2y ago[dead]
- henryethan 2y ago[flagged]
- MELEKE 2y ago[dead]
- Lewis324 2y ago[dead]
- beckylawhon 2y ago[dead]
- zanetaeliasz94 2y ago[flagged]
- joycecaroline 2y ago[dead]
- Virginia_mae 2y ago[dead]
- MELEKE 2y ago[dead]
- alfredmanios 2y ago[dead]
- LunaMoore 2y ago[dead]
- danacaldwell022 2y ago[dead]
- mabellopez 2y ago[dead]