This one has a bit of story behind it.
Less than 12h after the report was submitted, it was confirmed by the team. The team didn’t even try to argue about how catastrophic the impact was. They were fast responsive and professional and transparent with their users, something I really admired. They simply straight told me because of a large hack last year that they suffered from they’re struggling financially and they’re letting a lot of their people go. The direct impact was around 7 million dollars. They were honest and I like honesty so instead of the normal 700k bounty, I accepted the 300k, I don’t regret my decision and I hope the project bounces back even stronger during these hard times, I admire them and their security standards and I wish them the best.