Joined December 2022
64 Photos and videos
Pinned Tweet
Meanwhile i saved ecosystem from a massive $800m hack and the team is offering me $4k. Whitehats lose everytime.
๐Ÿšจ Breaking ๐Ÿšจ โš ๏ธ The attacker behind the $11.58M Verus exploit has reportedly returned $8.6 million The exploiter kept around $2.8M as a bounty reward
327
163
5,087
1,254,711
I wonder why people are posting so much about Claude finding the critical ZCash bug as if itโ€™s a big deal. HyperBridge got hacked, then launched a program on HackenProof and paid out about $120k within its first week or two for a ton of critical and high-severity bugs. My point is, I donโ€™t believe the bug was hidden in plain sight; security researchers simply werenโ€™t incentivized. Notice that the bug only came out after they ran a bug bounty program, attracted a lot of talent, and then closed the program. I would wager that the bug would have been found on the very first day on @HackenProof or @immunefi if they had launched a program, especially during this AI-assisted audit period weโ€™re in. If an AI model found it, anyone with a subscription could have found it too. A formal bug bounty program really helps, I hope projects learn from this and launch a bbp on any of this big platforms. And note, for web3, launching on bugcrowd if it isn't just the web2 aspect you are as good as not having a program(talking from experience)
7
1
111
3,893
Congrats man, first of many ๐Ÿ‘๐Ÿ‘
First bug bounty paid out. On to the next! ๐Ÿƒ๐Ÿฟ๐Ÿƒ๐Ÿฟ๐Ÿƒ๐Ÿฟ Big thanks to @only01Essential for teaching, mentoring, and giving me tips on how to approach bug bounties.
11
1
105
3,608
$8,000 total payout for one chain halt and a high severity bug. $4,000 worth of native tokens for another chain halt bug in project 2.
26
9
240
11,609
I guess calling them out was a good move then
Update: The THORSec team clarified that arrangements regarding a bounty for this report had already been underway with the treasury prior to this writeup. While a bounty has not been awarded yet, we appreciate the consideration from both the team and the treasury, and are adding this note to clarify the record.
22
2,152
$10,000 for another chain halt bug, through @cantinasecurity this time
45
10
469
20,597
I guess Christmas came early, lol With this bounties I have officially earned more than $100k in bounties this year already, within five months. 4 Critical bugs to one project, and a chain halt bug for another project.
My goal for 2026 is simple. Join the elites club by making over $100k in bug bounty
170
23
855
58,347
$3,000 bounty for another chain-halt bug. If exploited, any normal user could have completely halted the chain. Recovery would have required a patch and coordinated network upgrade.
51
7
362
27,440
Upgrading to an M5 Max with 128GB unified memory and 4TB SSD. Guess what model Iโ€™m about to run locally?
14
73
6,985
Yeay, I was awarded for a valid submission on @HackenProof #hackenproofed #bugbounty
32
4
349
9,723
Saved another chain with a lot of their native assets at risk(about $150k worth of it), plus two chain halt bugs. They paid $12,500 for the disclosures, also offered to pay for a private audit of their bridge ๐Ÿ”ฅ๐Ÿ”ฅ
38
1
260
8,642
Another project saved ๐Ÿ™Œ A chain halt bug this time. $4,000 for the disclosure. Expected more, but we move
28
1
258
9,615
Essential retweeted
My entire ethos of hunting has been to find only Critical and Highs but every now and then I keep pumping on these but of all the lows I have found am most proud of this coz it came from very reputable project. Shout out to @only01Essential for always being 1 call away
7
1
114
6,260
Found a bug today with millions at risk, I was expecting the team to be serious, but they were so adamant on following some set of rules for bug disclosures, which really didn't sit well with me. I feel bug disclosures should be streamlined and easy, I mean, if I wanted to report through a platform I would have just hunted there. Helping protocols ain't easy. Note that if the disclosure to reward process isn't smooth, researchers leave. Projects need to learn to take SECURITY RESEARCHERS MORE SERIOUSLY. Don't wait until you get rekt
8
4
76
9,102
Few weeks ago I responsibly disclosed a critical draining bug to @NibiruChain About $200k worth of assets were at risk as of the time I reported the bug. The team responded quickly, patched, shipped an upgrade and rewarded me $15k for the bug report. github.com/NibiruChain/nibirโ€ฆ
19
6
208
10,742
For those asking. This was reported off platforms. I reached out to them. If you don't know how to rightly do that, send me a dm.
5
30
3,513
I remember when protocols use "AI REPORT" to invalidate bug reports. AI has come a long way
2
21
3,133
Wen 1k?
5
27
3,152
Second dupped dlt High in this project. Man, I have been suffering with way too many duplicated reports
11
78
4,879