For the sake of clarity, the reason why I got so triggered is that 6 days ago, I sent a report to a protocol's BB program.
The protocol has 8 figs TVL. The report has not been acknowledged in 6 days, the term for full resolution according to the platform's SLAs is 14 days, including the payout term. Seeing the behavior, this is what's going through my mind right now:
> I'll be ghosted again.
> What if their dev is OOO?
> What if they are overwhelmed by reports?
> What if they simply didn't log in to see if they have new submissions?
> Will they treat me fairly or try to invent an excuse to not pay?
> Will they even reply, at all??
> Did the dev die? :))
I like to believe that I did my due diligence:
1. picked a protocol with 8 figs TVL to ensure that they are not too small, and they should theoretically be able to pay
2. they are active on socials every day. They post almost every day Monday - Friday, including 2 days after I sent my report.
3. they have active users interacting with the contracts on a daily basis (today included).
The report has a mainnet fork POC attached to it, proving the bug. I'm doing my best to provide as much value upfront as possible, make it as easy as possible for the person on the other end to see, and reproduce the bug and make the facts irrefutable. I can not do anything more than this, really. This is not a protocol draining bug, but it causes direct loss of funds for the protocol and its users in another way and the impact is Critical based on the program's rules.
On one hand, I see other whitehats having their reports paid, but on the other, this is like the 6th or 7th protocol that I sent reports to, and it always feels off. I have yet to encounter a protocol that actually cares, is responsive, and treats me fairly.
This has nothing to do with the platform itself (Immunefi). This is not a critique against them. I start to believe that they genuinely do whatever they can to the best of their abilities.
Is this sufficient? Well, not really, but at least they try. They can't force protocols to behave decently or enforce payments, so they have to rely on the protocol's "honor/ word/ decency", same as we (whitehats) do.
The problem is that some protocols don't honor their word and BB program rules. They simply take advantage of the information that whitehats submit through BB platforms, and then do whatever they can to not pay you or not pay you fairly. I start to think that the EXCEPTIONS are the ones that actually hold their word, while the RULE is that you'd get played one way or another.
This is why, as a whitehat you have to go through this embarrassment.
Protocols seem to pay only when they are cornered, and, unfortunately, that is, post an exploit .... that's why we see all these "return 75% of funds and keep the rest as whitehat bounty".
That's when they are vulnerable, desperate, and they'd do "anything" to get "some" of the money back ...
This IS NOT ME SAYING GO BLACKHAT, NO. That's NEVER an option, but I just wish protocols would treat BB submissions with the same degree of respect and seriousness. You know, just have a bit of honor and hold your promise.
This is why I got so triggered. Thanks for coming to my TED Talk.
I struggle to find and send valid bugs on
@immunefi , invest time and effort into finding and validating them, send them, just to be ghosted, lowballed, disrespected, while criminals just steal the money, and get paid
> checks note
~$3M as "whitehat bounty" ...
This triggers me, really. I still have an Immunefi mediation which was open back on Feb 10, where the protocol HAS NOT RESPONDED ANYTHING, although they FIXED the bug in January ...
Literally, the protocol did not reply anything about the mediation, although it was open more than 3 months ago, and the bug was fixed more than 4 months ago.
This is how whitehats get treated and below you can see how criminals are treated as "whitehats"
π€‘π