After having such a conversation with a Team member with the tag "Developer" on Discord and this happens..
Unfortunately my bug is still present in the codebase and now i am tempted to disclose publicly @SecretNetwork
We have identified an incident affecting assets bridged over IBC to Secret Network from the Axelar chain, with approximately $4.67M worth of tokens taken. Based on current information, the issue is isolated to the Secret-side ICS-20 smart contract of the Cosmos IBC connection
For those asking why I focus more on blockchain projects/DLT than smart contracts, it’s simply opportunity cost and attack surface.
Blockchain projects are usually much larger and more complex than smart contracts. They have more moving parts, more interactions, and more room
Very true!!
But now I find the concept of private bug bounties better as most times when protocols in general hosts bug bounty program on a web3 bug bounty platform, they end up not fully maximizing the use of it because of the number of spam submissions/AI slop that eventually end up getting the protocol team frustrated and then pausing their bounty program
If this hasn't convinced absolutely everyone that running a bug bounty program is critical in this new AI age, I don't know what will.
Whatever bugs are in your code will inevitably be found. You need to ensure they are found by friendlies. Only a bug bounty program will.
Almost every bug I report is on a code base audited by "top firms".
Some were math issues in code written and reviewed by BigTech alumni with PhDs in cryptography from Stanford/Ivy-League.
Everyone misses bugs. I miss too. AI misses bugs.
Let's stop talking about finding bugs missed by lots of experts as something new and unheard of.
It's so common I've been making a living off of it for 5 years straight.
I'm not the only one.
Can we stop using terms like top security firms, top auditors, or top whitehats to indicate how difficult a exploit was after they missed it?
> the vulnerability had evaded years of scrutiny by many of the world’s best cryptographers.
lol
@WhiteHatMage It pisses me off too
It’s now like simply implying that because the so called world’s best cryptographers couldn’t find it, the blockchain is very strong
Hahahah
🤯An AI security tool has 1st-place performance on security contests from just 1yr ago. Solidity-auditor v3 is out, FREE & Open Source.
Thousands of Solidity developers are using the tool already. Upgrade your security baseline, use the tool🫡
pashov.com/solidity-audit…
@ZeroK_____ But since I’m a beginner, I try to gather all the possible resources out there to get my agent to ᴜɴᴅᴇʀꜱᴛᴀɴᴅ ᴛʜᴇ ᴄᴏᴅᴇʙᴀꜱᴇ ᴛʜᴏʀᴏᴜɢʜʟʏ ᴅᴏɪɴɢ ᴀ ꜰᴜʟʟ ᴄᴏᴠᴇʀᴀɢᴇ before starting the hunt
152 Followers 227 Followingprev intern researcher now ft swe😴 | secular systems | linux | within chaos there exists emptiness👻
btw lead-in @weareWEB3mumbAI
552 Followers 1K Following♥️🇲🇦o7 Husky dad' Farming organic digital karma - When a measure becomes a target, it ceases to be a good measure. بياع ؤ شراي . level, moderate, and compact.
228 Followers 784 FollowingEx Web3 Intern @_learnable 22 | Ex Ambassador @calyptus_web3 | Member @base @baseafricaa - @superteamNG Enugu | FE Dev - SR & Web3 Dev Student @cyfrinupdraft
2K Followers 2K FollowingGod hacked me to hack things.
Web2 / Web3
EVM/Stacks/SOL/ZK
alter ego: @realgrew2fast
All opinions are my own; no financial advice.