For the whitehats and security researchers who see this:
What do you think of this proposal to legally "hack back" funds from hackers?
whitehouse.gov/presidential-a…
On one hand, this could be an incredible opportunity for Sherlock or other security companies to organize whitehats and security researchers to go on the offensive, which we all know you're capable of.
On the other hand, is it even realistic to hack the hackers? They aren't exactly running DeFi protocols, so findings bugs in their smart contracts seems unrealistic. And they don't seem to move their funds very often. But maybe phishing them or finding other opsec compromises could be the way to hack them?
Interested to hear if you all believe there's a real path to "hacking the hackers" here, or if it's unrealistic.
Sherlock could be open to posting the $1M bond and applying for the program if there's real potential.
@mark_k This aged extremely well
x.com/mark_k/status/…
After doing more research on this, I think the human contribution is worth mentioning, too. My understanding is that this came out of years of work by Diego Córdoba and Luis Martínez-Zoroa developing the underlying approach, with Tristan Buckmaster and Levent Alpöge then using LLMs to push that research much further and eventually formalize and verify the result.
Rumor: OpenAI may have solved the Navier-Stokes problem, one of the seven Millennium Prize Problems. An announcement could be coming soon.
If confirmed, this would be a historic mathematical breakthrough.
A stranger with no account on any bug bounty platform just made $47 million finding a bug that platform triage teams would have taken weeks to even acknowledge.
No submission fee. No queue. No committee deciding if his finding counts as "critical" or "high" based on a rubric written by someone who's never touched the codebase.
He found the bug, took the money the bug was worth, and gave the fix back.
Compare that to a researcher who finds a real vulnerability, pays to submit it, waits a month, gets told it's a duplicate or out of scope, and walks away with nothing but a rejection email and also loses his submission fee.
The system built to reward people for finding bugs is slower and cheaper than just exploiting the bug yourself and negotiating after.
That's not a researcher problem.
That's the whole model failing at the one job it exists to do.
Nobody wants to say it plainly so I will... If your bounty program is slower and pays less than the black market rate for the same bug, researchers will stop reporting to you.
They'll just take it...
369 Followers 258 FollowingAnalyst. Long distance runner.
Thinking in frameworks, living with a touch of lah.
Observations on crypto, code, and macro trends.
113 Followers 179 FollowingDrinking the last sip of orange soda, I let out a long burp. The bubble said, "Alright, I've stored the summer wind safely in your belly."
2K Followers 181 FollowingPrior World Record speedrun holder for Doom The Dark Ages. Washed #1 BF2042 player. @RegimentGG Member. Partnered Twitch/YT Streamer.
1.6M Followers 193 FollowingBF6 + REDSEC SEASON 4 IS LIVE ⚓ 🌊
ESRB Rating: MATURE (17+) with Blood, Strong Language & Violence/In-game purchases.
Status Updates: @BattlefieldComm
48K Followers 482 FollowingPrincipal Game Designer on @Battlefield - @EA_DICE // previously player and TOM at @FNATIC. Esports guy. My tweets are my own.
28K Followers 2K FollowingI tweet stuff, sometimes more than others, Baguetteer, Battlefield connoisseur, Youtuber, If you're younger than BFBC1, this prob ain't the place for you
12K Followers 909 FollowingIt's pronounced Rage, I promise it used to make sense. Partnered YouTuber and Streamer @SoaRGaming - business inquires: [email protected]
24K Followers 167 FollowingRetired Team Fortress and Counter-Strike modder. Started the now cancelled @csco_dev project. Gamedev hobbyist by night, obsessed with game feel.
11K Followers 893 FollowingI create & beat game challenges that make you question my sanity.
Also still decent at FPS!
Business: [email protected]
@ThisIsTeamEXE 🫡
91K Followers 967 FollowingProgrammer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc)
237K Followers 93 FollowingOne guy. Global cybercrime. Tracked so you don't have to. Ransomware, data breaches, dark web activity, darknet markets, IOCs & emerging threats. Stay informed!