An SR Summer winner just found a Critical vulnerability, earning him a $25,000 bounty.
@skydev0h joined Immunefi in April 2026 and has already earned $44,000 in bounties.
He has also been one of the most active users of Immunefi Studio, consistently testing it and sharing
Thanks to you all! 😊
It actually was a bit rough ride, and only this one out of 4 critical reports of the same caliber to this project made it through PKI and duplicates sieve, and there were some reproduction questions, but the project team handled it very professionally (although a bit slowly, but understandable, they were very overloaded) - asked additional questions (rather than closing the report right away like my earlier ones to some other projects), and, ultimately, after presenting a turnkey tool, accepted and rewarded the finding respecting the terms at the time of the submission.
Slow, but very pleasant experience, especially if compared to some other projects and platforms. 😔
@tjbecker I think that at some periods of compute starvation their "thinking longer" classifier gets shorter timeout or smaller quant and it is fail closed. Kind of "no time to check this, DENIED" *stamp*
@Valistheaeth Wow, why I've not seen it earlier... absolutely hate losing ANY data, who tf even thought about setting it just to 30 days by default... thankfully my "Lavos Left Shard" SBC did backups of "Lavos Core" AI zoo station, but something might got lost. Thanks for the important info!
@theBliz_ And they have audacity to call themselves "whitehats".
Quite sad that LN does not have a BBP, so that real whitehats would look in their direction as well.
Just having a BBP might have resulted in real responsible disclosure and would've avoided all this loss and drama.
What queue, what triaging? Liquid Network did not even have a bug bounty program at the time of incident. If they did more real whitehats would look in their direction >_<
Finding something on infra is not as difficult as proving it. Unlike SCs where you simply local-fork the chain and demonstrate the vuln, in infra even tens of multi-day experiments may not be enough. Without being able to touch production (obviously) it suddenly may turn out that production environment diverges from local testing one. Nevertheless infra is fun one to play with.
@mdp_sec@gkdataio I guess that Astra is not In DB package basically, once the DBL model would resolve to it rather than to Sol I think it will become usable
SR @skydev0h joined Immunefi in April and has already made a serious impact.
During SR Summer, he submitted 49 reports, with 44 of them being valid.
That’s an almost 90% accuracy rate.
Congrats, @skydev0h! 🏆
Reminder: To qualify as an official SR Summer participant,
3 Followers 118 FollowingAspiring Smart Contract Security Auditor.🛡️ | Breaking protocols & learning exploits ⚡ | On a mission to find 0-days 🔍 | Open to insights from the OGs 👀
3K Followers 3K Followingsecuring onchain cryptography next billion dollar (ZKP, MPC, FHE, PQC, TEEs) & making smart contract security accessible to any developer, creator @Zippel_Labs.
264 Followers 735 Following@ethereum protocol fellow | prev @Optimism research | I'm glad to discuss any knowledge related to the underlying aspects of Geth and Optimism rollup with you.
2K Followers 2K Following21| Banger | Security | Buildoor |Visual Artist | Bussiness
alter ego: @realgrew2fast
All opinions are my own; no financial advice.
3K Followers 3K Followingsecuring onchain cryptography next billion dollar (ZKP, MPC, FHE, PQC, TEEs) & making smart contract security accessible to any developer, creator @Zippel_Labs.
32K Followers 3K FollowingTech veteran turned health hacker. Merging science with self-experimentation to push the limits of longevity and peak performance with age. YRS=50 | N=1.
1K Followers 3K FollowingSecurity and anti-cheat researcher focused on Windows internals.
Advancing reliable detection and stronger system integrity.
https://t.co/1hoZxnzccW
2K Followers 1K FollowingSecurity Researcher
I find the bug before it finds the treasury
$400M+ exploits prevented
#22 Immunefi · #36 HackenProof
DMs open for collaborative audits