6 ms·
The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a ba
by danielvf 2y ago
The bounties in crypto are so big because the math is so clear on the cost vs benefits of the bounties. Paying two million to avoid losing a billion is not a bad deal. And there just aren't enough security people yet that market forces have commoditized bounty finding.
Good companies use bounties as yet another security layer - after doing everything else, add a bug bounty!
Almost all crypto bug bounties run through Immunefi. [1] There are lots of > one million dollar bounties. You can see SEI's current bounty page here.[2] The company I work (a different company) for has a one million dollar bounty listed on immunefi.com and median response time of six hours.
[1] https://immunefi.com/bug-bounty/ https://immunefi.com/bug-bounty/
[2] https://immunefi.com/bug-bounty/sei/ https://immunefi.com/bug-bounty/sei/
- strictnein 2y agoEverything in Crypto (for both meanings of the word) has a built in bug bounty. It's just whether or not the companies want to take part in it.
- j0hnyl 2y agoYou could say that about anything that is critical.
- wepple 2y agoNot really - a bug bounty gives you some type of currency. Jacking a database and trying to sell it on a DLS or dark web is a massive process.
- tptacek 2y agoNo, you can't.
- CyberDildonics 2y agoI can and I do, I say it all the time.
- acdha 2y agoTry thinking through other comparisons to understand the difference: if I find a bug in the power grid, how do I cash out? There aren’t many buyers, it’s really hard to move a lot of cash without getting caught, and if I use any other electronic system I have to pay a ton of money to get help laundering it because the risks are so high. Criminal outfits in Asia play games trying to get gift cards or things like that but it’s hard to scale and a lot of their dupes here get caught. Contrast that with cryptocurrency where a bunch of VC money pumped up a market for you to launder the proceeds and the protocols are intentionally designed not to have antifraud protections. Ransomware was possible a decade earlier but the profitability went up massively once it became easy to launder millions rather than hundreds of dollars.
- tptacek 2y agoI have a general rule of exploit sales which nobody has shot me down on yet and I'm increasingly confident about: people are buying non-speculative outcomes. Every dorm room conversation about vulnerability valuation inevitably veers into speculation about what bank-shot outcomes a buyer might hope to achieve with a purchase. The reality is that unless the buyer is getting exactly an outcome they already planned (and, usually, have already repeatably achieved), they're not interested. Exploits have to slot into existing business processes. This explains reliable, stealthy, zero-interaction full-chain iOS vulnerabilities, which fit into every intelligence, military, and law enforcement business process pin-compatibly. It explains browser vulnerabilities and ATO vectors. And it also approximates the market for blockchain vulnerabilities: if the exploit is "literally transfer untraceable cash from victims to buyer", lots and lots of criminal organizations already have that business process; you probably simplify their existing repeatable process. Blockchain vulnerabilities thus have a very credible market. As bonus: the work of discovering and POC'ing these vulnerabilities may be gnarly, but the engineering required to exploit them at scale probably isn't. It doesn't take months of R&D to make the exploit "reliable", it generates straight cash until it dies (and probably has a half-life measured in minutes), and so on. Every lucrative class of vulnerability has some kind of story like this; they all fit into some existing, very clearly stated demand. We get into trouble trying to generalize. All the markets are very specific; they're all sui generis. Most vulnerabilities are worth zero. There are mobile OS RCEs that are probably worth zero!
- BeetleB 2y agoOne just happens to be more legal than the other.
- asterix_pano 2y agoDepends, it's not clear yet that "code is law" or is not.
- TacticalCoder 2y ago> Depends, it's not clear yet that "code is law" or is not. Aren't there quite a few cases already where attackers stealing funds from smart contracts were considered just that: thieves. And where their "code is law" defense didn't amuse the judge? IIRC we recently even saw two sent to jail for manipulating smart contract prices: it's not even clear they used a bug in a smart contract. I already posted it but Uncle Sam cannot have it both ways: if Uncle Sam asks people making money with cryptocurrencies to pay taxes, Uncle Sam goes after those who steal from the taxpayers. And... Oh boy, does Uncle Sam tax gains.
- nubb 2y agoiirc someone successfully argued code is law in a court in france
- deleted 2y ago[deleted]
- MattGaiser 2y agoIs there any hint of the legal system accepting that? They certainly don’t accept “locks are law” or “finders keepers.”
- yieldcrv 2y agoyes, sometimes. Its mostly the opposite of what people expect, but truth is often stranger than fiction. The MEV and Sandwicher attackers are legal, increase the transaction costs for everyone, skim profits from everyone and annoy everyone, the exploiter of a MEV bot gets charged and convicted. I don't have any problem with that, I've analyzed the sentiment of discussion though. I don't think anyone got charged and said code is law. Its more about who gets charged at all.
- latchkey 2y agoEverything in finance... banks have the same bug bounty.
- bufferoverflow 2y agoNot really. Bank transactions are reversible (especially when banks themselves are affected). And if you try to wire money to your account, you will be found trivially.
- fragmede 2y agoSometimes they are. There's a network of seedy international banks that scammers use to take their victims money, because otherwise the scam wouldn't work.
- ffpip 2y agoDo you have examples? People can avoid them
- fragmede 2y agoThe scammers wire the money out of your account into a bank account they control, and then put it in another bank, and then move it further on from there. Knowing which bank they have their account at doesn't help you avoid the problem.
- ffpip 2y agoYeah I understood the mechanism, just wanted to know the companies that enable such things.
- latchkey 2y agoDefinitely not true. My last company had the finance department phished and they never recovered the funds. It was about $50k I believe. See also all the people pissed at zelle.
- yieldcrv 2y ago> And there just aren't enough security people yet that market forces have commoditized bounty finding. I have the opposite conclusion there, crypto organization sponsored bug bounties are far more accurately valued than Web 2.0’s arbitrary adversarial bug bounties, and have attracted tons of developer talent to crypto bug bounties and the crypto ecosystem as a whole
- j0hnyl 2y agoCrypto bug bounties require specialized low level knowledge. Web 2 pentesting is akin to a qa checklist. Imo op is right that web2 bounties are commoditized.
- yieldcrv 2y agoMore commoditized but vastly mispriced, especially consequential ones. but there are many laymen and seasoned programmers that would consider web 2 bug bounties to be very specialized, at the same time cosmos and EVMs have been around for at least 7 years now and many devs have only done that work - which is actually a problem in recruiting as many of these specialized crypto devs are quite junior when Apple is going to fight tooth and nail to not pay you $10,000 while the black hat government contractor will pay $1,000,000 for the same exploit, the market is saying what the real price is and its at parity with what Web 3 is paying
- bigiain 2y ago> and have attracted tons of developer talent to crypto And yet: "Both issues were caught after the code had been audited, merged, and slated for release" I wonder who did those audits?
- wslh 2y agoThe problem is that at certain level of TVL you cannot scale your security measures [1]. So, no silver bullet to security in crypto. [1] https://bittrap.com/resources/defis-growing-pains:-as-tvl-raises-so-does-the-probability-of-being-hacked https://bittrap.com/resources/defis-growing-pains:-as-tvl-ra...