bitcoin

2 articles
sort: new top best
clear filter
0 4/10
bug-bounty

A critical DoS vulnerability in the Stacks Clarity virtual machine was exploited via unhandled exceptions in smart contract execution, causing node crashes. The researcher 'Catchme' reported this flaw and received a $76,011 bounty; the fix involved proper error handling instead of relying on `.expect()`.

Stacks Catchme Immunefi Clarity Bitcoin PoX
medium.com · Catchme · 19 hours ago · details
0 6/10

A misconfigured CORS policy on a Bitcoin site's third-party contact form API allowed arbitrary origins with credentials enabled, enabling attackers to extract sensitive user data (name, email, phone, account ID) via a malicious webpage using XMLHttpRequest.

Arbaz Hussain HackerOne api.thirdparty.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details