bug-bounty

625 articles
Sort: New Top Best
clear filter
0 2/10

A security researcher documents a CORS misconfiguration vulnerability that leads to exposure of sensitive data, demonstrating a common web application security flaw.

Montaser Mohsen
medium.com · montaser mohsen · 1 hour ago · details
0 9/10

A multi-stage vulnerability in GitHub's private pages authentication flow combining CRLF injection, null byte parsing bypass, and cookie prefix case-sensitivity to achieve XSS and cache poisoning on private organization pages. The attack exploited case-insensitive cookie handling to bypass __Host- prefix protections and nonce fixation to achieve unauthenticated arbitrary code execution.

GitHub HackerOne ginkoid $35,000 bounty github.io pages-auth.github.com
robertchen.cc · kh4sh3i/bug-bounty-writeups · 3 hours ago · details
0 6/10

A security researcher discovered a rate-limiting vulnerability in Microsoft's password reset flow that could be exploited via concurrent requests to brute-force 7-digit security codes, bypassing encryption and rate limits to enable account takeover even on accounts with 2FA enabled. Microsoft patched the vulnerability and awarded a $50,000 bounty.

Laxman Muthiyah Microsoft MSRC HackerOne Instagram
thezerohack.com · kh4sh3i/bug-bounty-writeups · 3 hours ago · details
0
marxchryz.medium.com · kh4sh3i/bug-bounty-writeups · 3 hours ago · details
0
vulnerability
medium.com · kh4sh3i/bug-bounty-writeups · 3 hours ago · details
0 6/10
Sui
vulnerability

A high-severity DoS vulnerability in Sui's Narwhal consensus layer allowed attackers to crash validator nodes via Out-of-Memory (OOM) attacks by sending a single malicious request with 1.2M certificate digests (37MB payload), bypassing the absence of response limits and timeout handling in the get_certificates() function. The vulnerability was patched by removing the vulnerable GetCertificates and GetPayloadAvailability handlers, with the researcher earning a $50,000 SUI bounty.

Sui Immunefi @F4lt Narwhal Bullshark Move MystenLabs
immunefi.com · unknown · 3 hours ago · details
0
bug-bounty
blog.asymmetric.re · Felix Wilhelm · 3 hours ago · details
0
bug-bounty
x.com · Ehsan · 3 hours ago · details
0
bug-bounty
research.lido.fi · riptide · 3 hours ago · details
0
bug-bounty
x.com · samuraii77 · 3 hours ago · details
0 8/10
vulnerability

A high-risk vulnerability in Ondo Finance's TrancheToken smart contract allowed attackers to destroy the uninitialized implementation contract via selfdestruct, causing all proxy contracts to no-op and potentially draining $50m from UniswapStrategy contracts if a minting flag were enabled. The bug was patched immediately after disclosure with no user funds at risk.

Ondo Finance Ashiq Amien iosiro TrancheToken AllPairVault UniswapStrategy Immunefi
iosiro.com · Ashiq Amien · 3 hours ago · details
0
bug-bounty
medium.com · Niv Yehezkel · 3 hours ago · details
0
bug-bounty
medium.com · unknown · 3 hours ago · details
0
bug-bounty
medium.com · unknown · 3 hours ago · details
0
bug-bounty
medium.com · GothicShanon89238 · 3 hours ago · details
0
bug-bounty
medium.com · Lucash-dev · 3 hours ago · details
0
bug-bounty
medium.com · unknown · 3 hours ago · details
0
bug-bounty
medium.com · Ashiq Amien · 3 hours ago · details
0
bug-bounty
medium.com · Ashiq Amien · 3 hours ago · details
0
bug-bounty
medium.com · deliriusz.eth · 3 hours ago · details
0 8/10
vulnerability

A critical vulnerability in Axelar Network allowed attackers to force validators to miss votes by crafting transactions with excessive logs that exceed Tendermint's 1MB RPC request limit, leading to automatic Chain Maintainer deregistration and potential halt of cross-chain operations. The vulnerability has been patched via governance proposal 256 disabling the auto-deregistration mechanism.

Axelar Network Marco Hextor Immunefi AxelarGateway Tendermint Cosmos SDK governance-proposal-256
marcotnunes.com · Marco Nunes · 3 hours ago · details
0
bug-bounty
medium.com · LonelySloth · 3 hours ago · details
0
bug-bounty
medium.com · riproprip · 3 hours ago · details
0 2/10
bug-bounty

Portfolio page showcasing multiple critical smart contract vulnerabilities disclosed across DeFi/NFT protocols, including access control flaws, uninitialized UUPS proxies enabling arbitrary delegatecalls, and broken token transfer functions. Author details bounty payouts and rescued funds across 88mph, Polygon, KeeperDAO, and other projects, with limited technical depth on each vulnerability.

pxMythics 88mph Polygon KeeperDAO Rivermen NFT OpenZeppelin abwagmi AxonsToken Alchemix Ondo Finance Code 4rena Immunefi iosiro Damn Vulnerable DeFi Decently Safe DeFi yAcademy Curve Finance BSides Cape Town Dedaub Ashiq Amien
ashiq.co.za · Ashiq Amien · 3 hours ago · details
0 3/10
bragging-post

Security researcher's portfolio showcasing multiple critical vulnerability disclosures in DeFi and NFT smart contracts, primarily focused on proxy vulnerabilities (UUPS), uninitialized logic contracts, and access control issues that collectively protected over $50M in TVL. While demonstrating significant impact, the article lacks technical depth and primarily lists findings with references to external postmortems rather than detailed exploitation methodology.

OpenZeppelin 88mph Polygon KeeperDAO Rivermen NFT iosiro Immunefi Alchemix Ondo Finance pxMythics abwagmi AxonsToken Code4rena yAcademy Curve Finance Ashiq Amien Dedaub
ashiq.co.za · Ashiq Amien · 3 hours ago · details
0 2/10
bragging-post

Portfolio page showcasing multiple critical smart contract vulnerabilities disclosed across DeFi protocols, including UUPS proxy initialization flaws, access control bypasses, and token theft vectors. While listing numerous bug bounty successes (>$6.5m rescued), it provides minimal technical depth and primarily serves as credentials summary.

88mph Polygon KeeperDAO Rivermen NFT OpenZeppelin abwagmi AxonsToken pxMythics Alchemix Ondo Finance Code4rena Immunefi iosiro Hack South YesWeHack BSides Cape Town Damn Vulnerable DeFi yAcademy TrustX Curve Finance
ashiq.co.za · Ashiq Amien · 3 hours ago · details
0 2/10
bragging-post

A portfolio page showcasing multiple critical smart contract vulnerability disclosures across DeFi protocols (88mph, Polygon, KeeperDAO, Alchemix, Ondo Finance) and bug bounty wins totaling over $6.5M in rescued funds, with brief technical descriptions of UUPS proxy exploits, access control flaws, and token theft vulnerabilities.

88mph Polygon KeeperDAO Rivermen NFT OpenZeppelin abwagmi AxonsToken pxMythics Alchemix Ondo Finance Code4rena yAcademy Immunefi iosiro BSides Cape Town Underhanded Solidity Contest Curve Finance
ashiq.co.za · Ashiq Amien · 3 hours ago · details
0 8/10
vulnerability

Acala's Homa staking protocol contained an unbounded loop in the process_redeem_requests function that could be exploited by an attacker with 12,000+ DOT to create 22,000 redemption requests, causing the validator's on_initialize function to exceed block finalization time limits and halt the entire parachain's block production.

Acala Polkadot Homa Immunefi @Lastc0de Acala Foundation
immunefi.com · Lastc0de · 3 hours ago · details
0 5/10
vulnerability

A critical rounding convention bug in Vesu's Singleton liquidation contract allowed attackers to steal user funds through malicious pool extension contracts, flashloans, and improper handling of the receive_as_shares flag. The vulnerability was discovered via Immunefi bug bounty, remediated by removing the affected liquidation logic and whitelisting pool extensions within 5 days.

Vesu Immunefi ChainSecurity Argent Labs Re7 Labs Braavos Alterscope
docs.vesu.xyz · Alex · 3 hours ago · details
0 1/10
-
bragging-post

A portfolio/services page by security auditor Kiki showcasing 50+ smart contract audits and 15+ bug bounties across DeFi protocols, with client testimonials and links to published audit reports, primarily for lending/staking/perpetual trading protocols.

Kiki Enigma Dark Bail Security Guardian Audits Stable Jack Gloop Hyperdrive Camelot Silo Finance Arrakis Finance Ambit Finance GMX Synthetix Orderly Umami EigenLayer
github.com · Kiki · 3 hours ago · details
More