bug-bounty

621 articles
Sort: New Top Best
clear filter
0
bug-bounty

A collection of security research articles covering vulnerabilities in blockchain projects including Oasys (a gaming-focused Ethereum L2), Eco's lockup contracts, and Ocean Protocol's hybrid NFT implementation where on-chain data modifications can be exploited. Multiple bugs are documented with disclosure timelines and remediation details.

Oasys Merkle Bonsai Immunefi Bandai Namco DoubleJump.japan Eco Ocean Protocol
mirror.xyz · merkle_bonsai · 4 hours ago · details
0
bug-bounty
medium.com · rootrescue · 4 hours ago · details
0
bug-bounty
medium.com · unknown · 4 hours ago · details
0
bug-report

Security research analyzing a hybrid NFT vulnerability in Ocean Protocol where on-chain Data Description Objects (DDOs) stored on blockchain can be modified to enable attacks. The article discusses design flaws and issues discovered in Ocean Protocol's implementation, with bug bounty disclosures via Immunefi.

Ocean Protocol Immunefi Merkle Bonsai Oasys Eco Bandai Namco DoubleJump.japan
mirror.xyz · merkle_bonsai · 4 hours ago · details
0
-
vulnerability

Discussion of a business logic vulnerability in ad portals that allows running advertisements for free on major platforms like Reddit, Twitter, and Quora. While not directly compromising app security or user data, the vulnerability causes financial damage to companies through unauthorized ad budget bypass.

Reddit Twitter Quora Adam
mirror.xyz · Driver · 4 hours ago · details
0
bug-bounty
medium.com · zb3 · 4 hours ago · details
0
bug-bounty
medium.com · janbro.eth · 4 hours ago · details
0
bug-bounty
medium.com · unknown · 4 hours ago · details
0
vulnerability

A critical vulnerability in the Betverse ICO Token contract's transferTokenToLockedAddresses() function was caused by incorrectly marking it as public instead of internal, allowing attackers to steal BToken by repeatedly transferring funds to their addresses. The article documents this access control misconfiguration discovered during security research on the Immunefi platform.

Betverse Immunefi BToken Shanmuga Bharathi Ocean Protocol OASYS
mirror.xyz · Shanmuga Bharathi. N · 4 hours ago · details
0
bug-bounty
medium.com · Catchme · 4 hours ago · details
0
bug-bounty
twitter.com · Daniel Cohen Hillel · 4 hours ago · details
0
bug-bounty
medium.com · unknown · 4 hours ago · details
0
bug-bounty
medium.com · GothicShanon89238 · 4 hours ago · details
0
bug-bounty
twitter.com · iczc · 4 hours ago · details
0
bug-bounty
medium.com · unknown · 4 hours ago · details
0
bug-bounty
medium.com · unknown · 4 hours ago · details
0
bug-bounty
twitter.com · guhu · 4 hours ago · details
0
bug-bounty
medium.com · Ashiq Amien · 4 hours ago · details
0
bug-bounty
twitter.com · HollaWaldfee · 4 hours ago · details
0
bug-bounty
medium.com · Ashiq Amien · 4 hours ago · details
0
bug-bounty
x.com · Pavel Shabarkin · 4 hours ago · details
0
bug-bounty
x.com · Marco Nunes · 4 hours ago · details
0 7/10
vulnerability

Threshold Network's L2WormholeGateway contract contained a critical vulnerability allowing attackers to mint unlimited canonical L2 tBTC by exploiting the depositWormholeTbtc function through reentrancy via a malicious ERC20 token's transfer callback. The vulnerability was discovered via Immunefi bug bounty, patched by removing the vulnerable function and adding reentrancy protection, with no funds lost.

Threshold Network tBTC Immunefi Wormhole L2WormholeGateway Arbitrum Base Optimism Polygon Bitcoin
blog.threshold.network · unknown · 4 hours ago · details
0 8/10
vulnerability

A missing access control and unchecked state transition vulnerability in Alchemist's TimelockConfig.confirmChange() function allows any attacker to set arbitrary configuration parameters (including admin and recipient addresses) to zero without initiating the required first step, permanently bricking critical DeFi functions like token minting for staking rewards.

Alchemist Fjord Foundry Aludel Crucible TimelockConfig Dacian gogotheauditor pashovkrum
dacian.me · Dacian · 4 hours ago · details
0 1/10
-
bragging-post

A portfolio/services page by security auditor Kiki showcasing 50+ smart contract audits and 15+ bug bounties across DeFi protocols, with client testimonials and links to published audit reports, primarily for lending/staking/perpetual trading protocols.

Kiki Enigma Dark Bail Security Guardian Audits Stable Jack Gloop Hyperdrive Camelot Silo Finance Arrakis Finance Ambit Finance GMX Synthetix Orderly Umami EigenLayer
github.com · Kiki · 4 hours ago · details
0 5/10
vulnerability

A critical rounding convention bug in Vesu's Singleton liquidation contract allowed attackers to steal user funds through malicious pool extension contracts, flashloans, and improper handling of the receive_as_shares flag. The vulnerability was discovered via Immunefi bug bounty, remediated by removing the affected liquidation logic and whitelisting pool extensions within 5 days.

Vesu Immunefi ChainSecurity Argent Labs Re7 Labs Braavos Alterscope
docs.vesu.xyz · Alex · 4 hours ago · details
0
github.com · deadrosesxyz · 4 hours ago · details
0
bug-bounty
github.com · ABDul Rehman · 4 hours ago · details
0
bug-bounty
github.com · ABDul Rehman · 4 hours ago · details
0
bug-bounty
github.com · MiloTruck · 4 hours ago · details
More