disclosure

3 articles
sort: new top best
clear filter
0 7/10
bug-bounty

A logic error in Tidal Finance's staking contract on Polygon allowed attackers to claim unearned rewards by exploiting improper state management in the payout process, where user.rewardDebt remained zero after a finalized payout. The vulnerability was patched by moving a critical rewardDebt update line earlier in the execution flow.

Tidal Finance Immunefi Csanuragjain Polygon
medium.com · csanuragjain · 23 hours ago · details
0 2/10
opinion

Opinion piece criticizing Balancer's bug bounty program practices, highlighting issues with delayed payments, reduced payouts, and poor communication with security researchers.

Balancer riptide
mirror.xyz · riptide · 23 hours ago · details
0 5/10

A reflected XSS vulnerability was discovered in eBay's mobile application through improper sanitization of the itemId parameter, allowing arbitrary JavaScript execution via crafted URLs. The vulnerability was manually identified through input tampering and successfully reported to eBay's security team.

eBay Matthew Bryant mandatory
thehackerblog.com · devanshbatham/Awesome-Bugbounty-Writeups · 23 hours ago · details