bug-bounty498
google352
xss301
microsoft295
facebook262
rce211
exploit199
malware171
apple163
cve136
account-takeover115
bragging-post102
privilege-escalation95
csrf90
phishing86
browser75
writeup74
authentication-bypass69
supply-chain67
dos66
stored-xss65
reflected-xss57
ssrf56
reverse-engineering55
react52
access-control52
input-validation49
cross-site-scripting48
aws47
cloudflare47
docker46
web-security46
lfi46
sql-injection45
smart-contract45
web-application44
ethereum44
web343
ctf43
oauth43
node43
defi43
pentest40
race-condition39
open-source38
cloud37
idor37
info-disclosure36
burp-suite36
vulnerability-disclosure35
0
7/10
vulnerability
A critical infinite spend vulnerability in Aurora's Rainbow Bridge allowed attackers to withdraw unlimited ETH by exploiting DELEGATECALL context confusion, potentially exposing 70k ETH and $200m in assets. The bug was responsibly disclosed for a $6 million bounty payout.
smart-contract-vulnerability
delegatecall
infinite-spend-bug
bridge-security
ethereum
near-protocol
aurora
rainbow-bridge
evm
responsible-disclosure
bug-bounty
precompiled-contracts
ether-handling
Aurora
Rainbow Bridge
Immunefi
pwning.eth
NEAR
Ethereum
ExitToNear
ExitToEthereum