And here I am, having reported vulnerabilities throughout my career that could have resulted in a total of several billions (yes, with a B, > $2B) being *stolen*, while my total earnings are around $2M.
So what's the lesson the industry is teaching researchers?
That next time we should steal the funds first, then negotiate a "responsible disclosure," return 80–90%, and walk away with 10–20%?
Obviously, no. But it's insane that the incentives can make that rhetorical question even possible.
The bounty world is broken.
Blackhats exploit a protocol and get treated like kings in negotiations. Meanwhile, whitehats disclose the exact same kind of vulnerability privately, prevent any damage from happening, and then spend months arguing with projects that try to downgrade the finding and pay the bare minimum.
I'm fighting several cases like this right now. Millions of dollars protected, vulnerabilities responsibly disclosed, and yet projects still don't want to pay the amounts they themselves advertised.
We should be making responsible disclosure the overwhelmingly obvious choice.
Instead, the current state of Web3 is doing its absolute best to discourage whitehats while creating increasingly attractive incentives for blackhats and "grayhats".
Those incentives are backwards, and eventually the ecosystem pays the price.
‼️ Self-proclaimed whitehat hackers used a vulnerability to drain Liquid Network of 4000 BTC ($320M USD) yesterday.
Just now they've returned 3400 BTC and kept 600 BTC ($47M) as a 'bug bounty'. They've also 'responsibly' disclosed the vulnerability in a PGP-encrypted message.