This turned out to be worse than I thought.
1. The company behind v12 was a security vendor for Thorchain, did a security audit in January 2025 for one of their components, and hosted a bug bounty for a thorchain application up until recently!
2. Thorchain paused their bug bounty after being unable to handle the volume of submissions (h/t
@QED_Audit for the screenshot). An unfortunate trend for anyone with a bounty in 2026 (curl and many others have publicly spoken about this).
3. Getting denied on a bounty sucks. Every security researcher in the last 20 years will tell you a story of an unfair bounty. You find another target and move on. The pie is bigger than you think. It's not okay to extort, i.e., threaten to release more bugs in public, if they don't pay. It's even more egregious when its a former customer!