Bug huntoor GoLang | Rust | Move | C++ | Solidity

analyzer
Meanwhile i saved ecosystem from a massive $800m hack and the team is offering me $4k. Whitehats lose everytime.
🚨 Breaking 🚨 ⚠️ The attacker behind the $11.58M Verus exploit has reportedly returned $8.6 million The exploiter kept around $2.8M as a bounty reward
317
154
4,980
1,261,425
After responsibly disclosing a critical bug report that could allow anyone to mint @Islamic_Coin out of thin air, the team behind @The_HaqqNetwork has decided to completely ghost me for months after receiving the bug reports 🤡 What's going on @ivanovp_ @vorobev_sa ? While at it, no matter what you do, don't bother disclosing any bug to @eCash
15
5
56
2,946
More to come 🫡
Another $15,000 bounty secured by @only01Essential 🏆 Over the past year, @only01Essential has earned a total of $38,400 across 6 valid reports on HackenProof. And there’s more to come 👀 Congrats from the HackenProof team – keep it going!
37
1
156
3,692
And the culprit is @DadeKuma Is this another @0xHE1M ?
If you don't know the current situation in @code4rena, here is the brief: Code4rena hosted K2 competition, which was the last one before announcing a winding down. After distributing rewards to participants and sending judging fees, two SRs, @MaxZuvex and @0xArav, found what appears to be a Sybil attack. They found that two wardens created their accounts days before the competition ended and submitted findings clearly copied from other wardens' work. One submission belonged to a less-duplicated issue group, which increases their profit, and the other one was a QA report that resembles another warden's QA report and got 1st place. Code4rena Team believes that the Judger is the one responsible for this, as he was one of the few people who had access to the submission before closing. Code4rena was able to recover funds from these 2 newly created accounts (propabbly as KYC process and newly created account payout delays). Code4rena asked the Judger to return the funds, but he has not responded to date. C4 head judge will review the issues, remove duplicate sybil issues, review QA reports, and post the final result, and wardens will receive the amount deducted from their reward.
17
2,153
Essential retweeted
We really appreciate all you have done to support us and the wider community @only01Essential
One of the best teams i have worked with off bb platforms so far 🙌🙌
2
5
3,130
Essential retweeted
AI for Web3 Security: Zero to Hero continues. Your first AI agent had a blind spot - it could read code but had no idea what it was supposed to do. Module 2 fixes that - and it's up now.
3
5
84
7,641
Return the 3,400 btc first, then follow up with the full force of the law let's see how it goes
To those responsible for the theft of bitcoin from the Liquid Network: Blockstream will not pay a ransom for the return of stolen funds. Taking assets without authorization and withholding their return is a crime, not responsible disclosure. It is not white-hat activity. It is theft. We have engaged in good faith in an effort to secure the return of stolen user funds and protect the broader Bitcoin community. That effort should not be mistaken for acceptance of the actions taken nor of the terms being demanded. We will not be a party to the precedent that open-source software developed for the good of the Bitcoin community should subject its developers to paying a ransom that far exceeds their economic participation. Bitcoin is hard money and can’t be minted without costs, Bitcoin doesn’t haircut users to pay a ransom. To the Bitcoin community: We are fighting for what we believe in, for the users whose funds were taken, and for the principles on which Bitcoin was built. The community has demonstrated incredible resolve with teams of people dedicating their time in support of each other to identify and patch vulnerabilities in each other's products and systems. We are all driven by the mission that Bitcoin is the single best asset, for every person, company, and institution on the planet to invest, use, and build on. The world is a different place with the advancements of AI, and the Bitcoin community has responded with force to combat that threat. Damage has been done, battles have been lost, but on the whole the Bitcoin community is gaining ground in the war with bad actors. We want to thank the community for those efforts, for your support in hardening the network, helping users recover funds, and for your support in our assertion that crime does not deserve rewards. To those holding the stolen bitcoin: There is still an opportunity to resolve this responsibly. The bitcoin can be returned and we can revert to the standard of white-hat principals. However, if the funds are not returned, we will pursue every lawful avenue available to us. We will work with law enforcement, exchanges, service providers, forensic specialists, and other relevant parties to trace and recover the assets and identify those responsible. More importantly, Bitcoin is transparent by design and the community is made up of the most sophisticated engineers, cryptographers, and white-hat hackers globally. Transactions do not disappear, and neither does the evidence they leave behind. We will not pay for the return of stolen property. We will not abandon our users. The Bitcoin community will not stop pursuing the funds. Return the bitcoin.
1
39
3,458
Just got paid $15k for two chain halt bugs 🔥 They're definitely among my favourite project teams now
39
10
319
8,864
Okay. Local AI models are too slow for actual security work. I’m running these models on a 128GB, 8TB M5 MacBook Pro, by the way
10
2
53
3,781
$50m for supposedly saving $320m 🔥🔥 Crazy!! While hunting in the wild. I have saved close to $1b in losses, by responsibly disclosing the bugs to the affected project team, but i have never earned $50k in bounty for any single bug report, and I have reported a bug with about $800m at risk, $123m and $54m, and other multiple minting class bugs. Notably @Islamic_Coin sat on a critical minting bug i reported for nine days until an attacker exploited it, they then fixed it and another bug i sent over. It has been radio silence for three months. There are multiple other such projects, but let me save that for another time. Given how well this went for the grey hat, I presume we will likely see more of those in the coming weeks. If you are seeing this and I have sent a critical bug report your way, please encourage me by paying me what the bug is worth 🙏
12
16
160
5,769
Essential retweeted
And here I am, having reported vulnerabilities throughout my career that could have resulted in a total of several billions (yes, with a B, > $2B) being *stolen*, while my total earnings are around $2M. So what's the lesson the industry is teaching researchers? That next time we should steal the funds first, then negotiate a "responsible disclosure," return 80–90%, and walk away with 10–20%? Obviously, no. But it's insane that the incentives can make that rhetorical question even possible. The bounty world is broken. Blackhats exploit a protocol and get treated like kings in negotiations. Meanwhile, whitehats disclose the exact same kind of vulnerability privately, prevent any damage from happening, and then spend months arguing with projects that try to downgrade the finding and pay the bare minimum. I'm fighting several cases like this right now. Millions of dollars protected, vulnerabilities responsibly disclosed, and yet projects still don't want to pay the amounts they themselves advertised. We should be making responsible disclosure the overwhelmingly obvious choice. Instead, the current state of Web3 is doing its absolute best to discourage whitehats while creating increasingly attractive incentives for blackhats and "grayhats". Those incentives are backwards, and eventually the ecosystem pays the price.
‼️ Self-proclaimed whitehat hackers used a vulnerability to drain Liquid Network of 4000 BTC ($320M USD) yesterday. Just now they've returned 3400 BTC and kept 600 BTC ($47M) as a 'bug bounty'. They've also 'responsibly' disclosed the vulnerability in a PGP-encrypted message.
42
72
591
39,750
Just doing the lord's work 🫡
8
50
1,640
Essential retweeted
i hate security disclosure so much. the number of companies that take our work for granted is insane. how about you talk to us collaboratively from the start instead of being asinine about it? like, give us some respect, bro. we worked on this shit for weeks/months and showed you something that could have become a massive disaster if a bad guy finds it, and you don’t even seem to give a fuck and see us like some villains?
16
39
522
93,265
Essential retweeted
Heads up for anyone writing Rust today. The Rust Security Response Team just disclosed a supply chain attack. The popular arrayref crate was republished to pull in a malicious dependency that downloaded a payload through its build script. arrayref isn't obscure. If you or your dependencies pulled it recently, you'll want to check now. The malicious versions to look for: > arrayref 0.3.10 > internment 0.8.7 > append-only-vec 0.1.9 > proc-macro1, plus typosquats: proc-macro-en, aovine, arone, aronenao, tinymember All deleted from crates.io, and the maintainer's account is locked. The team believes the author's credentials were compromised rather than the author acting maliciously. Full advisory, including the one-line command to scan your local cargo cache: blog.rust-lang.org/2026/08/2…
6
50
155
14,174
Besides ornit ai, that was a bit helpful, no other small open weight model has impressed me in terms of web3 security. I will try this out then see if it'll live up to the hype
Qwen 3.8 27B weights and benchmarks are now out This thing in full precision would fit on a single RTX PRO 6000 and beats Opus 4.6 Max in several benchmarks SoTA at home
1
22
1,848
Around $18k in bounties for three new Critical bug reports that have now been fixed. It took about three weeks to get here, but I really appreciate how responsive the whole team was.
21
4
211
7,415
One of my many pending Reports just paid. $30k total. 20k for a critical bug report, and another $10k(not done yet) for a private engagement. One of the best teams that I have ever worked with, more details in a few weeks.
26
6
182
3,572
Found a bug in @NibiruChain and they are posting me in a branch product. I found and reported a serious chain halt bug in nibiru, which they fixed, then they claimed it was a cosmos bug and thus not going to pay for it, I have never seen a more pathetic excuse than this: github.com/NibiruChain/nibir…
Shoutout to @only01essential for being an active member in the Sai community. From finding bugs to helping strengthen the platform, your contributions don't go unnoticed!
9
3
69
11,643