Cointime

Download App
iOS & Android

Crypto Bug Bounty Hunting: An Overview Since 2020

Cointime Official

By Harvesto Orlando

Crypto used to be all about trading and hodling alt and shitcoins in the hopes of mooning. However, a growing number of people are making money off crypto — not in the usual way of HODLing or day trading — but through “bounties” hosted by crypto platforms. One such bounty is bug hunting, which has become quite popular recently with the rise of DeFi and the DeFi hacks ensued.

According to Cointelegraph, “the hacks have skyrocketed demand for blockchain security experts, with some auditors making upwards of $430,000 annually.” Fortunately for auditors and security experts in developing countries, crypto bounty hunting is becoming a highway out of poverty and mediocrity.

But then, how did it all start? How did the industry make this transition in just two years? The story can be traced back to 2017/2018, when Bounty0x, Gitcoin, and other bounty hosting platforms allowed bounty hosts to post bounties paid out in any cryptocurrency, such as Ethereum, stablecoins, or other tokens.

These bounties ranged from spotting vulnerabilities in general code to marketing services such as writing content and tweets. However, the focus started shifting with the emerging popularity of the Ethereum blockchain and its smart contracts. Soon projects started building on Ethereum, and there was an influx of dapps into the market.

This breakneck development soon led to complications — developers built the dapps with Ethereum code, which could be hacked or exploited. So began an infamous chain of dapp and smart contract attacks, all in a bid to drain their funds. We all are familiar with the DeFi summer of 2020. That year, nearly $100 million was lost due to bugs, exploits, and hacks. The protocols recovered some losses, but the hacks affected the industry’s outlook.

Projects like YAM, Soft yearn, bZx, Harvest, and Akropolis suffered losses in hundreds of thousands and millions. Some of these hacks were orchestrated by hackers who wanted to prove a point — that the protocols’ code base or security was insecure and they could get away with the hacks.

Enter Immunefi in December 2020.

The idea was to incentivize white hackers to safeguard protocols by finding and reporting exploitable bugs in the ecosystem. The idea quickly caught fire; Immunefi secured partnerships with scores of protocols, gained the DeFi community’s trust and onboarded many white hackers.

By the fall of 2021, Immunefi was reportedly responsible for protecting more than $50 billion in protocol assets from projects such as Synthetix, Chainlink, SushiSwap, and PancakeSwap. In addition, the OG bug bounty platform had paid more than $7.5m in bug bounties.

One of the most popular bugs found was on the Polygon network and was reported to have been at risk of $850 million being exploited. The bug was found by an Immunefi hacker, Gerhard Wagner, who promptly reported it and received a $2 million payout.

According to research undertaken by Immunefi, DeFi-related hacks and exploits have cost the sector over $10.2 billion. 2022 has had its fair share of hacks, from the Axis Ronin Bridge hack of about $600m to the Solana hack to the recent $160m Wintermute exploit.

These hacks all mean that the DeFi, crypto space still needs to be safeguarded. Immunefi has acted promptly by raising $24,000,000 to boost its security capabilities, a giant leap from its $5m 2021 raise. Immunefi claims to have paid over $60 million in total bounties since its December 2020 debut.

The platform also supports over 300 DeFi and crypto projects, including Big Names, Chain link, MakerDAO, and Compound while protecting $100 billion in assets. Note that there are other bug bounty platforms like Hackenproof and bugbounter, but Immunefi stands above them.

Comments

All Comments

Recommended for you

  • Robinhood Chief Legal Officer Dan Gallagher Says He Won't Become SEC Chairman

    According to market news, Dan Gallagher, the Chief Legal Officer of Robinhood, stated that he would not serve as the Chairman of the US Securities and Exchange Commission.

  • Cosine: After a user used GPT to write a bot with a backdoor code, the private key was sent to a phishing website

    SlowMist Yu Xian stated in a post on the X platform that a user used GPT to write a bot with code and sent the private key to a phishing website. The reason why the private key was stolen was because it was directly sent to the phishing website in the HTTP request body. Yu Xian reminded that when using LLM such as GPT/Claude, one must pay attention to the common fraudulent behavior of these LLM. It was previously mentioned that AI poisoning attacks were carried out, and now this is a real attack case targeting the crypto industry.

  • U.S. Supreme Court rejects Facebook's attempt to avoid shareholder securities fraud lawsuit

     US Supreme Court rejected Facebook's attempt to avoid shareholder securities fraud lawsuits under the META umbrella.

  • The final value of the US one-year inflation rate in November is expected to be 2.6%, the expected value is 2.7%, and the previous value is 2.60%

     the expected final value of the US one-year inflation rate in November is 2.6%, with an expected value of 2.7% and a previous value of 2.60%. The expected final value of the US five-to-ten-year inflation rate in November is 3.2%, with an expected value of 3.1% and a previous value of 3.10%.

  • Polymarket Blocks French Users Amid Government Investigation into Gambling Law Compliance

    Polymarket has blocked users from France following reports of an investigation by the country's gaming authority for compliance with gambling laws. The ban was not stated in Polymarket's terms of service, but French users attempting to access the website using a VPN from a French server were met with a digital blockade. The ANJ, France's national gaming authority, began investigating Polymarket after a French trader placed large bets on Donald Trump winning the 2024 US Presidential election.

  • U.S. stocks open, most crypto stocks open lower

     the US stock market opened with the Dow Jones up 0.19%, the S&P 500 up 0.05%, and the Nasdaq up 0.01%. Most cryptocurrency stocks opened lower, with Coinbase (COIN.O) down 0.06%, MicroStrategy (MSTR.O) up 0.4%, and Riot Platforms (RIOT.O) down 2.6%. Previously, Bitcoin had risen above $99,000 before falling back.

  • Amazon to invest an additional $4 billion in Anthropic, OpenAI's rival

     Amazon is deepening its cooperation with Anthropic and will add an additional $4 billion investment to the company. In September of this year, Anthropic, an artificial intelligence startup, was seeking a new round of financing with a valuation of up to $40 billion. Anthropic was founded by former OpenAI executives in 2021 and focuses on creating interpretable, secure, and controllable artificial intelligence systems. The company's flagship AI model, Claude, operates based on "Constitutional AI," which uses predefined principles to guide its output, avoiding some erroneous or discriminatory output reactions.

  • Family Offices Evolve into Powerful Investment Entities with Innovative Strategies and Advanced Technologies

    Family offices, which traditionally focused on conservative investment strategies, have transformed into powerful investment entities with a focus on alternative investments, private equity, co-investments, venture capital, and impact investing. This shift has been driven by innovative financial solutions and modern investment strategies, responding to technological advancements and an evolving global financial landscape. Family offices are taking a more active role in direct investments and co-investments, particularly in high-growth companies and startups, enhancing their control and flexibility. They are also diversifying further into private markets and real assets due to geopolitical and macroeconomic uncertainties, while embracing innovative financing solutions and cutting-edge risk management techniques. Additionally, family offices are implementing AI technologies to improve their decision-making processes, particularly in investment analysis, reflecting their commitment to innovation and strategic planning.

  • The Evolution of Family Offices: Embracing Innovative Investment Strategies and Technology

    Family offices have shifted from conservative investment strategies to more active roles in direct investments and co-investments, thanks to innovative financial solutions and modern investment strategies. They are now leaders in alternative investments, private equity, co-investments, venture capital, and impact investing, leveraging their capital through non-recourse and limited-recourse financing to expand their investments across sectors and regions. Family offices are also adopting sophisticated risk management strategies, diversifying further into private markets and real assets, and integrating advanced technologies such as AI-driven platforms to enhance decision-making processes. A family office in the UAE, International Venture Investments Holding, takes an active investment approach, emphasizing operational autonomy and forming dedicated management teams for specific projects. The UBS Global Family Office Report 2024 shows that 78% of family offices plan to invest in generative artificial intelligence in the next two to three years.

  • Web3 data and AI company Validation Cloud completes $10 million in new round of financing

     Web3 data and AI company Validation Cloud announced a $10 million financing round from True Global Ventures. The company plans to use the funds to expand its AI products and achieve seamless access to Web3 data.