Cointime

Download App
iOS & Android

Crypto Bug Bounty Hunting: An Overview Since 2020

By Harvesto Orlando

Crypto used to be all about trading and hodling alt and shitcoins in the hopes of mooning. However, a growing number of people are making money off crypto — not in the usual way of HODLing or day trading — but through “bounties” hosted by crypto platforms. One such bounty is bug hunting, which has become quite popular recently with the rise of DeFi and the DeFi hacks ensued.

According to Cointelegraph, “the hacks have skyrocketed demand for blockchain security experts, with some auditors making upwards of $430,000 annually.” Fortunately for auditors and security experts in developing countries, crypto bounty hunting is becoming a highway out of poverty and mediocrity.

But then, how did it all start? How did the industry make this transition in just two years? The story can be traced back to 2017/2018, when Bounty0x, Gitcoin, and other bounty hosting platforms allowed bounty hosts to post bounties paid out in any cryptocurrency, such as Ethereum, stablecoins, or other tokens.

These bounties ranged from spotting vulnerabilities in general code to marketing services such as writing content and tweets. However, the focus started shifting with the emerging popularity of the Ethereum blockchain and its smart contracts. Soon projects started building on Ethereum, and there was an influx of dapps into the market.

This breakneck development soon led to complications — developers built the dapps with Ethereum code, which could be hacked or exploited. So began an infamous chain of dapp and smart contract attacks, all in a bid to drain their funds. We all are familiar with the DeFi summer of 2020. That year, nearly $100 million was lost due to bugs, exploits, and hacks. The protocols recovered some losses, but the hacks affected the industry’s outlook.

Projects like YAM, Soft yearn, bZx, Harvest, and Akropolis suffered losses in hundreds of thousands and millions. Some of these hacks were orchestrated by hackers who wanted to prove a point — that the protocols’ code base or security was insecure and they could get away with the hacks.

Enter Immunefi in December 2020.

The idea was to incentivize white hackers to safeguard protocols by finding and reporting exploitable bugs in the ecosystem. The idea quickly caught fire; Immunefi secured partnerships with scores of protocols, gained the DeFi community’s trust and onboarded many white hackers.

By the fall of 2021, Immunefi was reportedly responsible for protecting more than $50 billion in protocol assets from projects such as Synthetix, Chainlink, SushiSwap, and PancakeSwap. In addition, the OG bug bounty platform had paid more than $7.5m in bug bounties.

One of the most popular bugs found was on the Polygon network and was reported to have been at risk of $850 million being exploited. The bug was found by an Immunefi hacker, Gerhard Wagner, who promptly reported it and received a $2 million payout.

According to research undertaken by Immunefi, DeFi-related hacks and exploits have cost the sector over $10.2 billion. 2022 has had its fair share of hacks, from the Axis Ronin Bridge hack of about $600m to the Solana hack to the recent $160m Wintermute exploit.

These hacks all mean that the DeFi, crypto space still needs to be safeguarded. Immunefi has acted promptly by raising $24,000,000 to boost its security capabilities, a giant leap from its $5m 2021 raise. Immunefi claims to have paid over $60 million in total bounties since its December 2020 debut.

The platform also supports over 300 DeFi and crypto projects, including Big Names, Chain link, MakerDAO, and Compound while protecting $100 billion in assets. Note that there are other bug bounty platforms like Hackenproof and bugbounter, but Immunefi stands above them.

Comments

All Comments

There are no comments yet, why not be the first?

Recommended for you

  • RedotPay Completes $40 Million Series A Funding, Led by Lightspeed

    On March 14th, according to an official announcement from RedotPay, it has completed a $40 million Series A financing round, led by Lightspeed with participation from HSG, Galaxy Ventures, DST Global Partners, Accel, Vertex Ventures, and others. This round of financing will be used to accelerate the expansion of global encrypted payment solutions.

  • Surveillance technology company Flock Safety receives $275 million in funding led by A16z

    Flock Safety, a surveillance technology company based in Atlanta, has completed a $275 million financing round led by Andreessen Horowitz (A16z), with a company valuation reaching $7.5 billion. Other participants in this round of investment include Greenoaks Capital and Bedrock Capital.

  • Trump's crypto project WLFI has completed its public offering, with a total financing amount of US$550 million

    according to the official website, the Trump family's encrypted project World Liberty Financial has completed all community public offering financing (previously added an additional round), with a total financing amount of $550 million.

  • nunu.ai Completes $6 Million Seed Round, Led by TIRTA Ventures and a16z Speedrun

    according to official news from nunu.ai, the company has completed a $6 million seed round of financing, led by TIRTA Ventures and a16z speedrun, with other investors including Factorial Funds, Y Combinator, Earthling, Hartmann Capital, FOV Ventures, and New Renaissance Ventures.

  • South Korea plans to issue new guidelines in Q3 to lift ban on institutional cryptocurrency investments

    South Korean financial regulatory agency announced on Wednesday that it plans to release comprehensive guidelines for institutional cryptocurrency investments in the third quarter. The Financial Services Commission made this announcement during a meeting with local cryptocurrency industry experts. While investment guidelines for listed companies and professional investors are expected to be introduced in the third quarter, the Financial Services Commission stated that its goal is to release investment guidelines for non-profit organizations and cryptocurrency exchanges in April. The Financial Services Commission first announced in January that it would gradually lift the ban on institutional investors investing in cryptocurrencies. Last month, the regulatory agency revealed that it intends to first allow charities and universities to sell their cryptocurrency assets in the second quarter. The upcoming detailed guidelines further solidify South Korea's shift in stance towards cryptocurrencies, no longer strictly opposing the entry of crypto assets into traditional financial markets.

  • Transaction Agreement Vest Completes $5 Million Financing, with BlackRock, Jane Street Group and Others Participating

    On March 12th, Vest, a trading agreement, announced the completion of a $5 million financing round, with participation from BlackRock, Jane Street Grop, Selini Capital, Amber Group, QCQ Group, and Big Brain VC. 

  • Deutsche Börse’s Clearstream to Start Offering Bitcoin, Ethereum Custody Services in April

    Clearstream, the post-trade division of Deutsche Boerse, announced that it will start providing cryptocurrency settlement and custody services for institutional clients in April this year.

  • Citi: Downgrade US stocks to neutral, upgrade China stocks to overweight

    Citigroup's strategist has downgraded the rating of the U.S. stock market from overweight to neutral, while upgrading the rating of the Chinese stock market to overweight, citing that "the U.S. exceptionalism has at least been suspended."

  • WLFI's investment portfolio has lost $110 million, with ETH accounting for 65% of the entire portfolio

    According to on-chain analyst Yu Jin's monitoring, the investment portfolio of WLFI has currently lost 110 million US dollars. The 9 types of tokens purchased for 336 million US dollars are now worth only 226 million US dollars. Because ETH accounts for 65% of the entire investment portfolio, it is also the biggest loser: the average cost of ETH is $3,240, and the current price is $2,000. The loss is as high as 80.85 million US dollars (-37%). Surprisingly, the one that has dropped the least is Sun Ge's TRX: it has only dropped by 5% since being bought from WLFI.

  • Web3 data and AI company Validation Cloud completes $10 million in new round of financing

     Web3 data and AI company Validation Cloud announced a $10 million financing round from True Global Ventures. The company plans to use the funds to expand its AI products and achieve seamless access to Web3 data.