White Hat Hackers Earn $32,000 for Finding Crypto Security Exploits in Last Two Months

Published at: May 20, 2019

White hat hackers have earned $32,000 in bounties over the last two months by reporting security holes in crypto and blockchain projects, according to a report by Hard Fork on May 20.

This lump sum of over $30,000 was distributed by 15 firms from March 28 to May 16 and documented in 30 public bug reports, per the article.

The rewards for a single discovery can differ depending on how damaging the exploit is. Hardfork noted that most of the bounties awarded by blockchain-driven firm OmiseGo were around $100; EOS company Block.one and the blockchain startup Aeternity, however, issued $10,000 individual rewards over the course of these two months.

Tron reportedly paid $3,500 to a hacker who found a vulnerability that could have crashed its entire blockchain. A following disclosure about the vulnerability stated that an attacker could have filled up the available memory on a computer and perform a Distributed Denial of Service attack on Tron’s network by using malicious code in smart contracts.

Major crypto exchange Binance also offers up to $10,000 per project for “P1: Critical” fixes, with a maximum reward of $100,000 in Binance Coin (BNB) per user. Binance classifies P1 in accordance with the Bugcrowd’s Vulnerability Rating Taxonomy.

As previously reported by Cointelegraph, white hat hackers earned $878,000 bounties for finding crypto bugs in 2018. Within that sum, major crypto exchange Coinbase reportedly spent $290,381, while Tron paid $76,200.

Tags
Eos
Related Posts
Report: Over 40 Bugs in Blockchain and Crypto Platforms Detected Over Past 30 Days
White hat hackers have detected over 40 bugs in blockchain and cryptocurrency platforms over the past 30 days, tech news outlet The Next Web (TNW) reported on March 14. According to an investigation conducted by TNW, 13 blockchain- and cryptocurrency-related companies were hit with a total of 43 vulnerability reports from Feb. 13–March 13. In the blockchain field, e-sports gambling platform Unikrn reportedly got the most vulnerability reports, amounting to 12 bugs. Unikrn is followed by OmiseGo developer, Omise, having received six bug reports. In third place is EOS, with five vulnerability reports. Consensus algorithm and peer-to-peer (P2P) networking protocol …
Blockchain / March 14, 2019
Report: Blockchain-related hacks have declined in 2020
The amount of cryptocurrency and blockchain-related hacks has been decreasing over the course of 2020, a new report claims. According to data analyzed by VPN provider Atlas VPN, the number of hacks in the first half of 2020 dropped more than three times compared to the same period in 2019. The data is part of a report released by Atlas VPN on Oct. 28. According to Atlas VPN, 2019 was a record-breaking year for blockchain hackers that exploited 94 successful attacks in the first half of the year, while in H1 2020 there were 31. Per the report, 2019 as …
Technology / Nov. 2, 2020
PIVX, Possibly Other PoS Chains Vulnerable to Bug, Attackers Profit
Private transactions cryptocurrency PIVX and over 200 other blockchains are vulnerable to attackers obtaining disproportionately high staking rewards. A major staking vulnerability Cryptocurrency consulting firm Lunar Digital Assets claimed in a post published on its website on Aug. 12 that a staking vulnerability is being used across PIVX and its forks. The weakness reportedly allows the attacker to obtain mathematically impossible staking rewards on vulnerable proof-of-stake (PoS) chains. According to the post’s author, the PIVX development team claimed to have solved the issue in January. Nonetheless, a core developer of PoS altcoin BitGreen (BITG) noticed that the vulnerability in question …
Blockchain / Aug. 13, 2019
‘Blockchain Bandit’ Has Stolen 45,000 ETH by Guessing Weak Private Keys, Report Claims
A “blockchain bandit” has managed to amass almost 45,000 ether (ETH) by successfully guessing weak private keys, according to a report released by Independent Security Evaluators on April 23. Adrian Bednarek, a senior security analyst, said he discovered the sophisticated hacker by accident. While guessing a private key is meant to be a statistical improbability, he managed to uncover 732 private keys through his research — giving him the ability to complete transactions as if he was the account holder. The report notes that rather than using a brute force search for random private keys, it used a combination of …
Blockchain / April 23, 2019
Five Critical Vulnerabilities Discovered in EOS in 2019, HackerOne Data Shows
EOS.io, the company responsible for the development of fourth-largest crypto by market cap EOS, has handed over bug bounties for five critical vulnerabilities this year. Public activity on breach disclosure platform HackerOne revealed the bounties. On Jan. 10, $40,750 was awarded to five white hat hackers on the platform by EOS.io, and the day after, another researcher received a $10,000 bounty. Five of those bounties are equivalent to $10,000 each, which is the highest possible payout reserved by the company only for the most critical vulnerabilities. The Tron Foundation, the company behind the cryptocurrency Tron, also awarded four bounties in …
Altcoin / Feb. 5, 2019