


ProofofBug
68 posts





@immunefi I need immediate intervention I submitted a valid bug (64228) to @FloeProtocol. They confirmed it, said they'd fix it "in the future," and closed without paying Then my account was banned by your anti-spam filter. They then shipped my exact fix, and blocked me on X.







@immunefi I need immediate intervention I submitted a valid bug (64228) to @FloeProtocol. They confirmed it, said they'd fix it "in the future," and closed without paying Then my account was banned by your anti-spam filter. They then shipped my exact fix, and blocked me on X.






Security is paramount at @injective and we take our bug bounty program very seriously. First and foremost, the figures referenced in the post are entirely misleading. There was no impact realized from this issue. Zero user funds were affected and zero addresses were compromised. For the stated vulnerability to work in practice, it would require execution of several suspicious transactions that would have an extraordinarily limited impact. Injective has dynamic rate limiting functionalities which are applied automatically based on our live monitoring systems. This functionality has been live on mainnet since last year and is publicly available in our code base. In addition to all of the above, this report was reviewed against the clearly defined terms of our Immunefi program. Based on those terms, issues such as those raised in this report that DO NOT impact block production or consensus are categorized outside of the Blockchain/DLT tier and carry a maximum payout of $50,000. If the poster had requested a mediation we would explain to him the dynamic rate limiters and monitoring systems we have in place and why his stated figures are misleading. However, he did not do so. We always follow the procedures set forth by the Immunefi program and expect the submitter to do so as well. We remain committed to fair, transparent, and consistent handling of all reports, and to maintaining the highest standards of security for the ecosystem. Injective has done so since its mainnet inception in 2021 and will continue to do so in perpetuity, always putting builders and security first.


