LoopGhost

269 posts

LoopGhost

LoopGhost

@LoopGhost007

Doing my best to protect web3 protocols.

Joined Ağustos 2025
206 Following95 Followers
LoopGhost
LoopGhost@LoopGhost007·
@MitchellAmador @theonejvo I also want to apologize for my part in the situation. Even if I didn’t always feel fairly treated, I recognize that I did not fully comply with the rules either. If you’re willing to request a re-evaluation of my case, I would genuinely appreciate it.
English
0
0
0
13
LoopGhost
LoopGhost@LoopGhost007·
@MitchellAmador @theonejvo I’m happy to provide examples of this work if helpful, so you or the team can evaluate my current level and mindset. I understand the importance of the rules and the role they play in keeping the ecosystem sustainable. I’m committed to fully adhering to them going forward.
English
1
0
0
12
Jamieson O'Reilly
Jamieson O'Reilly@theonejvo·
Yup. Bug bounty is dead AF in this sense. I know multiple people at this point who have reported national security level issues (not exaggerating) via programs only to have some mouth breathing, reddit mod worthy triage team member flag it as out of scope. In multiple of these cases, the original finder reported it directly to said effected party (Govt/defence) and very quickly it was treated with the significance it deserved. They will keep doing this to keep churn down as their business model isn't ready to scale for AI bug finding. But once the third-world hunters (who are being exploited for low payouts) dry up, it's GG.
sujith@sujithsomraaj

My bug bounty: not a vuln, requires all DVNs Their deployment: removes the ‘all’ part Hackers: collects $295M bounty instead

English
8
2
71
13.2K
LoopGhost
LoopGhost@LoopGhost007·
@MitchellAmador @theonejvo Simple steps like a small submission fee, for example $5, and a fair review of past bans could significantly improve the platform and rebuild trust across the community.
English
1
0
0
27
LoopGhost
LoopGhost@LoopGhost007·
@MitchellAmador @theonejvo The goal should be to facilitate responsible disclosure, not discourage it. Fixing edge cases is not easy, but it is necessary.
English
1
0
0
15
LoopGhost
LoopGhost@LoopGhost007·
@MitchellAmador @theonejvo Real whitehats are getting non-sense bans again and again. Some of them will directly disclose to the projects, but some others may turn blackhats. You should take care of the projects listed on Immunefi. Your policies are putting them at a critical risk of being exploited.
English
1
0
0
24
LoopGhost
LoopGhost@LoopGhost007·
@MitchellAmador @theonejvo The web3 bug bounty space is full of unfairness, and your platform is the main reason for it. I’ve found huge criticals on blockchain/dlt BBPs outside Immunefi since you banned me. Still you don’t want me in your platform. The projects on Immunefi are at risk of exploitation.
English
2
0
0
41
LoopGhost retweeted
TradeLots
TradeLots@tradelots·
@LoopGhost007 @0xMSF14 @immunefi This 👆🏽 i also know of researcher banned because their first few submissions were closed as not valid. And this is a researcher established in Web2 research with many CVEs to their name
English
0
1
1
46
LoopGhost
LoopGhost@LoopGhost007·
@0xMSF14 @immunefi I totally agree, they are massively banning real researchers just because none of their first 3 reports were marked as valid (in some cases marked as invalid even though they were valid). I’m banned, and in the last 3 months I’ve secured HUNDREDS OF MILLIONS in Blockchain BBPs
English
1
0
0
128
Mx (beta)
Mx (beta)@0xMSF14·
I don't know what happened to @immunefi but they are partly responsible for the surge in hacks in 2026. People may want to submit a critical vulnerabilities and you are asking them to submit KYC information first ? to limit "spam". What happens if they don't want to ?
English
9
5
99
7.1K
sashko.eth🇺🇦
If your goal was to make $1M from bug bounties in 2026 you might want to move faster. @infsec_io is already halfway there… and that’s only counting submissions on HackenProof 👀 The pace this year is different.
HackenProof@HackenProof

$500,000 to @infsec_io — what a legend move, Respect 🫡🔥 Half a million for a single valid find, climbing straight to #4 on the leaderboard! Huge congrats from the entire HackenProof team 🎉

English
2
3
56
3.1K
LoopGhost retweeted
playboi.eth
playboi.eth@adeolRxxxx·
@hyperbridge, you said I should hack you, yh? x.com/hyperbridge/st… Well, unfortunately, I did not hack you, but I have a list of bugs, and this was the 3rd on my list. @seunlanlege It is better that you pause this bridge indefinitely.
playboi.eth tweet media
English
28
11
128
5.5K
LoopGhost
LoopGhost@LoopGhost007·
@LuxLode They wanted to get hacked, check out this recent tweet. They got what they were looking for!
English
1
0
1
602
lodelux
lodelux@LuxLode·
> Only 1 audit. > No public Bug Bounty Program. > Overly confident marketing. Gets hacked. Feel sorry for the users and the team, but this should be once again a sign to take security more seriously.
English
2
6
57
7.8K
playboi.eth
playboi.eth@adeolRxxxx·
You bluff too much for a bridge that has undergone only one audit, which is currently live onchain. I hope you learn from products who has 10 and still got hacked.
English
4
4
74
12.4K