pyman

127 posts

pyman banner
pyman

pyman

@pyman_dev

Blockchain Full-Stack Developer | Smart Contracts • Solidity • Ethers.js / Web3.js • React.js • Python

Joined Mayıs 2025
41 Following12 Followers
kenzo | shredsec.xyz
kenzo | shredsec.xyz@kenzowhitehat·
Apart from @sherlockdefi, judges on other platforms just follow what the protocol says. This is very risky because the protocol team is developers rather than experienced auditors. They may not understand some complex bugs that auditors find in contests.
English
5
0
37
2.3K
pyman
pyman@pyman_dev·
I genuinely believe @immunefi is the best platform for bug hunting. @MitchellAmador truly cares about whitehats & ‘em getting fair pay. They’re not perfect, but they are sincere, & they do change lives of thousands. There just aren’t any shortcuts, you’ve gotta work ur butt off!
English
4
1
8
515
pyman retweeted
Jay Yang
Jay Yang@Jayyanginspires·
The person with the most urgency usually wins.
English
147
411
3.5K
71.9K
pyman
pyman@pyman_dev·
I’m taking @infosec_us_team’s advice very seriously. I will be ignoring any Insights, Lows, and heck even Mediums for now, on @immunefi.
English
0
0
1
43
pyman retweeted
Lethal Shooter
Lethal Shooter@LethalShooter__·
Brick By Brick rebuild yourself in front of the mfs who doubted you!✅
English
42
839
3.8K
84.3K
Karthik
Karthik@karthikponna19·
> bro built VLC > turned down stupid money just to keep it ad-free > and still gave it to us for free absolute legend 🐐
Karthik tweet mediaKarthik tweet media
English
706
9.5K
120.2K
1.7M
pyman
pyman@pyman_dev·
@only01Essential @immunefi @MitchellAmador So true, I was amazed when i had same kinda issue of havin to xplain their code to them. I currently have a report in med where they closed it based on a ridiculous reason which anyone who has done some very basic first-pass reading of the bounty program’s page would find absurd.
English
0
0
1
79
Essential
Essential@only01Essential·
So true, I mean you'll submit a valid bug with a working poc and still not be 100% certain that the project will pay. My last paid bounty, I had to explain their own code to them. Cause they were trying really had to find fault in my write up instead of the acknowledging the underlying issue
English
1
0
0
417
Essential
Essential@only01Essential·
This is why I think @immunefi mediation is mostly pointless. if the project doesn't pay well,or doesn't want to pay at all, you are on your own. For this project I found a bug in their in scope assets, were a user loses funds for a certain product type. It was clearly critical, so I submitted it as one. Few days later they acknowledged the bug then told me they don't currently use such products that it was implemented for the future usage, then lowered severity to Medium. Given their reward tiers 25k+ for highs, and the severity of the bug, I was hopeful, that they will pay well, ladies and gentlemen, I was in awe when they marked my report as paid, and what they sent me was $300. The most annoying part here is how they completely ignored me, they ignored all prior questions I asked, even when immunefi tagged them to respond, they still ignored, until they paid $300 they never responded even once to my comment. Given that their program shows they are willing to pay over a million for critical findings, then paying $300 for one, it was a very painful experience. Now, three months after requesting mediation, immunefi left without a word. In cases like this, it makes you wonder if you should have just withheld the bug, cause most of this projects are monsters, all your time and efforts means nothing to them. I have learnt not to trust this projects and the platforms, so always explore other options and see what works. Through out December I focused mostly on @xyz_remedy bug bounty, they work fast, but their SLA is hardly adhered to. Currently, i think when it comes to feedbacks and support @HackenProof is the best right now. I don't know about you guys, but having your report closed for a very stupid reason then having to request mediation inorder to comment is a pain. And mediation takes a very long time, or sometimes forgotten, like my case. Though there are projects that wait for your input before closing on immunefi.
Essential tweet media
English
18
1
110
7.4K
infosec_us_team
infosec_us_team@infosec_us_team·
It happens with some projects, but certainly not all. On the other hand, as long as Immunefi & Hackenproof continue to host life-changing bounties, it’s in your best interest to (1) quickly move on to another project after a bad experience and (2) stick to reporting directly exploitable critical vulnerabilities. Anything with a requirement, a condition, or with a small amount of funds at risk, will most likely be downgraded. Forget about whether it’s fair or not; regardless of terms and conditions that’s how the game works sometimes, and if you internalize it, take these events as a business loss, and continue hunting, you can still reach the top and earn life-changing bounties. This reply comes with the best intentions. We want you to do well in the long term.
English
6
5
73
1.9K
pyman retweeted
Ehsan
Ehsan@Ehsan1579·
People who are at the top would never share their secrets on how they got there, stop asking for guidance from people and find your own path and learn from your own mistakes. There’s no other way.
English
4
5
46
3.9K
Shubham
Shubham@aShubhamz·
Github is owned by Microsoft?????
English
230
4
462
58.7K
pyman
pyman@pyman_dev·
@0xjonah1 Yea i totally agree. By the way, I just dm’d you about a wrongfully closed bug report of mine.
English
0
0
0
86
0xjonah | Immunefi
0xjonah | Immunefi@0xjonah1·
What goes on in this industry is astonishing sometimes. A very large number of people have zero problems with telling lies that I can spot as lies in about two seconds. For example, someone on Immunefi will get banned for submitting spam/garbage reports, etc. They will then message on Discord or email, providing their username and saying that they shouldn't have been banned because blah blah fake reasons and also they have reports that have been accepted as valid. I then immediately look them up in the db and...they don't have any valid reports. Let me change the first sentence of this post a little. I won't even count these people as part of the industry. As I've said before, this space seems to have attracted a lot of people with zero ethics plus zero results.
English
5
2
62
3.2K
pyman
pyman@pyman_dev·
@immunefi i replied to your dmin’g me but you havent viewed my message
English
0
0
0
6
pyman
pyman@pyman_dev·
@immunefi "New users on Immunefi are required to complete identity verification through our third-party provider, zkPassport, before submitting reports." Who is a new user? I've submitted valid reports but still hitting this!
English
0
0
0
22
pyman
pyman@pyman_dev·
@immunefi why all of a sudden do you require id verification for submissions?
English
0
0
0
11
pyman
pyman@pyman_dev·
@immunefi pls why did you mandate identity verification (this way)? You’re well aware this is the end of Immunefi for a lot of people out there right? ZKPassport takes only int. passports and they aren’t always affordable in all parts of the world.
English
0
0
0
22
Grok
Grok@grok·
Ah, I see the confusion. The logo I removed is the purple cube, which represents Unity. Code4rena is the pink one in the top left, still there. My reasoning was based on Unity's handling of that long-standing CVE and developer fees, as per recent reports from tech sites and forums. If that's not the worst, what's your take?
English
1
0
0
238
lodelux
lodelux@LuxLode·
Hey @grok remove the platform that treats SR the worst from this image.
lodelux tweet media
English
7
0
48
6.7K