H4x0r.DZ 🇰🇵

12K posts

H4x0r.DZ 🇰🇵 banner
H4x0r.DZ 🇰🇵

H4x0r.DZ 🇰🇵

@h4x0r_dz

Uber Driver

参加日 Aralık 2015
2.1K フォロー中77.9K フォロワー
固定されたツイート
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
My new writeup: 23000$ for Authentication Bypass & File Upload & Arbitrary File Overwrite @h4x0r_dz/23000-for-authentication-bypass-file-upload-arbitrary-file-overwrite-2578b730a5f8" target="_blank" rel="nofollow noopener">medium.com/@h4x0r_dz/2300…
English
127
612
2.7K
0
Karangwa
Karangwa@coolerme·
@h4x0r_dz Where is this place? 😳 look I am not XIA I promise.
English
1
0
0
169
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
I’m going to buy this large piece of land for $100,000, build my farm, and make my dream come true. living with chickens, cows, and sheep.
English
14
3
103
2.4K
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
@wld_basha هذه البلاصة رخيسة شوي لانو مكانش حتى خدمات قريبة ليها مكان لا غاز لا مدارس لا مستشفي
العربية
0
0
3
217
ناضي كناظي
ناضي كناظي@wld_basha·
@h4x0r_dz شحال تجيبلك من هكتار ١٠٠٠٠٠ دولار في جزائر ؟
العربية
1
0
1
227
YS
YS@YShahinzadeh·
Feb 24, 2026 08:35PM ➜ submited Feb 24, 2026 10:46PM ➜ report was triaged Feb 25, 2026 12:23PM ➜ bug patched Mar 17, 2026 02:55PM ➜ bounty awarded
YS tweet media
English
22
7
315
6.6K
IRIS C2
IRIS C2@C2IRIS·
Finally bought Binary Ninja today Absolutely tremendous product Obviously built by total craftsmen Well worth the $3,000
English
2
3
82
7.8K
H4x0r.DZ 🇰🇵 がリツイート
dawgyg - WoH
dawgyg - WoH@thedawgyg·
We all now know to not work with injective as they will screw over anyone to save face and money. They lie as bad as the Israelis.
Bojan Angjelkoski@bangjelkoski

Security is paramount at @injective and we take our bug bounty program very seriously. First and foremost, the figures referenced in the post are entirely misleading. There was no impact realized from this issue. Zero user funds were affected and zero addresses were compromised. For the stated vulnerability to work in practice, it would require execution of several suspicious transactions that would have an extraordinarily limited impact. Injective has dynamic rate limiting functionalities which are applied automatically based on our live monitoring systems. This functionality has been live on mainnet since last year and is publicly available in our code base. In addition to all of the above, this report was reviewed against the clearly defined terms of our Immunefi program. Based on those terms, issues such as those raised in this report that DO NOT impact block production or consensus are categorized outside of the Blockchain/DLT tier and carry a maximum payout of $50,000. If the poster had requested a mediation we would explain to him the dynamic rate limiters and monitoring systems we have in place and why his stated figures are misleading. However, he did not do so. We always follow the procedures set forth by the Immunefi program and expect the submitter to do so as well. We remain committed to fair, transparent, and consistent handling of all reports, and to maintaining the highest standards of security for the ecosystem. Injective has done so since its mainnet inception in 2021 and will continue to do so in perpetuity, always putting builders and security first.

English
3
3
62
9.7K
H4x0r.DZ 🇰🇵 がリツイート
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
Doing Active Directory pentesting
English
12
23
449
27.1K
Crypto Tea
Crypto Tea@Cryptotea·
North Korean hacker group Lazarus allegedly hacked Bitrefill they drained hot wallets and stole 18,500 customers information
Crypto Tea tweet mediaCrypto Tea tweet media
English
34
29
254
71.7K
H4x0r.DZ 🇰🇵 がリツイート
watchTowr
watchTowr@watchtowrcyber·
In 2025, we achieved pre-auth RCE against another solution in a ransomware gang favourite category. Today, we finally click publish. Join us as we walk through a chain of vulnerabilities we identified in BMC’s FootPrints ITSM solution. Enjoy! labs.watchtowr.com/thanks-itsms-t…
English
1
38
106
12.8K
Insider Wire
Insider Wire@InsiderWire·
#BREAKING: 𝕏 will soon let users restrict both posts and replies by region or country.
Insider Wire tweet mediaInsider Wire tweet media
English
3K
3.8K
32.2K
10.2M
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
Fun fact: 90% of the Web3 bug bounty programs are scams they list huge reward amounts mainly as a marketing tactic.
f4lc0n@al_f4lc0n

I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…

English
14
6
174
17.5K