Funkaclau

3K posts

Funkaclau banner
Funkaclau

Funkaclau

@Funkaclau

Web3 Developer and Project Multi Project Founder

DeGen Katılım Mart 2021
419 Takip Edilen530 Takipçiler
SHIDO NERD
SHIDO NERD@shidoNERD·
Guess who is back!?
SHIDO NERD tweet media
English
2
2
5
46
shidokid
shidokid@shidokid·
Did you miss anything? 👶
shidokid tweet media
English
4
4
21
263
Funkaclau retweetledi
0x_Vivek
0x_Vivek@0x_Vivek·
@al_f4lc0n changing the bounty terms after the report drops is the ultimate rug pull. projects value chain consensus over user funds until the tvl actually drains. good on you for keeping the receipts.
English
1
3
22
1.8K
qckhp
qckhp@qckhp·
@al_f4lc0n > I’d really like to know when this line was added. and do you really value chain consensus more than users' funds? @infosec_us_team got you Dec 4, 2025 #diff-d4aaedd43a789fbb2114e0105ce5adf0894797e783ab155e8f26b791ea46b517" target="_blank" rel="nofollow noopener">github.com/infosec-us-tea…
English
1
0
25
1.6K
f4lc0n
f4lc0n@al_f4lc0n·
the figures referenced in the post are entirely misleading. There was no impact realized from this issue. Zero user funds were affected and zero addresses were compromised. My response: Are you suggesting I should have actually exploited the bug and caused real damage before coming to talk to you? For the stated vulnerability to work in practice, it would require execution of several suspicious transactions that would have an extraordinarily limited impact. My response: You should know better than anyone that on a Cosmos-based chain, a single transaction can pack multiple messages. Just one transaction is more than enough to completely drain multiple whale accounts. Injective has dynamic rate limiting functionalities which are applied automatically based on our live monitoring systems. This functionality has been live on mainnet since last year and is publicly available in our code base. My response: First, this has nothing to do with the vulnerability itself. Rate limiting doesn't stop attackers from stealing funds. It only slows them down when they try to bridge those funds over to Ethereum. Second, when I submitted my report, the mainnet configuration for this feature was not set. In other words, this feature wasn't even turned on! In addition to all of the above, this report was reviewed against the clearly defined terms of our Immunefi program. Based on those terms, issues such as those raised in this report that DO NOT impact block production or consensus are categorized outside of the Blockchain/DLT tier and carry a maximum payout of $50,000. My response: First, Immunefi has always put the impact of direct fund theft at the very top of its priority list. This is a fact that everyone knows. Second, you changed your bug bounty page after I submitted my report. Here’s the snapshot from November 8, 2025: web.archive.org/web/2025110816… . And now, there’s an extra line added to your bug bounty page: “IMPORTANT: Within the Assets in Scope table, the injective-core folder is listed for both Blockchain/DLT and Web/App due to overlap between the two within the same folder. However, for a report to be categorized as Blockchain/DLT, the resulting impact has to be directly involved with the block production process or with consensus failures. All reports not dealing directly with either of these are to be categorized as Web/App.” I’d really like to know when this line was added. and do you really value chain consensus more than users' funds? We remain committed to fair, transparent, and consistent handling of all reports, and to maintaining the highest standards of security for the ecosystem. Injective has done so since its mainnet inception in 2021 and will continue to do so in perpetuity, always putting builders and security first. My response: You never even replied to my messages, and now you’re blaming me for not requesting mediation? I can post the original report if you agree. I left many messages, but you haven't replied to a single one. ---------- Finally: Stop making excuses from every angle and trying to use technical jargon to confuse people who aren't developers. That doesn’t work anymore these days. Anyone can just ask an AI to fact-check what both of us are saying. I have no ill intentions toward your project. All I'm asking is for you to be honest and handle this transparently.
English
41
35
478
46.1K
Funkaclau
Funkaclau@Funkaclau·
@EvanKlein338226 @al_f4lc0n they are teaching us about their method of work, and teaching us how should we treat them and their user base next time a vulnerability is found. play with fire, get burned
English
0
0
1
4
Evan Klein
Evan Klein@EvanKlein338226·
The "no impact = no payout" logic is broken. That's like saying a fire alarm that catches a fire early doesn't deserve credit because nothing burned. You found the vulnerability. You reported it responsibly. The alternative was waiting for actual damage. This is why many researchers just go full disclosure now.
English
2
2
14
1.8K
Abraham
Abraham@abrahamonchain·
@MaxLensherr @al_f4lc0n 😂😂😂 Ngl bruh They're trying every means possible to divert the topic
English
1
0
1
51
Funkaclau
Funkaclau@Funkaclau·
@al_f4lc0n It's not time to stop! It's time to push those irresponsible and deceptive power abusers. It pains me deeply to empathize with what you are going through, and everyone should know how rotten and unaccountable is that Blockchain team. Trying to walk away as if nothing happened
English
0
0
0
23
BenJamin Steele
BenJamin Steele@Benn_Bullish·
@HyperliquidX is a great platform. But its fees and slippage on scalping are highly HIGHLY fuckink suspect. Seems to be a greedy platform with little or no respect for its clients. Even on winning trades, the slippage is maximum in the reverse. One day, they will be audited, and one day people will go to prison and enjoy a shower. Now that is maximum slippage.
English
2
0
2
15
Funkaclau
Funkaclau@Funkaclau·
Dev Life 😅
f4lc0n@al_f4lc0n

I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…

English
0
0
2
36
Jolt
Jolt@0xJolt·
I need the next 1000x 🎉 Shill me that ticker NOW!
English
173
10
112
7.1K
Funkaclau retweetledi
Shido
Shido@ShidoNetwork·
Discover Shido DEX on @CoinMarketCap, now featuring updated tracking for liquidity and trading volume on the Shido Network. Explore market pairs and gain deeper insights into trading activity on the world’s largest crypto data platform. 🔗 coinmarketcap.com/exchanges/shid…
Shido tweet media
English
18
73
150
4.2K
Funkaclau
Funkaclau@Funkaclau·
@Balance0606 @al_f4lc0n @injective i dont develop on Injective, but seeing humans stand up this way to help out a noble dev, i have to join. I know what he is feeling. i have been there and on my case not even a "thank you" i got
English
0
1
0
144
Funkaclau
Funkaclau@Funkaclau·
@al_f4lc0n @immunefi sad, real and more common than you would imagine. i dont even dare share my experience on this 🤣
English
0
0
0
512
f4lc0n
f4lc0n@al_f4lc0n·
I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…
English
521
528
4.6K
1.8M
Fincozy
Fincozy@Fincozy1·
@kyrixavlr @al_f4lc0n @immunefi so you like it when billion dollar businesses enrich themselves with lowball payouts to ordinary people who are supposed to do it for "the love of it" cucklord
English
2
0
5
298
Funkaclau retweetledi
Shido
Shido@ShidoNetwork·
Shido weekly AMA on X, Sunday 5pm UTC 🎙️ As usual, join Rayqua to ask any questions. Not recorded, so don’t miss it👇 x.com/i/spaces/1lKQR…
English
13
31
76
1.4K
Funkaclau
Funkaclau@Funkaclau·
AI generated video can deceive many, but if you pay attention to the sound. you will notice a very peculiar buzz that is a very distinguishable feature of AI created content. Last but not the least, welcome to the age of Disinformation and fantasy 😂 it's only getting worse from here 😅
English
0
0
16
9.1K
Idris
Idris@7signxx·
This is Tel-Aviv Airport, Israel. Why are they lying about what is truly happening in Israel? Iran isn't here to play...
English
308
1.8K
7K
826.8K