Pepin
390 posts

Pepin retweetledi
Pepin retweetledi
Pepin retweetledi
Pepin retweetledi

@immunefi Raccoon is fitting, also a Frog, because Frogs eat bugs :D
English
Pepin retweetledi

The future of Immunefi is now here.
We’ve officially announced the Immunefi Security OS: end-to-end, enterprise-grade security infrastructure to stop hacks before they happen, powered by the Immunefi Token (IMU).
Once live, the token will align incentives across protocols [that need security], researchers [that provide it] and end users [that seek safe yield] on the basis of the fundamental idea of…doing well by doing good.
The token has not been released yet. We will make an announcement sharing TGE date, including the tokenomics. So don’t get scammed.
The Security OS is a single command center that aggregates all security products in one place and integrates them with each other.
What that means: every time you use one product, all other products improve in effectiveness for you. It’s an intelligent, living ecosystem.
The command center has bug bounties, audit competitions, audits, PR reviews, monitoring, multisig transaction review, and more.
And today, we announced two major products:
1. The Immunefi Firewall, Powered by Dedaub
It’s a protocol-controlled firewall that blocks exploits in real time without breaking composability/DeFi integrations.
It has a 96% exploit blocking rate, tested across a dataset of 525 hack and 20.9K benign contracts. If this firewall had been in place across the industry at the beginning of this year, web3 would be a very different place today.
The firewall also is designed for DeFi’s lego-like ecosystem, making it a completely unique product. It surgically blocks bad actors without halting legitimate transactions, which continue uninterrupted through a seamless onchain integration.
And for protocols that love optionality, the firewall is totally configurable for each protocol’s logic and risk profile. Protocol teams maintain granular control over what gets allowed or blocked, unlike generic solutions where you’re stuck with default settings.
It’s incredibly easy to integrate with most smart contract protocols and will be deployable across Ethereum mainnet, major L2s, Avalanche, and more coming soon.
Every team needs this. DM for early access. Spots limited.
2. Immunefi’s Code Review Agent
The Immunefi Code Review Agent plugs right into your GitHub to provide security reviews for all your pull requests.
Most importantly, it’s powered by the world’s largest and private dataset of live web3 vulnerabilities.
➡️ Real-time reviews: Uses Immunefi’s ever-growing dataset to pinpoint actionable issues based on real web3 vulnerabilities.
➡️ Learns intelligently: As you accept and decline recommendations, the Code Review Agent learns from your feedback and improves its pattern recognition.
➡️Pairable with human reviews: Activate human reviews, the Code Review Agent or both.
➡️ Privacy conscious: Secure your code from human access with AI code review-only options.
➡️Scalable and fast: Reviews can occur concurrently across multiple repositories and PRs while balancing speed and quality.
—-----------------------------------------------
The new journey of Immunefi begins today as the security rails bringing trillions onchain.
We have the trust, the data, and the distribution.
Together, we will make web3 safe.
English
Pepin retweetledi

Statement:
A. Spectra Finance contracted with Immunefi to run an Audit Competition. Per our process, Immunefi provided Spectra the program draft that included the reward structure and linked to our standard competition reward terms. The Spectra team, including their CEO, conducted multiple reviews over 3+ weeks and approved the program draft that clearly stated that a single bug finding unlocks the full $40K pool. Not a single time during program drafting, marketing or during the 1.5 month hunting and evaluation period did they bring up an issue with this reward mechanic. Only when it was time to pay the community did they claim there was a disconnect in expectations.
B. The program received 331 reports from 103 SRs of which 27 were confirmed reports excluding insight reports.
C. After several weeks of good faith engagement to resolve the matter with Spectra including offering to contribute Immunefi program fees to bridge the gap and cover the full $40k payout, the matter remains unresolved. Spectra has not honored its commitment per the program rules they approved for publishing on Immunefi.
D. We have designed our platform rules to protect the balance of interests and hold them at the highest tier of priority to protect against bad faith actions from either party.
E. In this case, given the >1 month delay in payment to SRs, we have decided to make SRs whole using Immunefi’s own funds, rather than accept the unreasonably low and unfair offer made by Spectra. Their offer to pay per bug finding is precisely what a Bug Bounty program is - NOT an audit competition.
F. It would have been easier for us to either shortchange SRs or quietly fill the gap in payments from Spectra but we instead chose transparency and solving the problem for SRs. Given the recent undercurrent of opacity on such issues in the web3 sec space, we decided to take the lead in defining the way forward - even if it means taking a financial hit for it.
G. We would like to highlight here that this is the first case of such abuse by a project in our history of running 43 competition programs.
H. To protect SRs and the platform from such abuse in the future, we will be updating our policy on pre-payment of the reward in due course.
Spectra@spectra_finance
Public Statement on the Immunefi Audit Contest Dispute
English
Pepin retweetledi

We've been overwhelmed with applications to the Immunefi All Stars.
And it makes sense.
Immunefi has paid out **checks database** $119 million in public rewards to whitehats as of today.
We welcome you to compare that figure to the payouts of other platforms.
There's no better place to grind, progress your career, and make big earnings--without being locked down by heavy-handed contracts that restrict your freedom.
Join us below. We're still assessing applications.

English
Pepin retweetledi
Pepin retweetledi

🚨 Live shot of @WhiteHatMage collecting his $1,000,000 bug bounty.
Congratulations, WhiteHatMage! 🧙♂️
When he hits $2m, he's promised to start a retro game company (please).
English
Pepin retweetledi
Pepin retweetledi
Pepin retweetledi

Magnus is the future of onchain security.
But what is it and how does it work?
What does it mean for projects and security researchers?
The real answers are coming on The Magnus Snow.
Thursday, March 13, 5pm UTC.
Tune in.
x.com/i/spaces/1RDGl…

English
Pepin retweetledi

⚡Introducing Magnus: The bridge to a trillion-dollar onchain future ⚡
Magnus is the first platform to unify the onchain security tech stack in a single command center, delivering 360° hack prevention with AI-optimized SecOps.
Discover the future of onchain security👇
#ImmunefiMagnus
🧵1/8

English
Pepin retweetledi
Pepin retweetledi
Pepin retweetledi

2024 was HUGE for Immunefi and our community of rockstar security researchers.
🔥 $23M paid out this year
🚨 1,700+ vulnerabilities found
💰 600+ Criticals & Highs
SRs leveled up, broke records, and boosted onchain security like never before.
Watch the recap 👇
#Immunefi2024
English













