DiMaX
456 posts


@Shabosec @sachin_pandey98 Congratulations, can you share what self-hosted bbp is?
English

Are security teams hitting the limits of what humans alone can handle in the cloud?
The data points to yes.
Read the report to see what’s changing and what it means for how you defend the cloud:
okt.to/ZyD2sf
English

I reported a critical vulnerability to a top-tier crypto exchange—an exploit that could allow an attacker to crack and steal wallet private keys within minutes. By all industry standards, this was a severe, high-impact bug. Yet, they initially offered me a measly $4,000 bounty.
I refused to accept it and pushed back hard. After a prolonged back-and-forth, they spent ages escalating it to their leadership. Following endless rounds of "approvals," they finally added a whopping $1,000 to the offer, bringing the grand total to $5,000. I am honestly "moved to tears" by their generosity, considering an exploit of this magnitude is easily worth at least $50,000.
Seriously, my advice is to avoid participating in Bug Bounty programs run by certain Chinese teams. It seems they would much rather risk getting drained for tens or hundreds of millions of dollars by actual hackers than pay a white hat a single extra cent for protecting them.
English

The good news? ✨
Security teams can see more risk than ever.
The bad news? ⛔
Risk doesn’t go away until something gets fixed.
Start delivering security outcomes today: okt.to/CrzHEy

English

@immunefi I hit a whitehat level gate, I found a high vulnerability, how can I report it?
@immunefi @AlchemixFi
English

Alchemix bug bounty has relaunched on @immunefi with their new v3 contracts.
Up to $300K in rewards.
Now's the time to look at that code.
immunefi.com/bug-bounty/alc…
English

Yesterday I tried @hakiraio 's AI agent on a bounty in @HackenProof platform. It handed me a critical & a low severity bug. Best thing is I cross tested the same with opus 4.6 and it also verified it. Outstanding work by @hakiraio team.
English

@Ehsan1579 Congratulations! Can you honestly tell us if you use any kind of AI or if you find vulnerabilities completely manually?
English

@rez0__ @ZackKorman Does NVIDIA have a private BBP? What platform is it on?
English

@ZackKorman you should submit to their vdp and then get invites to their private programs so you can make some cash off your efforts
English

Devil's Advocate protocol on sc-auditor V2 is working so well 🔥
Reached an impressive 90% True Positive rate on a benchmarked contest by @pashov and @0xiehnnkta with 16 true positives on 18 total finds.
Full numbers, comparison and release of sc-auditor V2 tomorrow 🕵️
English

Proud of my achievement with @AMD !
Thanks to @Intigriti for such a fair environment; I never feel the need for mediation because their integrity is truly top-tier.
This recognition is the result of truly hard work and continuous dedication.
#BugBounty #Intigriti #InfoSec

English














