InfiniteSec

52 posts

InfiniteSec

InfiniteSec

@infsec_io

HackenProof All-Time Rank #4. Web3 security team specializing in blockchain audits and vulnerability research. Audit requests → https://t.co/upePa4whxT

เข้าร่วม Aralık 2025
39 กำลังติดตาม245 ผู้ติดตาม
sashko.eth🇺🇦
If your goal was to make $1M from bug bounties in 2026 you might want to move faster. @infsec_io is already halfway there… and that’s only counting submissions on HackenProof 👀 The pace this year is different.
HackenProof@HackenProof

$500,000 to @infsec_io — what a legend move, Respect 🫡🔥 Half a million for a single valid find, climbing straight to #4 on the leaderboard! Huge congrats from the entire HackenProof team 🎉

English
2
3
56
3.1K
InfiniteSec
InfiniteSec@infsec_io·
@d0rsky Yes, we have basically achieved the 1M target, and soon we will also appear on the Filecoin and Ethereum leaderboards.
English
1
0
2
66
InfiniteSec รีทวีตแล้ว
HackenProof
HackenProof@HackenProof·
$500,000 to @infsec_io — what a legend move, Respect 🫡🔥 Half a million for a single valid find, climbing straight to #4 on the leaderboard! Huge congrats from the entire HackenProof team 🎉
HackenProof tweet media
English
8
11
214
10.2K
InfiniteSec
InfiniteSec@infsec_io·
We are proud to see InfiniteSec officially acknowledged in the latest $TON Core Release (v2026.02)! ​Following our security research in Jan 2026, we’ve worked closely with the @ton_blockchain core team to further enhance infrastructure stability and overall ecosystem resilience. High-impact research, real-world results. ​A big shoutout to the core developers for the professional collaboration in making The Open Network more robust for everyone. 🤝 ​Check out the full release log: 🔗 github.com/ton-blockchain… ​CC: @ton_blockchain#TON #BlockchainSecurity #InfiniteSec #Web3 #Infrastructure
English
0
0
1
561
InfiniteSec
InfiniteSec@infsec_io·
I completely agree. Although we’ve uncovered many vulnerabilities and earned significant payouts through bug bounties, it’s fair to say that most issues encountered are trivial. Experienced hunters won't report these, but newcomers create a lot of noise—especially now with LLMs in the mix
English
0
0
1
166
WhiteHatMage
WhiteHatMage@WhiteHatMage·
@philbugcatcher I'd never recommend bounties to beginners. For their own sake, and for the sake of everyone. It's not a playground, but where professionals gather to prevent exploits. I'd suggest doing CTFs, reproducing exploits, and proving findings from reports and writeups. Git gud first.
English
3
0
63
1.4K
phil
phil@philbugcatcher·
Pretty sad that audit contests are over The best path for beginners now is bug bounty, which is a tougher entry point than contests On the bright side, the next cohorts of SRs will likely come out even stronger
English
19
4
177
11K
InfiniteSec
InfiniteSec@infsec_io·
And the last update to the codebase was 4 years ago, I should have realized it.
English
0
0
1
494
InfiniteSec
InfiniteSec@infsec_io·
After submitting a high-risk vulnerability to the @immunefi bug bounty program, you discovered that the project's TVL is currently less than $400,000. 🙀🙀🙀
English
1
0
3
560
InfiniteSec
InfiniteSec@infsec_io·
We discovered a critical vulnerability in Flare that could halt the chain, but it has been duplicated. It's truly disheartening to hear such news. We will release a writeup after the vulnerability is fixed.
InfiniteSec tweet media
English
0
0
2
1.2K
InfiniteSec
InfiniteSec@infsec_io·
A friendly heads-up before you dive in: Ethereum's client diversity significantly devalues vulnerability severity ratings. Look at the severity criteria — Critical requires impacts like slashing >50% of validators or causing the entire network to halt. But no single client holds >50% market share right now. Geth is at ~41%, Lighthouse at ~42%. So even if you find a devastating RCE or consensus bug in the most popular client, the impact is inherently capped by that client's market share percentage. In practice, this means virtually no single-client vulnerability can be rated as Critical. A catastrophic bug in Geth, for example, would only affect ~41% of the network — that lands you at High severity at best (the threshold is >33%). For smaller clients like Reth (2%) or Nimbus (6%), even a total crash-the-node bug barely qualifies as Low.
English
0
0
0
26
Ehsan
Ehsan@Ehsan1579·
@WhiteHatMage @thedaofund I'm going to be auditing Ethereum soon, I thought the exact same thing, I think it should be at least 50 million ngl.
English
1
0
2
361
WhiteHatMage
WhiteHatMage@WhiteHatMage·
Hey @thedaofund, use the funds to actually secure Ethereum. The $250k max cap for the Bug Bounty Program is too low by any standards.
WhiteHatMage tweet media
English
8
7
89
4.9K
InfiniteSec
InfiniteSec@infsec_io·
@WhiteHatMage We'd suggest that even if bug hunters don't have time for thorough market research, at least check the project's TVL on defillama. Treasury funds are also a great reference point — they often determine how much a project can actually invest in security.
English
0
0
0
97
WhiteHatMage
WhiteHatMage@WhiteHatMage·
@infsec_io I should read my own post again. I keep falling for bad projects lol
English
2
0
5
298
WhiteHatMage
WhiteHatMage@WhiteHatMage·
The hardest part of bounty hunting isn’t finding the vulnerability. It’s actually getting paid what it’s worth. Behind every happy payout there are dozens of horror stories.
English
12
10
159
5.2K
InfiniteSec
InfiniteSec@infsec_io·
@WhiteHatMage We've run into plenty of failed bug bounty payouts ourselves. We plan to share those stories in the future, but for now we're more focused on the hunt. Really appreciate you sharing this.
English
0
0
1
50
InfiniteSec
InfiniteSec@infsec_io·
We discovered a consistency-related vulnerability in the transaction processing pipeline of a major public blockchain’s transaction bundling / block-building infrastructure. Unfortunately, this issue ultimately turned out to be a duplicate, but that’s one of the most common outcomes bug hunters run into—so we keep moving forward.
InfiniteSec tweet media
English
0
0
1
410
InfiniteSec
InfiniteSec@infsec_io·
Read through a @Ehsan1579 zkSync security report and spotted a new critical vulnerability. Unfortunately it turned out to be a dup. It happens. Onwards.
InfiniteSec tweet media
English
0
0
4
378