

De-fi
A silent security scandal or dying profession? DeFi Bug Bounty Wall of Shame has millions in unpaid bounties – Crypto News
The crypto community is grappling with issues surrounding bug bounty programs, a crucial mechanism for discovering and addressing system vulnerabilities.
Usmann Khan, a web3 security auditor, posted on Aug. 17, “Remember that projects can simply not pay, whitehat,” with a screenshot of a message from Immunefi indicating a project had been removed from its bug bounty problem for failure to pay a minimum of $500,000 in bounties.
In response, security researcher Marc Weiss shared the ‘Bug Bounty Wall of Shame’ (BBWoS), a list documenting unpaid rewards allegedly owed to white hat hackers in web3. The data from BBWoS appears to signal a significant lack of accountability and trust within the crypto ecosystem that cannot be ignored.
The BBWoS indicates that a bug bounty for the Arbitrum exploit of Sep. 2022 had a $2 million reward. Yet, the white hate was awarded just $780,000 for identifying an exploit that exposed over $680 million.
Further, BBWoS states the CRV borrowing/lending exploit on Aave from Nov. 2022 led to the loss of $1.5 million, with $40 million at risk, and no bounty was paid to the white hat who identified the attack path “days before.”
Lastly, in April this year, just $500 was paid to a white hat who reportedly identified a way for managers to steal up to $14 million worth of “tokens from users using malicious swap paths” after being told by dHEDGE that the issue was “well-known.”
The list was created by whitehat hackers “tired of spending sleepless nights finding bugs in protocols only to have a payout of $500 when the economic damage totals in the millions,” with the creator stating,
“I created this leaderboard to help inform the security community as to the projects that don’t take security seriously so we can avoid them and spend time on the projects that do.”
The need for in-house auditors in DeFi.
In his presentation at the DeFi Security Summit in July, Weiss highlighted auditors’ critical role at various stages of protocol development. By integrating auditors and researchers in-house, he stressed their potential to make insightful architectural decisions, design effective codebases, and adopt a security-focused approach to protocol development.
Consequently, it is concerning when platforms fail to acknowledge and adequately reward the efforts of these security professionals when working on a contract basis.
Auditors Gogo and MiloTruck highlighted that non-payment for identified vulnerabilities is a widespread issue. Their posts underscore the urgent need for these platforms to enhance their accountability and trustworthiness and ensure due recognition for white hat hackers.
More transparency is required in handling vulnerabilities. High-profile cases listed on BBWoS, like the compromised deposit contract of Arbitrum, the economic exploit of Aave, and the malicious swap paths in dHEDGE, amplify this need.
Trusted Execution Environments in DeFi.
In response to Weiss’s issues about trust, Danny Ki from Super Protocol emphasized the potential of “decentralized confidential computing” to bolster trust in Web3 projects and mitigate vulnerabilities. Ki is referencing the option to run DeFi in Trusted Execution Environments (TEE), something inherent in Super Protocol.
A TEE is a secure area of a processor that guarantees code and data loaded inside be protected for confidentiality and integrity. However, one disadvantage of using TEEs within DeFi dApps is relying on proprietary architecture from centralized companies such as Intel, AMD, and ARM. There are efforts in the open-source community to develop open standards and implementations for TEE, such as Open-TEE and OP-TEE projects.
Ki argues that should “Web3 projects operate within confidential enclaves, there may be no need to pay out for vulnerabilities, as the security will be inherently fortified.”
While a fusion of blockchain and confidential computing could provide a formidable security layer for future projects, the move to replace bug bounties and security auditors with TEEs seems complex, to say the least.
Issues with bug bounties in DeFi.
Still, there are additional concerns for white hat hackers, such as improper bug disclosures from security firms on social media. A post from Peckshield identifying a bug in July simply said, “Hi @JPEGd_69, you may want to take a look,” with a link to an Ethereum transaction.
Gogo lambasted the post stating, “If this vulnerability were responsibly disclosed instead of exploited, PEGd’s users wouldn’t have lost $11 million, No reputational damage would have been caused, The guy would have gotten a solid bug bounty instead of been front-run by an MEV bot.”
Gogo shared their bug bounty experience with Immunefi, a company they described as ‘beyond fantastic,’ where the payout required a mediation process, eventually leading to a satisfactory payout of $5k for a critical bug.
These insights from the web3 security community underscore the critical role of auditors and the importance of effective bug bounty programs to the crypto ecosystem’s security, trust, and growth.
As some have identified, hacks are covered extensively in the news and on X, but what for those who discover the exploits and are never adequately compensated? Nearly $2.5 million in allegedly unpaid bounties is listed on BBWoS alone, yet, as Ki highlighted, could the future include a web3 that is innately secure with no need for bounties?
-
Technology1 week ago
Meet Matt Deitke: 24-year-old AI whiz lured by Mark Zuckerberg with whopping $250 million offer – Crypto News
-
Technology5 days ago
Binance to List Fireverse (FIR)- What You Need to Know Before August 6 – Crypto News
-
Technology1 week ago
Is AI causing tech worker layoffs? Thats what CEOs suggest, but the reality is complicated – Crypto News
-
Cryptocurrency1 week ago
XRP inflows drop 95% since July spike, while Chaikin data signals possible rally – Crypto News
-
others1 week ago
XRP NIGHT Token Airdrop: Snapshot, Claim Date and What to Expect? – Crypto News
-
Blockchain1 week ago
Bank of America Sees Interest in Tokenization of Real-World Assets – Crypto News
-
Blockchain7 days ago
Altcoin Rally To Commence When These 2 Signals Activate – Details – Crypto News
-
others1 week ago
Breaking: Strategy Files $4.2 Billion STRC Offering To Buy More Bitcoin – Crypto News
-
Blockchain1 week ago
SEC Crypto ETFs Ruling Brings Structural Fix, Not Retail Shakeup – Crypto News
-
Business1 week ago
Breaking: Solana ETFs Near Launch as Issuers Update S-1s With Fund Fees – Crypto News
-
Cryptocurrency6 days ago
Cardano’s NIGHT Airdrop to Hit 2.2M XRP Wallets — Find Out How Much You Can Get – Crypto News
-
others1 week ago
Ripple Swell 2025: Top Speakers and Panelists to Watch this November – Crypto News
-
Technology1 week ago
Oppo K13 Turbo series confirmed to launch in India with in-built fan technology: Price, specs and everything expected – Crypto News
-
Business1 week ago
Bitpanda Co-Founder & Co-CEO Paul Klanschek Steps Down as Firm Eyes Frankfurt IPO – Crypto News
-
Cryptocurrency1 week ago
Coinbase and JPMorgan Chase partner for crypto integration – Crypto News
-
Business1 week ago
Stablecoins Won’t Boost Treasury Demand, Peter Schiff Warns – Crypto News
-
De-fi1 week ago
White House Crypto Report Recommends Expanding CFTC’s Role in Crypto Regulation – Crypto News
-
Technology1 week ago
Coinbase to Offer Tokenized Stocks and Prediction Markets in U.S. – Crypto News
-
others1 week ago
Canadian Dollar under pressure amid weak GDP, Trump tariff threat, and strong US data – Crypto News
-
Technology6 days ago
Beyond Billboards: Why Crypto’s Future Depends on Smarter Sports Sponsorships – Crypto News
-
others1 week ago
Gold slides below $3,300 as traders await Fed policy decision – Crypto News
-
others1 week ago
Gold slides below $3,300 as traders await Fed policy decision – Crypto News
-
Business1 week ago
Breaking: SEC Launches “Project Crypto” To Enable Tokenization of U.S. Markets – Crypto News
-
others1 week ago
Can the record-breaking rally last? – Crypto News
-
De-fi1 week ago
Court Overturns Fraud Conviction of OpenSea’s Nate Chastain – Crypto News
-
Technology1 week ago
Big Tech’s Big Bet on AI Driving $344 Billion in Spend This Year – Crypto News
-
Cryptocurrency1 week ago
CME XRP Futures Hit Record Highs in July Amid ETF Approval Optimism – Crypto News
-
Cryptocurrency7 days ago
Stablecoins Are Finally Legal—Now Comes the Hard Part – Crypto News
-
Cryptocurrency7 days ago
Tron Eyes 40% Surge as Whales Pile In – Crypto News
-
Cryptocurrency7 days ago
Ethereum Hits Major 2025 Year Peak Despite Price Dropping to $3,500 – Crypto News
-
Business5 days ago
Analyst Spots Death Cross on XRP Price as Exchange Inflows Surge – Is A Crash Ahead ? – Crypto News
-
Technology4 days ago
Oppo K13 Turbo, K13 Turbo Pro to launch in India on 11 August: Expected price, specs and more – Crypto News
-
Technology4 days ago
OpenAI releases new reasoning-focused open-weight AI models optimised for laptops – Crypto News
-
Business1 week ago
Breaking: CBOE Files For Rule Change To List Crypto ETFs Without SEC Approval – Crypto News
-
De-fi1 week ago
Samourai Wallet Founders Plead Guilty, Agree to $237 Million Forfeiture – Crypto News
-
Technology1 week ago
Solana DEX volume dips 20% after co-founder slams meme coins – Crypto News
-
Technology1 week ago
Tim Cook confirms Apple will ramp up AI spending, ‘open’ to acquisitions – Crypto News
-
Technology1 week ago
Oppo K13 Turbo series confirmed to launch in India with in-built fan technology: Price, specs and everything expected – Crypto News
-
Blockchain1 week ago
Strategy Expands STRC Offering Twice in One Week – Crypto News
-
Technology1 week ago
Will The First Spot XRP ETF Launch This Month? SEC Provides Update On Grayscale’s Fund – Crypto News
-
Technology1 week ago
Amazon Great Freedom Sale deals on smartwatches: Up to 70% off on Samsung, Apple and more – Crypto News
-
Blockchain6 days ago
XRP Must Hold $2.65 Support Or Risk Major Breakdown – Analyst – Crypto News
-
Blockchain6 days ago
XRP Must Hold $2.65 Support Or Risk Major Breakdown – Analyst – Crypto News
-
Business6 days ago
Is Quantum Computing A Threat for Bitcoin- Elon Musk Asks Grok – Crypto News
-
Technology6 days ago
Elon Musk reveals why AI won’t replace consultants anytime soon—and it’s not what you think – Crypto News
-
Technology6 days ago
Google DeepMind CEO Demis Hassabis explains why AI could replace doctors but not nurses – Crypto News
-
Cryptocurrency5 days ago
Lido Slashes 15% of Staff, Cites Operational Cost Concerns – Crypto News
-
De-fi4 days ago
TON Sinks 7.6% Despite Verb’s $558M Bid to Build First Public Toncoin Treasury Firm – Crypto News
-
Blockchain4 days ago
Shiba Inu Team Member Reveals ‘Primary Challenge’ And ‘Top Priority’ Amid Market Uncertainty – Crypto News
-
others4 days ago
Bank of America CEO Denies Alleged Debanking Trend, Says Regulators Need To Provide More Clarity To Avoid ‘Second-Guessing’ – Crypto News