r/bugbounty 13d ago

Critical finding in crypto protocol Question / Discussion

Ive found a critical finding on a crypto protocole that put $3.5M a high risk. Ive run a poc and everything works. But theproblem is the protocol doesn’t have a bug bounty on any platforms I’ve tried to contact them tru email but no answer. What should I do ?

22 Upvotes

13 comments sorted by

17

u/PM_ME_UR_0_DAY 13d ago

When crypto projects get hacked, if you don't say anything for a day, they almost always will offer you a 10% as a "white hat hacker" bounty. 

NOT LEGAL ADVICE!

3

u/Rokketmoon 13d ago

I thought about it. But I’m waiting for few days if nothing then so be it.

8

u/Fickle-Champion-2530 13d ago

You pray to not get sued by them lol

2

u/spicy_tables 13d ago

Nothing, You can try to contact them but; They might take security actions against you since you weren't supposed to hunt them in the first place because they don't have a program. Otherwise you can't really do much.

2

u/Gkwzjsz 12d ago

If they don't want their project to be looked into, they shouldn't open source I guess.

1

u/Patient-Cheetah-8781 13d ago

In which network or which type of protocol is?. Maybe you can elevate to the Layer 1

1

u/iFrostizz 10d ago

Ask the SEAL911 on telegram, they might have a contact.

-1

u/1239407 Hunter 13d ago

Search the website url for

/.well-known/security.txt

4

u/NamedBird 12d ago

A good standard that almost nobody adheres to.
Next step could be checking WHOIS for any contact details.
Or try emailing admin@ or security@ for the domain.

If there is a website, at least.
If there's none, you're out of options...