DeepTide TechFlow News: On March 16, white hat hacker f4lc0n discovered a critical vulnerability on the Injective chain involving over $500 million in asset risk. The vulnerability could allow arbitrary users to directly drain any account on the chain. After the vulnerability was reported through Immunefi, the Injective team pushed a mainnet upgrade to fix it the next day. However, they remained silent for three months before finally notifying a bounty of $50,000, far below the $500,000 maximum for critical vulnerabilities in their bug bounty program. The bounty has not yet been paid, and f4lc0n has received no response or explanation after raising objections.

INJ3,58%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin