White hat hacker paid DeFi’s largest reported bounty fee

White hat hacker paid DeFi’s largest reported bounty fee

Belt Finance, an automated market maker (AMM) protocol operating a yield optimization strategy on Binance Smart Chain (BSC), claims to have paid the largest bounty in the history of decentralized finance (DeFi) to a white hat hacker who averted a $10-million bug crisis. 

Industry white hat programmer Alexander Schlindwein discovered the vulnerability in Belt Finance’s protocol this week and reported the news to the team. For his efforts, Schlindwein received a generous compensation of $1.05 million, the majority of which ($1 million) was granted by Immunefi, with the additional $50,000 offered by Binance Smart Chain’s Priority One program.

Our top trading bots

Immunefi is one of the market leaders in software security for cryptocurrency projects. Since its inception, the platform has reportedly paid out in excess of $3 million to white hat hackers who have successfully identified technical infrastructure flaws in smart contracts and crypto platforms.

Priority One is a BSC initiative launched in July to enhance the security of decentralized applications (DApp) within the platform’s native ecosystem. Mirroring the structure of Immunefi, the service provides a $10-million incentive fund to blockchain bounty hunters who successfully contribute to the avoidance of security breaches across 100 DApps.

Schlindwein told Cointelegraph about how he discovered the vulnerability:

“I went through the list of bug bounties on Immunefi and picked Belt Finance as the next one to work on. While I was studying their smart contracts, I noticed a potential bug in the internal bookkeeping, which keeps track of each user’s deposited funds. Playing the attack through with pen and paper gave me more confidence in the existence of the bug. I continued by producing a proper proof-of-concept [PoC] which undoubtedly confirmed its validity and economic damage.”

“The next step was to create an official report on Immunefi including the PoC and an extensive description of the exploit,“ Schlindwein said, adding, “Immunefi reacted immediately to the critical report, and within three minutes after submission, it was escalated to the Belt team. Shortly after, Belt confirmed the validity of the report and began implementing a fix, which then patched the vulnerability.”

Related: The perfect storm: DeFi hacks will advance the crypto sector moving forward

Although DeFi’s security breaches remain a prevalent concern, it has been argued by some that the nascent ecosystem will benefit from such incidents in the long term, as areas of weaknesses are starkly highlighted.

Cointelegraph asked Schlindwein his perspective on the importance of bounty programs in supporting DeFi’s antifragile ambitions:

“I am strongly convinced of the importance of bug bounties and initiatives such as bounty funds. DeFi security consists of multiple layers, starting with peer review and unit testing to external audits and formal verification. Bug bounties are the last line of defense should an issue slip through the overlying layers with the potential to prevent a devastating hack while instead seriously fixing the issue and compensating the finder.”

“Bug bounties in DeFi have been a rare sight before Immunefi existed, only offered by the ‘Crème de la Crème’ of projects. It’s great to see hundreds of projects launching their bug bounty nowadays, which will certainly bring DeFi security forward in the long run,” Schlindwein concluded.

Continue reading about Cointelegraph
Korean government tells Apple and Google stores to take down P2E games
The South Korean government has moved to block the release of new play to earn (P2E) games and requested that existing ones be removed from Google Play...
Price analysis 11/12: BTC, ETH, BNB, ADA, SOL, XRP, DOT, DOGE, SHIB, LUNA
Bitcoin (BTC) price continues to weaken following the shakeout of the leveraged traders in the derivatives markets on Nov. 10. This caused the derivative...
Presearch, Aragon and IOTA explode higher after Bitcoin price clips $50K
Optimism across the crypto market continues to rise as bullish developments in the price of Bitcoin and Ethereum (ETH) renewed discussions about a 2013-style...
Publishing platform Substack now accepts Bitcoin payments
An integration with payment processor OpenNode will allow content platform Substack to accept Bitcoin payments on-chain and using the Lightning Network.In...
XRP Climbs 19% In Bullish Trade
Investing.com - XRP was trading at $1.22988 by 13:00 (17:00 GMT) on the Investing.com Index on Saturday, up 18.69% on the day. It was the largest one-day...
IMF intends to 'ramp up' digital currency monitoring
The International Monetary Fund, or IMF, plans to “step up” its monitoring of digital currencies, according to a report by Reuters. This intent, as published...
Here’s one way to trade Bitcoin even as BTC price teeters over an abyss
In the last 29 days, Bitcoin (BTC) has been ranging from $31,000 to $36,000 as the impact of the recent China ban and a $1.4 billion Grayscale GBTC share...
Enterprise Ethereum matures, looks to open-source community for standards
Ethereum is quickly becoming an integral part of the enterprise blockchain ecosystem. As more companies begin to leverage public networks for business,...
Ethereum Classic devs announce upcoming hard fork
On Monday, developers of the Ethereum Classic (ETC) blockchain announced a hard fork to implement the project’s latest version, now scheduled for launch...
Green Bitcoin: The impact and importance of energy use for PoW
While writing the world's most famous white paper, Satoshi Nakamoto defined the Bitcoin (BTC) mining process. It was established that the minting of new...
Investors cautiously re-enter crypto funds while ETH vehicles show strength
A new report from analytics firm Coinshares shows that while the market dip may not have ended, prices are now at levels where stock market investors are...
Bitcoin, ethereum plunge; crypto market cap losses nearly $1 trillion
NEW YORK (Reuters) - Bitcoin and ethereum posted their largest one-day drop since March last year on Wednesday, with losses in the market capitalization...
'Crypto for COVID': Indian neobank aims to feed those affected by pandemic
Cashaa, a crypto banking platform with physical branches across India, is launching an initiative aimed at bringing crypto enthusiasts together to provide...
Ripple wins access to SEC discussions on defining crypto assets as securities
Ripple Labs has been granted access to U.S. Securities and Exchange Commission documents “expressing the agency’s interpretation or views” on the subject...
Will Amazon Launch Blockchain-Based Services?
Despite the rumors, Amazon Web Services (AWS) will not offer services on Blockchain technology in the nearest time. CEO Andy Jassy made a statement at...