• DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise
Real Hacker
  • Home
  • Review
    Meta introduces Instagram Reels APIs for developers – TechCrunch

    Meta introduces Instagram Reels APIs for developers – TechCrunch

    Basic home office hacks: 8 things you need to elevate your workspace

    Basic home office hacks: 8 things you need to elevate your workspace

    Fintech investors appear to be favoring later-stage deals as sector takes a hit, recent data shows – TechCrunch

    Fintech investors appear to be favoring later-stage deals as sector takes a hit, recent data shows – TechCrunch

    Spurred by Roe overturn, senators seek FTC probe of iOS and Android tracking

    Spurred by Roe overturn, senators seek FTC probe of iOS and Android tracking

    OSOM’s OV1 is now Solana’s web3 Android handset, Saga – TechCrunch

    OSOM’s OV1 is now Solana’s web3 Android handset, Saga – TechCrunch

    NFT summer in New York is in full swing amid crypto winter – TechCrunch

    NFT summer in New York is in full swing amid crypto winter – TechCrunch

  • Gaming
    How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

    How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

    Hideo Kojima set aside superhero project for being too close to Amazon’s The Boys

    Hideo Kojima set aside superhero project for being too close to Amazon’s The Boys

    Freshly Frosted Has Me Dreaming Colorful Donut Dreams

    Freshly Frosted Has Me Dreaming Colorful Donut Dreams

    Video Games Double Down On NFTs Despite Historic Crashes

    Video Games Double Down On NFTs Despite Historic Crashes

    Microsoft Flight Simulator update could lead to a virtual Space Shuttle

    Microsoft Flight Simulator update could lead to a virtual Space Shuttle

    Into The Breach Advanced Edition Introduces New Mechs And A Mobile Port Through Netflix

    Into The Breach Advanced Edition Introduces New Mechs And A Mobile Port Through Netflix

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    Nvidia GTX 1630 leaks, an entry level Turing card

    Nvidia GTX 1630 leaks, an entry level Turing card

    Check out the Akai Switch – a Nintendo Switch and Akai MPC concept

    Check out the Akai Switch – a Nintendo Switch and Akai MPC concept

    The Google Pixel 6a boasts faster fingerprint sensor than the 6 Pro in this video

    The Google Pixel 6a boasts faster fingerprint sensor than the 6 Pro in this video

    What to expect from Apple in the second half of 2022?

    What to expect from Apple in the second half of 2022?

    Intellytech Pocket-V Dual Charger – Newsshooter

    Intellytech Pocket-V Dual Charger – Newsshooter

    The Gamesir X3 adds a cooling fan to your phone, but does it work?

    The Gamesir X3 adds a cooling fan to your phone, but does it work?

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    GEEKOM Mini IT8 Mini PC, A Price Almost As Small As The System

    GEEKOM Mini IT8 Mini PC, A Price Almost As Small As The System

    As HPC Chip Sizes Grow, So Does the Need For 1kW+ Chip Cooling

    As HPC Chip Sizes Grow, So Does the Need For 1kW+ Chip Cooling

    Cooler Master V850 SFX Gold, In White

    Cooler Master V850 SFX Gold, In White

    Banished To Work In The Metaverse For A Week

    Banished To Work In The Metaverse For A Week

    The Gigabyte UD1000GM PG5 1000W PSU Review: Prelude to ATX 3.0

    The Gigabyte UD1000GM PG5 1000W PSU Review: Prelude to ATX 3.0

    AMD Updates Ryzen Embedded Series, R2000 Series With up to Four Cores and Eight Threads

    AMD Updates Ryzen Embedded Series, R2000 Series With up to Four Cores and Eight Threads

  • Applications
    Cybersecurity Experts Warn of Emerging Threat of “Black Basta” Ransomware

    Cybersecurity Experts Warn of Emerging Threat of “Black Basta” Ransomware

    iMore Show 800: What’s the deal with the new M2 MacBook Pro?

    iMore Show 800: What’s the deal with the new M2 MacBook Pro?

    Air Twister Flies Onto Apple Arcade

    Air Twister Flies Onto Apple Arcade

    Popular Apple Music service tier gets sudden price hike in the US, UK, and Canada

    Popular Apple Music service tier gets sudden price hike in the US, UK, and Canada

    Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

    Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

    Zoom’s new subscription makes it an even better team collaboration service

    Zoom’s new subscription makes it an even better team collaboration service

  • Security
    Stories from the SOC – Detecting internal reconnaissance

    Stories from the SOC – Detecting internal reconnaissance

    Threat Intelligence Services Are Universally Valued by IT Staff

    Threat Intelligence Services Are Universally Valued by IT Staff

    #InfosecurityEurope2022: Preparing for Future Challenges and Opportunities

    #InfosecurityEurope2022: Preparing for Future Challenges and Opportunities

    Mitek launches MiVIP platform to fight identity theft

    Mitek launches MiVIP platform to fight identity theft

    #InfosecurityEurope2022: The Interactivity Between Nation-State Attackers and Organized Crime Gangs

    #InfosecurityEurope2022: The Interactivity Between Nation-State Attackers and Organized Crime Gangs

    Does an iPhone Need Antivirus Software?

    Does an iPhone Need Antivirus Software?

No Result
View All Result
  • Home
  • Review
    Meta introduces Instagram Reels APIs for developers – TechCrunch

    Meta introduces Instagram Reels APIs for developers – TechCrunch

    Basic home office hacks: 8 things you need to elevate your workspace

    Basic home office hacks: 8 things you need to elevate your workspace

    Fintech investors appear to be favoring later-stage deals as sector takes a hit, recent data shows – TechCrunch

    Fintech investors appear to be favoring later-stage deals as sector takes a hit, recent data shows – TechCrunch

    Spurred by Roe overturn, senators seek FTC probe of iOS and Android tracking

    Spurred by Roe overturn, senators seek FTC probe of iOS and Android tracking

    OSOM’s OV1 is now Solana’s web3 Android handset, Saga – TechCrunch

    OSOM’s OV1 is now Solana’s web3 Android handset, Saga – TechCrunch

    NFT summer in New York is in full swing amid crypto winter – TechCrunch

    NFT summer in New York is in full swing amid crypto winter – TechCrunch

  • Gaming
    How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

    How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

    Hideo Kojima set aside superhero project for being too close to Amazon’s The Boys

    Hideo Kojima set aside superhero project for being too close to Amazon’s The Boys

    Freshly Frosted Has Me Dreaming Colorful Donut Dreams

    Freshly Frosted Has Me Dreaming Colorful Donut Dreams

    Video Games Double Down On NFTs Despite Historic Crashes

    Video Games Double Down On NFTs Despite Historic Crashes

    Microsoft Flight Simulator update could lead to a virtual Space Shuttle

    Microsoft Flight Simulator update could lead to a virtual Space Shuttle

    Into The Breach Advanced Edition Introduces New Mechs And A Mobile Port Through Netflix

    Into The Breach Advanced Edition Introduces New Mechs And A Mobile Port Through Netflix

  • Gear
    • All
    • Audio
    • Camera
    • Laptop
    • Smartphone
    Nvidia GTX 1630 leaks, an entry level Turing card

    Nvidia GTX 1630 leaks, an entry level Turing card

    Check out the Akai Switch – a Nintendo Switch and Akai MPC concept

    Check out the Akai Switch – a Nintendo Switch and Akai MPC concept

    The Google Pixel 6a boasts faster fingerprint sensor than the 6 Pro in this video

    The Google Pixel 6a boasts faster fingerprint sensor than the 6 Pro in this video

    What to expect from Apple in the second half of 2022?

    What to expect from Apple in the second half of 2022?

    Intellytech Pocket-V Dual Charger – Newsshooter

    Intellytech Pocket-V Dual Charger – Newsshooter

    The Gamesir X3 adds a cooling fan to your phone, but does it work?

    The Gamesir X3 adds a cooling fan to your phone, but does it work?

    Trending Tags

    • Best iPhone 7 deals
    • Apple Watch 2
    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • iOS 10
    • iPhone 7
    • Sillicon Valley
  • Computers
    GEEKOM Mini IT8 Mini PC, A Price Almost As Small As The System

    GEEKOM Mini IT8 Mini PC, A Price Almost As Small As The System

    As HPC Chip Sizes Grow, So Does the Need For 1kW+ Chip Cooling

    As HPC Chip Sizes Grow, So Does the Need For 1kW+ Chip Cooling

    Cooler Master V850 SFX Gold, In White

    Cooler Master V850 SFX Gold, In White

    Banished To Work In The Metaverse For A Week

    Banished To Work In The Metaverse For A Week

    The Gigabyte UD1000GM PG5 1000W PSU Review: Prelude to ATX 3.0

    The Gigabyte UD1000GM PG5 1000W PSU Review: Prelude to ATX 3.0

    AMD Updates Ryzen Embedded Series, R2000 Series With up to Four Cores and Eight Threads

    AMD Updates Ryzen Embedded Series, R2000 Series With up to Four Cores and Eight Threads

  • Applications
    Cybersecurity Experts Warn of Emerging Threat of “Black Basta” Ransomware

    Cybersecurity Experts Warn of Emerging Threat of “Black Basta” Ransomware

    iMore Show 800: What’s the deal with the new M2 MacBook Pro?

    iMore Show 800: What’s the deal with the new M2 MacBook Pro?

    Air Twister Flies Onto Apple Arcade

    Air Twister Flies Onto Apple Arcade

    Popular Apple Music service tier gets sudden price hike in the US, UK, and Canada

    Popular Apple Music service tier gets sudden price hike in the US, UK, and Canada

    Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

    Hackers Exploit Mitel VoIP Zero-Day in Likely Ransomware Attack

    Zoom’s new subscription makes it an even better team collaboration service

    Zoom’s new subscription makes it an even better team collaboration service

  • Security
    Stories from the SOC – Detecting internal reconnaissance

    Stories from the SOC – Detecting internal reconnaissance

    Threat Intelligence Services Are Universally Valued by IT Staff

    Threat Intelligence Services Are Universally Valued by IT Staff

    #InfosecurityEurope2022: Preparing for Future Challenges and Opportunities

    #InfosecurityEurope2022: Preparing for Future Challenges and Opportunities

    Mitek launches MiVIP platform to fight identity theft

    Mitek launches MiVIP platform to fight identity theft

    #InfosecurityEurope2022: The Interactivity Between Nation-State Attackers and Organized Crime Gangs

    #InfosecurityEurope2022: The Interactivity Between Nation-State Attackers and Organized Crime Gangs

    Does an iPhone Need Antivirus Software?

    Does an iPhone Need Antivirus Software?

No Result
View All Result
Real Hacker
No Result
View All Result

Home Security

Skyrocketing cryptocurrency bug bounties expected to lure top hacking talent

RealHacker Staff by RealHacker Staff
February 27, 2022
Share on FacebookShare on Twitter


As high-stakes cryptocurrency and blockchain tasks proliferate and soar in worth, it’s no shock that malicious actors have been enticed to steal $14 billion in cryptocurrency throughout 2021 alone. The frantic tempo of cryptocurrency thefts is continuous into 2022.

In January, thieves stole $30 million in foreign money from Crypto.com and $80 million in cryptocurrency from Qubit Finance. February began with the second-largest decentralize finance (DeFi) theft so far when a hacker exploited a token change bridge in Wormhole to steal $320 million value of Ethereum.

The biggest cryptocurrency hack to this point passed off final August when blockchain interoperability mission Poly Community suffered a hack that resulted in a lack of over $600 million. In an uncommon transfer, Poly unsuccessfully tried to publicly negotiate with the hacker a post-theft “bug bounty” of $500,000 in change for returning the $600 million, a bounty value six instances greater than that usually provided in conventional cryptocurrency bug bounty packages.

$2 million paydays set the tempo

With a lot cash at stake, at the least $3 trillion by some calculations in late-2021, it’s additionally not shocking that bona fide bug bounties within the cryptocurrency sector are skyrocketing. Every week in the past, famous white-hat hacker Jay Freeman introduced that he earned a $2,000,042 million bug bounty from Ethereum layer-2 scaling mission Optimism for locating a bug that may have allowed an attacker to print an arbitrary amount of tokens.

Freeman is just not alone in producing a $2 million payday from a cryptocurrency bounty. Gerhard Wagner submitted a crucial vulnerability final October that affected the Polygon Plasma Bridge, which put $850 million in danger, incomes a $2 million bounty within the course of. In December, one other crucial vulnerability in Polygon, which put $18 billion in danger, generated a $2.2 million bounty for white-hat Leon Spacewalker. Each of those bounties have been paid through Web3 bug bounty platform Immunefi.

On the identical day Freeman’s bounty was made public, Ethereum-based protocol MakerDAO introduced a most $10 millon reward by way of Immunefi for white hat hackers who level out authentic safety threats in its good contracts.

What’s a bug value?

With cryptocurrency bounties reaching seven and eight figures, the stress for conventional bug bounty packages to up the ante will little doubt mount, at the least in the long term, as prime hackers retrofit their expertise to go the place the cash is. “Sure, there’s monetary competitors for expertise and knowledge, and our class must reply,” Casey Ellis, CTO, and Founding father of Bugcrowd, tells CSO. “Cryptocurrency firms stands out as the first ones to succinctly reply the query, ‘What’s a bug value?’”

Ellis provides that “in conventional markets, iOS exploits can promote for greater than $2 million, but it surely’s often to consumers who’re far harder to take care of, and who intend to maintain these vulnerabilities alive for future use. To see a identified and respected jail-breaker pivot towards the relative ease of earnings afforded by the cryptocurrency increase offers you an concept of the place the vulnerability knowledge market goes.”

“Bounty measurement goes up in Web2 stuff no matter what occurs in crypto,” Mitchell Amador, Founder and CEO of Immunefi, tells CSO. “All people and their canine are digitizing their infrastructure, their workflows, their enterprise logic, and their operations. That is an unbelievable enhance within the assault service over a comparatively quick period of time.”

The meteoric rise in cryptocurrency bug bounties gained’t eradicate the necessity for conventional bug bounty hackers, Amador says. “It is not going to hole out the present bug base. You’ve got acquired these legions of hackers who’ve constructed very worthwhile, particular expertise going after particular vulnerabilities. They’re simply going to maintain plying their commerce.”

Greatest hackers will migrate to crypto area

What would possibly occur is that the most effective hackers will migrate to the crypto area. “Folks need to crack the toughest issues within the hacker neighborhood,” Amador says. “You get numerous fame, numerous clout as a result of you are able to do one thing that no one else has been capable of do. You’ll be able to show that you are the finest.”

The problem of cracking essentially the most complicated issues with the large payoffs might show irresistible to prime expertise. “We have mixed a few of the hardest technical challenges in crypto, together with, by far, the most important payouts. It’s going to dramatically speed up the speed at which this prime tier, this prime 10% of the hacking neighborhood, migrates to crypto. It’s a must to be an exceptionally proficient particular person and have years of coaching and expertise in an effort to deal with these issues.”

Upward stress ‘very, very doubtless’ in the long run

Dane Sherrets, options architect at HackerOne, who additionally does bug bounties on the facet, tells CSO that within the quick time period, “I do not anticipate to see any actual up upward stress [as a result of the rising crypto bug bounties] however in the long run, very, very doubtless.”

Sherrets thinks it’s vital to know why these bug bounties are so excessive for good contract tasks. “There’s a actual must have some sort of a payout that is smart. With MakerDAO having a $10 million bounty, you could have billions locked up, in order that’s a drop within the bucket. It turns into like a advertising initiative. The bounties are so excessive because of the want to truly have a powerful safety posture and mission the robust safety posture to get extra customers concerned. It simply is smart because it pertains to how a lot cash is sitting in these good contracts.”

Conventional hackers must retool for the crypto market

Proper now, in accordance with Sherrets, the hackers that usually take part in conventional bug bounty packages lack the required expertise to take part in cryptocurrency bug bounty packages. These white-hat hackers must retool their customary IT skillsets and study extra about cryptocurrency. “I could possibly be one of many prime net hackers on the planet, but when I am not accustomed to how an automatic market maker [a part of decentralized exchanges introduced to remove any intermediaries in the trading of cryptocurrency assets] works, if I do not perceive that as a hacker, I am not going to have the ability to work out methods to take advantage of that,” Sherrets says.

Bounties might attain lots of of hundreds of thousands of {dollars}

For these causes, bug bounty hunters within the conventional area will take at the least two years to come back on top of things the place they will earn severe cash within the crypto world. “There’s extra of a studying curve than hackers simply saying, ‘Okay, I need to hack on Net 3.0 at present,’” Sherrets says.

Lengthy-term, “for those who settle for the premise that that is the place the long run goes, you then’ll see much more individuals simply diving straight into this,” Sherrets says. That’s when conventional bug bounty packages will actually begin to really feel the stress to extend their payouts to lure proficient hackers.

Furthermore, long-term legacy web firms will likely be incorporating extra good contracts and blockchain applied sciences into their choices, which can spur much more hackers to leap into the Web3 world. Even at present, TikTok, Twitter, GameStop, and different main tech-based firms are incorporating Web3 options equivalent to non-fungible tokens (NFTs) into their providers.

“The scale of this market is mainly untapped,” Amador says. “The factor to think about is that MakerDAO has $15 billion to $20 billion in its contracts at present, a very huge, huge quantity of capital, greater than many international locations have circulating of their banks. Consequently, there’s an incentive to guard that’s extraordinarily excessive. There is not any motive to imagine that bug bounties will not get into the lots of of hundreds of thousands of {dollars}.”

Copyright © 2022 IDG Communications, Inc.



Source link

Related

Tags: bountiesbugcryptocurrencyexpectedHackinglureSkyrocketingtalentTop
RealHacker Staff

RealHacker Staff

Recommended.

The Galaxy Z Flip 4 might fix one of the things you hate about its predecessor

The Galaxy Z Flip 4 might fix one of the things you hate about its predecessor

June 12, 2022
How to change your Reddit username

How to change your Reddit username

April 20, 2022

Trending.

Hypex Presents New Nilai500 DIY Audio Amplifier Module

Hypex Presents New Nilai500 DIY Audio Amplifier Module

May 16, 2022
ADPTR Audio Sculpt review: A must-have dynamics plug-in for mastering and mixing engineers

ADPTR Audio Sculpt review: A must-have dynamics plug-in for mastering and mixing engineers

March 15, 2022
12 best rotary mixers for DJs

12 best rotary mixers for DJs

March 16, 2022
NAMM 2022: Audeze partners Manny Marroquin on the Manny MM-500 headphones

NAMM 2022: Audeze partners Manny Marroquin on the Manny MM-500 headphones

June 3, 2022
Behringer synthesizers 2022: Every hardware instrument Behringer is working on

Behringer synthesizers 2022: Every hardware instrument Behringer is working on

April 12, 2022

Follow Us

Categories

  • Applications
  • Audio
  • Camera
  • Computers
  • Gaming
  • Gear
  • Laptop
  • Metaverse
  • Microsoft
  • Photography
  • Review
  • Security
  • Smartphone
  • Uncategorized

Recent News

Meta introduces Instagram Reels APIs for developers – TechCrunch

Meta introduces Instagram Reels APIs for developers – TechCrunch

June 27, 2022
How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

How To Get Every Free Reward From Apex Legends Mobile’s Latest Login Event

June 27, 2022
  • DMCA
  • Disclaimer
  • Terms and Conditions
  • Cookie Privacy Policy
  • Privacy Policy
  • Contact
  • Advertise

© 2019 - theme develop by real hacker news.

No Result
View All Result
  • Home
  • Review
  • Applications
  • Computers
  • Gaming
  • Gear
    • Audio
    • Camera
    • Smartphone
  • Microsoft
  • Photography
  • Security

© 2019 - theme develop by real hacker news.

error: Content is protected !!