Hacker News new | ask | show | jobs
by nailer 730 days ago
> Was the $2M figure advertised in advance?

https://blog.sei.io/bug-bounty/

> Where does one go about discovering bug bounties of this size?

- SECURITY.txt for individual projects.

- https://immunefi.com for blockchain in general.

- BugCrowd and HackerOne for wider tech.

I'm an infrastructure engineer though and may not be the best person to answer.

> It seems like it might be worth the gamble of taking 3-6 months off work to discover a bug of that size.

https://www.hackerone.com/ethical-hacker/meet-six-hackers-ma...

Note: I work at a foundation for another blockchain. This doesn't affect anything I wrote above, just disclosing potential CoI.