Based on a brand new report launched on Dec. 21, blockchain safety agency Immunefi stated that it has processed greater than $65,918,994 crypto bounties paid to moral hackers over 1,248 reviews since its inception on Dec. 9, 2020. Net 3.0 tasks listing bounty packages on ImmuneFi to encourage whitehat hackers to report vulnerabilities and declare financial rewards, which the corporate then facilitates.
The payouts seem like concentrated in nature, with bounty packages operated by Wormhole, Aurora, Polygon, Optimism, and an undisclosed agency accounting for $30.2 million value of rewards up to now yr. The median payout was $2,000, and the typical payout was $52,800. A small variety of essential vulnerability bug reviews acquired the very best rewards.
“A $5,000 bounty payout for a essential vulnerability may fit within the web2 world, for instance, nevertheless it doesn’t work within the web3 world. If the direct lack of funds for a web3 vulnerability could possibly be as much as $50 million {dollars}, then it is smart to supply a a lot bigger bounty measurement to incentivize good conduct.”
By way of vulnerability notifications, Good Contracts points took the lead, with a complete of 728 submissions, accounting for 58.3% of paid reviews. In the meantime, the Web sites and Purposes and Blockchain/Distributed Ledger Know-how (DLT) classes totaled 488 submissions (39.1) and 32 submissions (2.6%), respectively. Apparently, regardless of having a excessive variety of submissions, Web site and Purposes reviews solely represented 2.9% of complete whitehat payouts, whereas Good Contract bugs accounted for 89.6% of funds.

The bounty packages detected excessive vulnerability reviews, such because the case in Pods Finance, for a logic error that allowed for theft of yield or abuse of the rewards system on the protocol. One other contains Mushrooms Finance’s vulnerability which could possibly be probably exploited through a miner-extractable worth assault with flash bots.
The report additionally devoted a portion of ransom evaluation, revealing that malicious hackers have returned $32.7 million in funds illicitly gained from decentralized finance (DeFi) protocols throughout 5 particular conditions in 2022. Hackers have stored $6,44 million in complete ransom funds. Some specialists say that the fee of ransom to hackers quantities to giving into extortion, however almost all agree that it is significantly better to instate a bug bounty program ex ante facto. Immunefi presently gives $144 million in bounty rewards by means of Net 3.0 tasks listed on the platform.