Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

CertiK Accused Of Front-Running Bug Bounties Through Subsidiary

Altszn.com by Altszn.com
June 26, 2024
in Blockchain, Crypto, DeFi, Web3
0
CertiK Accused Of Front-Running Bug Bounties Through Subsidiary
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter



Security researchers have flagged OpenBounty, a platform affiliated with CertiK, for allegedly front-running bug bounty reports.

CertiK, the smart contract auditor, is at the center of renewed controversy for allegedly seeking to front-run bug bounty reports.

On June 25, Pop Punk, the co-founder of Gaslite, a gas efficiency auditor, accused OpenBounty, a bug bounty platform incubated by Shentu — the rebranded CertiK Chain — of front-running bug bounty reports and violating the terms of service surrounding bug bounty reports.

OpenBounty ostensibly provides a platform for aggregating bug bounties and facilitating reporting web3 code vulnerabilities. However, critics believe the platform principally serves as a vehicle for front-running bounty reports to claim any rewards on offer.

“OpenBounty… appears to front-run bug bounty reports,” Pop Punk said. “This is a direct violation of many large protocol’s bug bounty terms… The more suspicious thing is that their website makes requests to a domain with CertiK in the name when you report a bounty.”

Suspicions regarding OpenBounty were first raised by h0wlu, a security researcher.

“I created a test account on their platform to check it out, thinking maybe it’s just an aggregator, but no,” h0wlu said. “They have submission forms for all these programs and the findings are sent to their API servers.”

Howlu found that OpenBounty’s APIs are hosted by the “bounty-prod.noopsbycertik.com” subdomain, further suggesting CertiK is associated with the platform. They also noted that Uniswap’s bug bounty policy states that reports must be madedirectly,and not via a third party.

“If you find a bug, report it to the protocol directly. Not some shady website associated with CertiK,” added Pop Punk. “Who [knows] if they’re going to.”

All eyes on CertiK

The OpenBounty allegations are swirling after CertiK came under fire for exploiting a vulnerability it identified on the Kraken centralized exchange to siphon $3 million from the platform last week.

Kraken accused CertiK’s researchers of holding the funds “hostage” in a bid to negotiate a bug bounty. “This is not whitehat hacking,” said Nick Percoco, chief security officer at Kraken. “This is extortion.”

Security researchers have also spoken out against CertiK in response to the controversy, accusing the firm of carrying out lazy security audits.

CertiK claimed it was merely carrying out “research” into the extent of the exploit before reporting it, and returned the funds after facing backlash.

Related: Former Certik Clients Question Security Firm’s Stronghold On Protocol Audits



Read More: thedefiant.io

Tags: accusedbountiesbugCertiKDeFiFrontRunningSubsidiary
ADVERTISEMENT

Recent

AI agents are poised to be crypto’s next major vulnerability

AI agents are poised to be crypto’s next major vulnerability

May 25, 2025
Polygon co-founder steps down, says he can no longer give his best

Polygon co-founder steps down, says he can no longer give his best

May 24, 2025
Crypto, NFTs are a lifeboat in the sinking fiat system: Finance Redefined

Crypto, NFTs are a lifeboat in the sinking fiat system: Finance Redefined

May 23, 2025

Categories

  • Bitcoin (4,653)
  • Blockchain (11,040)
  • Crypto (8,975)
  • Dark Web (486)
  • DeFi (8,216)
  • Ethereum (4,697)
  • Metaverse (7,103)
  • Monero (265)
  • NFT (1,253)
  • Solana (4,963)
  • Web3 (20,187)
  • Zcash (475)

Category

Select Category

    Advertise

    Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

    Useful Links

    Advertise
    DMCA
    Contact Us
    Privacy Policy
    Shipping & Returns
    Terms of Use

    Resources

    Exchanges
    Changelly
    Web3 Jobs

    Recent News

    AI agents are poised to be crypto’s next major vulnerability

    AI agents are poised to be crypto’s next major vulnerability

    May 25, 2025
    Polygon co-founder steps down, says he can no longer give his best

    Polygon co-founder steps down, says he can no longer give his best

    May 24, 2025

    © 2022 Altszn.com. All Rights Reserved.

    No Result
    View All Result
    • Home
      • Home – Layout 1
      • Home – Layout 2
      • Home – Layout 3

    © Altszn.com. All Rights Reserved.

    • bitcoinBitcoin (BTC) $ 107,487.00
    • ethereumEthereum (ETH) $ 2,515.81
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.30
    • bnbBNB (BNB) $ 665.08
    • solanaSolana (SOL) $ 172.44
    • usd-coinUSDC (USDC) $ 0.999790
    • dogecoinDogecoin (DOGE) $ 0.220471
    • cardanoCardano (ADA) $ 0.743947
    • tronTRON (TRX) $ 0.272989
    • staked-etherLido Staked Ether (STETH) $ 2,514.25
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 107,224.00
    • hyperliquidHyperliquid (HYPE) $ 36.79
    • suiSui (SUI) $ 3.53
    • wrapped-stethWrapped stETH (WSTETH) $ 3,027.95
    • chainlinkChainlink (LINK) $ 15.21
    • avalanche-2Avalanche (AVAX) $ 22.44
    • stellarStellar (XLM) $ 0.283181
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • bitcoin-cashBitcoin Cash (BCH) $ 414.24
    • leo-tokenLEO Token (LEO) $ 8.90
    • hedera-hashgraphHedera (HBAR) $ 0.184871
    • moneroMonero (XMR) $ 407.79
    • the-open-networkToncoin (TON) $ 2.99
    • litecoinLitecoin (LTC) $ 94.99
    • wethWETH (WETH) $ 2,513.33
    • polkadotPolkadot (DOT) $ 4.48
    • usdsUSDS (USDS) $ 0.999765
    • bitget-tokenBitget Token (BGB) $ 5.37
    • wrapped-eethWrapped eETH (WEETH) $ 2,684.50
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999000
    • pi-networkPi Network (PI) $ 0.774735
    • pepePepe (PEPE) $ 0.000013
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • whitebitWhiteBIT Coin (WBT) $ 31.82
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 107,465.00
    • aaveAave (AAVE) $ 265.38
    • daiDai (DAI) $ 0.999721
    • bittensorBittensor (TAO) $ 421.03
    • uniswapUniswap (UNI) $ 6.04
    • nearNEAR Protocol (NEAR) $ 2.70
    • aptosAptos (APT) $ 5.13
    • jito-staked-solJito Staked SOL (JITOSOL) $ 207.43
    • okbOKB (OKB) $ 51.92
    • ondo-financeOndo (ONDO) $ 0.925223
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.094824
    • ethereum-classicEthereum Classic (ETC) $ 18.13
    • kaspaKaspa (KAS) $ 0.104755
    • internet-computerInternet Computer (ICP) $ 5.13
    • bitcoinBitcoin (BTC) $ 107,487.00
    • ethereumEthereum (ETH) $ 2,515.81
    • tetherTether (USDT) $ 1.00
    • xrpXRP (XRP) $ 2.30
    • bnbBNB (BNB) $ 665.08
    • solanaSolana (SOL) $ 172.44
    • usd-coinUSDC (USDC) $ 0.999790
    • dogecoinDogecoin (DOGE) $ 0.220471
    • cardanoCardano (ADA) $ 0.743947
    • tronTRON (TRX) $ 0.272989
    • staked-etherLido Staked Ether (STETH) $ 2,514.25
    • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 107,224.00
    • hyperliquidHyperliquid (HYPE) $ 36.79
    • suiSui (SUI) $ 3.53
    • wrapped-stethWrapped stETH (WSTETH) $ 3,027.95
    • chainlinkChainlink (LINK) $ 15.21
    • avalanche-2Avalanche (AVAX) $ 22.44
    • stellarStellar (XLM) $ 0.283181
    • shiba-inuShiba Inu (SHIB) $ 0.000014
    • bitcoin-cashBitcoin Cash (BCH) $ 414.24
    • leo-tokenLEO Token (LEO) $ 8.90
    • hedera-hashgraphHedera (HBAR) $ 0.184871
    • moneroMonero (XMR) $ 407.79
    • the-open-networkToncoin (TON) $ 2.99
    • litecoinLitecoin (LTC) $ 94.99
    • wethWETH (WETH) $ 2,513.33
    • polkadotPolkadot (DOT) $ 4.48
    • usdsUSDS (USDS) $ 0.999765
    • bitget-tokenBitget Token (BGB) $ 5.37
    • wrapped-eethWrapped eETH (WEETH) $ 2,684.50
    • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999000
    • pi-networkPi Network (PI) $ 0.774735
    • pepePepe (PEPE) $ 0.000013
    • ethena-usdeEthena USDe (USDE) $ 1.00
    • whitebitWhiteBIT Coin (WBT) $ 31.82
    • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 107,465.00
    • aaveAave (AAVE) $ 265.38
    • daiDai (DAI) $ 0.999721
    • bittensorBittensor (TAO) $ 421.03
    • uniswapUniswap (UNI) $ 6.04
    • nearNEAR Protocol (NEAR) $ 2.70
    • aptosAptos (APT) $ 5.13
    • jito-staked-solJito Staked SOL (JITOSOL) $ 207.43
    • okbOKB (OKB) $ 51.92
    • ondo-financeOndo (ONDO) $ 0.925223
    • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
    • crypto-com-chainCronos (CRO) $ 0.094824
    • ethereum-classicEthereum Classic (ETC) $ 18.13
    • kaspaKaspa (KAS) $ 0.104755
    • internet-computerInternet Computer (ICP) $ 5.13