Discussion about this post

User's avatar
yakuhito's avatar

I've experienced the issue you're describing first-hand in CircuitDAO's security competition, where the judges had to go through hundreds of reports to ultimately declare only a few issues were valid. Requiring PoCs can help, but also (sometimes) translates to more work being required to submit valid reports - and, if you're not carefully reviewing the AI slop report, you're likely not going to review the AI slop PoC either (from my experience, chatbots seem to do 'simulations' in python, which are hard to follow/invalidate). I appreciated your point about scam bug bounty programs, which is a consequence of requiring fees I haven't considered before.

I'm also a fan of Sherlock's payout criteria, which requires researchers to have at least 2 valid bugs and >20% of their total submissions to be valid. What do you think about that? https://docs.sherlock.xyz/audits/watsons/meeting-the-payout-criteria

Expand full comment
Red Rocket's avatar

Dude you gifted bra. Your brain is telling you to do the right thing for people. Just like my brain is telling me to do the right thing for people and you.

Expand full comment
2 more comments...

No posts

Ready for more?