what happened to rune june? 🥲
take me back https://t.co/zdOGzTqwBh

what happened to rune june? 🥲
take me back https://t.co/zdOGzTqwBh
I have seen many such stories recently: on terrible security practices and ethos from the THORChain project, which is a shame, really, as the project's original vision is (was?) fantastic
+ unpaid bounties when their BBP was both open and closed
+ fixing reported vulnerabilities without paying or crediting the security researchers who found them
Which leads me to agree with @kayabaNerve, here ↓
> "Their track record of treating security professionals horribly, with multiple other such incidents, has done nothing but continue to the point they simply deserve to get hacked"
We are entering a new paradigm security-wise
Those who do not adapt and start applying good security practices and properly rewarding independent security researchers will become big black hat targets and die pretty quickly
thorchain:native may become one of the first real proofs of that
https://t.co/RCIplJFGXV
Be Thorchain
> Hacked 4x
> White hat reports an exploit
> Silently patch it
> Refuse bounty, claim program closed
Stop using protocols that gamble with your money
Guy with access to a $200/mo Claude Max and a spare weekend: "omg I found a P0, you owe me 10% of your TVL or else"
Yeah sure buddy, how about you share your prompt, and we'll refund you your time and token costs with a 100% premium.
(aka ~$2000)
What happened to responsible disclosure? This industry starting to become pathetic.