Connect with us
  • tg

Cryptocurrency

Bug bounties can help secure blockchain networks, but have mixed results

letizo News

Published

on

Bug bounties are programs organizations offer to incentivize security researchers or ethical or white hat hackers to find and report vulnerabilities in their software, websites or systems. Bug bounties aim to improve overall security by identifying and fixing potential weaknesses before malicious actors can exploit them.

Organizations that implement bug bounty programs typically establish guidelines and rules outlining the scope of the program, eligible targets, and the types of vulnerabilities they are interested in. Depending on the severity and impact of the discovered vulnerability, they may also define the rewards offered for valid bug submissions, ranging from small amounts of money to significant cash prizes.

Security researchers participate in bug bounty programs by searching for vulnerabilities in designated systems or applications. They analyze the software, conduct penetration testing, and employ various techniques to identify potential weaknesses. Once a vulnerability is discovered, it is documented and reported to the organization running the program, usually through a secure reporting channel provided by the bug bounty platform.

Upon receiving a vulnerability report, the organization’s security team verifies and validates the submission. The researcher is rewarded according to the program’s guidelines if the vulnerability is confirmed. The organization then proceeds to fix the reported vulnerability, improving the security of its software or system.

Bug bounties have gained popularity because they provide a mutually beneficial relationship. Organizations benefit from the expertise and diverse perspectives of security researchers who act as an additional layer of defense, helping identify vulnerabilities that may have been overlooked. On the other hand, researchers can showcase their skills, earn financial rewards and contribute to the overall security of digital ecosystems.

Discovering vulnerabilities within a platform’s code is crucial when it comes to protecting users. According to a report by Chainalysis, around $1.3 billion worth of crypto was stolen from exchanges, platforms and private entities.

Bug bounties can help to encourage responsible and coordinated vulnerability disclosure, encouraging researchers to report vulnerabilities to the organization first rather than exploiting them for personal gain or causing harm. They have become integral to many organizations’ security strategies, fostering a collaborative environment between security researchers and the organizations they help protect.

Getting involved

Communities can play a crucial role in bug hunting by leveraging their diverse perspectives and skill sets. When organizations engage the community, they tap into a vast pool of security researchers with varying backgrounds and experiences.

Troy Le, head of business at blockchain auditing firm Verichains, told Cointelegraph, “Bug bounty programs harness the power of the community to enhance the security of blockchain networks by engaging a wide range of skilled individuals, known as security researchers or ethical hackers.”

Le continued, “These programs incentivize participants to search for vulnerabilities and report them to the bounty organization. Organizations can leverage a diverse talent pool with varying expertise and perspectives by involving the community. Ultimately, bug bounty programs promote transparency, facilitate continuous improvement, and bolster the overall security posture of blockchain networks.”

In addition to diverse perspectives, engaging the community in bug hunting offers scalability and speed in the discovery process.

Organizations often face resource constraints, such as limited time and manpower, which can hinder their ability to thoroughly assess their systems for vulnerabilities. However, by involving the community, organizations can tap into a large pool of researchers who can work simultaneously to identify bugs.

This scalability allows for a more efficient bug discovery process, as multiple individuals can review different aspects of the system concurrently.

Another advantage of engaging the community in bug hunting is the cost-effectiveness compared to traditional security audits. Traditional audits can be expensive, involving hiring external security consultants or conducting in-house assessments. On the other hand, bug bounty programs provide a cost-effective alternative.

Recent: Google Cloud furthers Bitcoin Lightning ambitions with Voltage partnership

This pay-for-results model ensures that organizations only pay for actual bugs found, making it a more cost-efficient approach. Bug bounties can be tailored to fit an organization’s budget, and the rewards can be adjusted based on the severity and impact of the reported vulnerabilities.

Pablo Castillo, chef technology officer of Chain4Travel — the facilitator of the Camino blockchain — told Cointelegraph, “Engaging the community in bug hunting has many benefits for both organizations and security researchers. For one, it expands access to talent and expertise, allowing them to tap into a diverse set of skills and perspectives.”

Castillo continued, “This increases the chances of discovering and effectively addressing vulnerabilities, thereby improving the overall security of blockchain networks. It also fosters a positive relationship with the community, building trust and reputation within the industry.”

“For security researchers, participating in bug bounty programs is an opportunity to showcase their skills in a real-world scenario, gain recognition and potentially earn financial rewards.”

This collaboration not only strengthens the organization’s security posture but also provides recognition and rewards to the researchers for their valuable contributions. The community benefits by gaining access to real-world systems and the opportunity to sharpen their skills while making a positive impact.

Crypto projects launching without auditing

Many crypto projects launch without conducting proper security audits and instead rely on white hat hackers to uncover vulnerabilities. Several factors contribute to this phenomenon.

Firstly, the crypto industry operates in a fast-paced and highly competitive environment. Being the first to market can provide a significant advantage. Comprehensive security audits can be time-consuming, involving extensive code review, vulnerability testing and analysis. By skipping or delaying these audits, projects can expedite their launch and gain an early foothold in the market.

Secondly, crypto projects, especially startups and smaller initiatives, often face resource constraints. Conducting thorough security audits by reputable auditing firms can be expensive.

These costs include hiring external auditors, allocating time and resources for testing, and addressing the identified vulnerabilities. Projects may prioritize other aspects, such as development or marketing due to limited budgets or prioritization decisions.

Another reason is blockchains’ decentralized nature and the crypto space’s strong community-driven ethos. Many projects embrace the philosophy of decentralization, which includes distributing responsibilities and decision-making.

However, there are significant downsides to launching crypto projects without proper audits and relying solely on white hat hackers. One major downside is the increased risk of exploitation. Without a thorough codebase assessment, potential vulnerabilities and weaknesses may remain undetected. 

Malicious actors can exploit these vulnerabilities to compromise the project’s security, leading to theft of funds, unauthorized access or system manipulation. This can result in significant financial losses and reputational damage.

Another downside is the incomplete or biased nature of security assessments. While white hat hackers play a crucial role in identifying vulnerabilities, they do not provide the same level of assurance as comprehensive audits conducted by professional security firms.

White hat hackers may have biases, areas of expertise or limitations regarding time and resources. They may focus on specific aspects or vulnerabilities, potentially overlooking other critical security issues. The overall security assessment may be incomplete without a holistic view provided by a thorough audit.

Castillo said, “While white hat hackers play a critical role in identifying vulnerabilities, relying solely on them may not provide comprehensive coverage. Without proper security audits with established providers, there is a greater chance of missing critical vulnerabilities or design flaws that malicious actors could exploit.”

Castillo continued, “Inadequate security measures can lead to various risks, including potential breaches, loss of user funds, reputational damage and more. To sum up: Launching without an audit could put the project at risk of non-compliance, leading to legal issues and financial penalties.”

Furthermore, relying solely on white hat hackers may lack the accountability and quality control measures typically associated with professional audits. Auditing firms follow established methodologies, standards and best practices in security testing.

They also adhere to industry regulations and guidelines, ensuring a consistent and rigorous evaluation of the project’s security posture. In contrast, relying on ad hoc assessments by individual white hat hackers may result in inconsistent methodologies, varying levels of rigor and potential gaps in the security assessment process.

Moreover, the legal aspects surrounding the actions of white hat hackers can be ambiguous. While many projects appreciate and reward responsible disclosure, the legal implications can vary depending on the jurisdiction and project policies.

White hat hackers may face challenges in claiming rewards, receiving proper recognition, or even encountering legal repercussions in some cases. Without clear legal protection and well-defined frameworks, there can be a lack of trust and transparency between the project and the hackers.

Lastly, relying solely on white hat hackers may result in a narrower range of expertise and perspectives than a comprehensive audit. Auditing firms bring specialized knowledge, experience and a systematic approach to security testing.

They can identify complex vulnerabilities and potential attack vectors that individual hackers may miss. By skipping audits, projects risk not uncovering critical vulnerabilities that could undermine the system’s security.

Le said, “Launching crypto projects without proper security audits and relying solely on white hat hackers carries significant risks and downsides.”

Le stressed that proper security audits conducted by experienced professionals “provide a systematic and thorough evaluation of a project’s security posture.” These audits help identify vulnerabilities, design flaws and other potential risks that might go unnoticed.

“Neglecting these audits can result in serious consequences, including loss of user funds, reputational damage, regulatory issues and even project failure,” Le said. “It is essential to adopt a balanced approach that includes both bug bounty programs and professional security audits to ensure comprehensive security coverage and mitigate potential risks.”

Recent: Animoca still bullish on blockchain games, awaits license for metaverse fund

While involving white hat hackers and the community in security testing can provide valuable insights and contributions, relying solely on them without proper audits presents significant downsides.

It increases the risk of exploitation, can result in incomplete or biased security assessments, lacks accountability and quality control, offers limited legal protection, and may lead to the oversight of critical vulnerabilities.

To mitigate these downsides, crypto projects could prioritize comprehensive security audits conducted by reputable professional auditors while still leveraging the skills and enthusiasm of the community through bug bounty programs and responsible disclosure initiatives.

Collect this article as an NFT to preserve this moment in history and show your support for independent journalism in the crypto space.

Cryptocurrency

Ripple (XRP) Price Predictions, Recent Cardano (ADA) Developments, and More: Bits Recap June 13

letizo News

Published

on

TL;DR

  • ADA is down for the day, but essential developments, such as whale purchases and ecosystem progress, can have a positive impact on the price.
  • XRP trades near $2.14, with bullish targets ranging from $2.80 to $10, while Ripple’s case versus the US SEC nears resolution.
  • ETH fell back to around $2,500. Analysts remain cautiously bullish, noting that $2,380 is a crucial support zone.

What’s New Around ADA?

Cardano’s native token suffered the negative consequences of the geopolitical tension caused by the conflict between Israel and Iran, with its price plunging by over 7% in the last 24 hours and currently trading at around $0.63.

ADA Price
ADA Price, Source: CoinGecko

Some prominent analysts on X took notice of the decline, warning that a further plunge could be incoming. Nebraskangooner, for instance, claimed that “the head and shoulders” price pattern is “potentially breaking down,” suggesting this could lead to a correction below $0.50.

However, some important developments that took place earlier this week indicate that all hope isn’t lost for the bulls. On June 10, Ali Martinez revealed that Cardano whales (those holders having between 100 million and 1 billion tokens) bought 120 million ADA in the span of just 48 hours. Back then, the USD equivalent of the stash was approximately $85 million.

Another bullish factor is the development of the Cardano ecosystem. A few days ago, the project’s founder, Charles Hoskinson, announced Cardinalthe first Bitcoin DeFi protocol on Cardano, which allows people to use BTC for staking and lending on the platform, with no custody required. 

XRP’s Price Targets

Ripple’s cross-border token was also hit by the latest correction. It currently trades at roughly $2.14, representing a 5% decline on a daily scale.

XRP Price
XRP Price, Source: CoinGecko

X user CRYPTOWZRD noted that XRP’s performance is similar to other major altcoins, arguing that “anything is possible from this level.” 

The analyst said the main daily support target is $2, claiming a bullish reversal to the $2.80 resistance level isn’t completely out of the question. However, it will heavily depend on a breakout above the daily lower high trend line. 

Another industry participant who has recently touched upon the matter is the X user Cobb. Earlier this week, the analyst forecasted that XRP’s next leg “is going to be brutal,” suggesting the price could exceed a staggering $10 per coin. 

Meanwhile, it appears that Ripple and the US Securities and Exchange Commission (SEC) are nearing an official resolution of their court dispute. Some experts, though, believe the eventual conclusion of the legal battle is unlikely to trigger any substantial volatility for XRP. 

How About ETH?

The price of the second-largest cryptocurrency surged to nearly $2,900 on June 11, marking the highest level since February. Currently, though, it is worth around $2,500, representing a 13% decline from the local top.

ETH Price
ETH Price, Source: CoinGecko

Despite the downtrend, multiple market observers remain optimistic that Ethereum (ETH) is poised to reach significant peaks, and “no war can stop it.”

The X user DevKhabib also chipped in, claiming that ETH “is still in a good area” despite the ongoing unfavorable conditions. The trader, though, expressed concerns about a potential plunge below $2,380, saying it has proven to be strong support for now. 

Earlier this week, Ali Martinez opined that investors should turn bullish only after a sustained close above $2,750. Failing that, he projected a potential drop toward $2,500 or possibly as low as $2,380.

SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Continue Reading

Cryptocurrency

Trump Urges Iran to Sign Nuclear Deal Before ‘There’s Nothing Left:’ How Will BTC Price React?

letizo News

Published

on

US President Donald Trump said he urged the Iranian authorities to sign the nuclear deal; otherwise, the situation might escalate.

BTC’s price has already experienced substantial volatility after the initial Israeli missile strikes against Iran, but has recovered some ground and now stands close to $105,000.

Trump said on his own social media platform that he “gave Iran chance after chance to make a deal. I told them, in the strongest words, to “just do it,” but no matter how hard they tried, no matter how close they got, they just couldn’t get it done.”

The POTUS blamed it on a certain “Iranian hardliner” who spoke “bravely,” but noted that all of the top military personnel are now dead. Consequently, Trump urged the nation’s leaders to sign the nuclear deal once again, or the situation could worsen.

“The United States makes the best and most lethal military equipment anywhere in the World, BY FAR, and that Israel has a lot of it, with much more to come – And they know how to use it.”

He warned that the next planned attacks will be even more brutal and Iran should make a deal before “there is nothing left, and save what was once known as the Iranian Empire.”

Israel’s strike earlier this morning led to immediate price volatility across all financial sectors. While oil went up, the ever-volatile crypto market plunged, with BTC dumping below $103,000 for the first time since last Friday.

However, the asset has recovered some ground and now stands close to $105,000. Investors should be aware that more volatility is likely to follow if the tension between the US, Iran, and Israel further escalates.

BTCUSD. Source: TradingView
BTCUSD. Source: TradingView
SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Continue Reading

Cryptocurrency

Crypto Price Analysis June-13: ETH, XRP, ADA, SOL, and HYPE

letizo News

Published

on

This week, we examine Ethereum, Ripple, Cardano, Solana, and Hype in greater detail.

Ethereum (ETH)

Ethereum began the week on a strong footing by testing the $2,800 resistance following a 10% rally. However, this suddenly came to a stop in the past 24 hours after Israel bombed Iran. The geopolitical tension pushed the whole crypto market down, and ETH erased much of its recent gains, closing the week with a modest 1% gain.

The price briefly visited the $2,400 support during its recent drop and is hovering around $2,500 at the time of this post. Hopefully, buyers will defend this support level as a breakdown here could open the way to $2,000 next.

With the market on edge due to the geopolitical context, volatility could continue to be high. So far, ETH has made a higher low, and on Wednesday, it made a higher high. This supports a bullish bias as long as the key support holds.

ETHUSDT_2025-06-13_17-13-30
Chart by TradingView

Ripple (XRP)

XRP reversed on Monday and turned bearish when it was rejected at the $2.3 resistance. With sellers taking back control, the last four daily candles closed in red, which brought the price back to the $2 support. This is why XRP closed the week in red with a 1% loss.

While this is not too concerning, the support at $2 has to hold if this cryptocurrency hopes to make higher highs later. The current momentum is bearish, but due to the low volume, sellers don’t seem interested in doing much more at this time.

Looking ahead, this cryptocurrency remains stuck in a tight range with low volatility. This has been ongoing for months, and there has been no decisive breakthrough to date. This is likely to continue to suppress the price.

XRPUSDT_2025-06-13_17-14-17
Chart by TradingView

Cardano (ADA)

ADA tried to distance itself from the $0.64 support, but in the past three days, sellers brought it back to this key level, closing the week with a 2% loss.

Ит struggled throughout May and June, and it has not been much better to date. This supports a bearish bias with momentum favoring sellers at this time. The daily MACD also turned bearish today which could put in danger the current support.

Looking ahead, if Cardano can’t hold its price above $0.64, then it could revisit $0.5 in the near future. This is a level where buyers returned in the past. Hopefully, they do it again if the key support is lost.

ADAUSDT_2025-06-13_17-13-55
Chart by TradingView

Solana (SOL)

Solana gave market participants a brief excitement when its price moved above $152, which used to act as a resistance. However, that did not last, and in the past three days, sellers returned and pushed it under $150.

With a lower low confirmed, the downtrend for Solana is likely to continue. If so, the next major support levels will be found at $130 and $118. The momentum indicators, such as the daily MACD and RSI, also remain bearish at this time.

If nothing changes in the days to come, which is unlikely considering the wider market context, then SOL has a good chance to revisit $130. This is a level that could attract buyers and lead it into a relief bounce.

SOLUSDT_2025-06-13_17-15-04
Chart by TradingView

Hype (HYPE)

HYPE made waves in the past few months, and this week is no different. It made a new all-time high at $44 and closed this week with a 15% gain. This makes it the best performer on our list and across most of the market.

This achievement also got HYPE next to ADA in terms of market cap on sites such as CoinMarketCap. If this performance continues, HYPE is well placed to challenge ADA or even TRX and DOGE in the future.

Looking ahead, HYPE remains in a clear uptrend with key resistances at $41 and $44, at the time of this post. The support level is found at $38, and the price bounced on it during its most recent pullback. If the rally continues, then expect new record prices in the future.

HYPEUSDT_2025-06-13_17-19-59
Chart by TradingView
SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Disclaimer: Information found on CryptoPotato is those of writers quoted. It does not represent the opinions of CryptoPotato on whether to buy, sell, or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk. See Disclaimer for more information.

Cryptocurrency charts by TradingView.

Continue Reading

Trending

©2021-2024 Letizo All Rights Reserved