Connect with us
  • tg

Cryptocurrency

Bug bounties can help secure blockchain networks, but have mixed results

letizo News

Published

on

Bug bounties are programs organizations offer to incentivize security researchers or ethical or white hat hackers to find and report vulnerabilities in their software, websites or systems. Bug bounties aim to improve overall security by identifying and fixing potential weaknesses before malicious actors can exploit them.

Organizations that implement bug bounty programs typically establish guidelines and rules outlining the scope of the program, eligible targets, and the types of vulnerabilities they are interested in. Depending on the severity and impact of the discovered vulnerability, they may also define the rewards offered for valid bug submissions, ranging from small amounts of money to significant cash prizes.

Security researchers participate in bug bounty programs by searching for vulnerabilities in designated systems or applications. They analyze the software, conduct penetration testing, and employ various techniques to identify potential weaknesses. Once a vulnerability is discovered, it is documented and reported to the organization running the program, usually through a secure reporting channel provided by the bug bounty platform.

Upon receiving a vulnerability report, the organization’s security team verifies and validates the submission. The researcher is rewarded according to the program’s guidelines if the vulnerability is confirmed. The organization then proceeds to fix the reported vulnerability, improving the security of its software or system.

Bug bounties have gained popularity because they provide a mutually beneficial relationship. Organizations benefit from the expertise and diverse perspectives of security researchers who act as an additional layer of defense, helping identify vulnerabilities that may have been overlooked. On the other hand, researchers can showcase their skills, earn financial rewards and contribute to the overall security of digital ecosystems.

Discovering vulnerabilities within a platform’s code is crucial when it comes to protecting users. According to a report by Chainalysis, around $1.3 billion worth of crypto was stolen from exchanges, platforms and private entities.

Bug bounties can help to encourage responsible and coordinated vulnerability disclosure, encouraging researchers to report vulnerabilities to the organization first rather than exploiting them for personal gain or causing harm. They have become integral to many organizations’ security strategies, fostering a collaborative environment between security researchers and the organizations they help protect.

Getting involved

Communities can play a crucial role in bug hunting by leveraging their diverse perspectives and skill sets. When organizations engage the community, they tap into a vast pool of security researchers with varying backgrounds and experiences.

Troy Le, head of business at blockchain auditing firm Verichains, told Cointelegraph, “Bug bounty programs harness the power of the community to enhance the security of blockchain networks by engaging a wide range of skilled individuals, known as security researchers or ethical hackers.”

Le continued, “These programs incentivize participants to search for vulnerabilities and report them to the bounty organization. Organizations can leverage a diverse talent pool with varying expertise and perspectives by involving the community. Ultimately, bug bounty programs promote transparency, facilitate continuous improvement, and bolster the overall security posture of blockchain networks.”

In addition to diverse perspectives, engaging the community in bug hunting offers scalability and speed in the discovery process.

Organizations often face resource constraints, such as limited time and manpower, which can hinder their ability to thoroughly assess their systems for vulnerabilities. However, by involving the community, organizations can tap into a large pool of researchers who can work simultaneously to identify bugs.

This scalability allows for a more efficient bug discovery process, as multiple individuals can review different aspects of the system concurrently.

Another advantage of engaging the community in bug hunting is the cost-effectiveness compared to traditional security audits. Traditional audits can be expensive, involving hiring external security consultants or conducting in-house assessments. On the other hand, bug bounty programs provide a cost-effective alternative.

Recent: Google Cloud furthers Bitcoin Lightning ambitions with Voltage partnership

This pay-for-results model ensures that organizations only pay for actual bugs found, making it a more cost-efficient approach. Bug bounties can be tailored to fit an organization’s budget, and the rewards can be adjusted based on the severity and impact of the reported vulnerabilities.

Pablo Castillo, chef technology officer of Chain4Travel — the facilitator of the Camino blockchain — told Cointelegraph, “Engaging the community in bug hunting has many benefits for both organizations and security researchers. For one, it expands access to talent and expertise, allowing them to tap into a diverse set of skills and perspectives.”

Castillo continued, “This increases the chances of discovering and effectively addressing vulnerabilities, thereby improving the overall security of blockchain networks. It also fosters a positive relationship with the community, building trust and reputation within the industry.”

“For security researchers, participating in bug bounty programs is an opportunity to showcase their skills in a real-world scenario, gain recognition and potentially earn financial rewards.”

This collaboration not only strengthens the organization’s security posture but also provides recognition and rewards to the researchers for their valuable contributions. The community benefits by gaining access to real-world systems and the opportunity to sharpen their skills while making a positive impact.

Crypto projects launching without auditing

Many crypto projects launch without conducting proper security audits and instead rely on white hat hackers to uncover vulnerabilities. Several factors contribute to this phenomenon.

Firstly, the crypto industry operates in a fast-paced and highly competitive environment. Being the first to market can provide a significant advantage. Comprehensive security audits can be time-consuming, involving extensive code review, vulnerability testing and analysis. By skipping or delaying these audits, projects can expedite their launch and gain an early foothold in the market.

Secondly, crypto projects, especially startups and smaller initiatives, often face resource constraints. Conducting thorough security audits by reputable auditing firms can be expensive.

These costs include hiring external auditors, allocating time and resources for testing, and addressing the identified vulnerabilities. Projects may prioritize other aspects, such as development or marketing due to limited budgets or prioritization decisions.

Another reason is blockchains’ decentralized nature and the crypto space’s strong community-driven ethos. Many projects embrace the philosophy of decentralization, which includes distributing responsibilities and decision-making.

However, there are significant downsides to launching crypto projects without proper audits and relying solely on white hat hackers. One major downside is the increased risk of exploitation. Without a thorough codebase assessment, potential vulnerabilities and weaknesses may remain undetected. 

Malicious actors can exploit these vulnerabilities to compromise the project’s security, leading to theft of funds, unauthorized access or system manipulation. This can result in significant financial losses and reputational damage.

Another downside is the incomplete or biased nature of security assessments. While white hat hackers play a crucial role in identifying vulnerabilities, they do not provide the same level of assurance as comprehensive audits conducted by professional security firms.

White hat hackers may have biases, areas of expertise or limitations regarding time and resources. They may focus on specific aspects or vulnerabilities, potentially overlooking other critical security issues. The overall security assessment may be incomplete without a holistic view provided by a thorough audit.

Castillo said, “While white hat hackers play a critical role in identifying vulnerabilities, relying solely on them may not provide comprehensive coverage. Without proper security audits with established providers, there is a greater chance of missing critical vulnerabilities or design flaws that malicious actors could exploit.”

Castillo continued, “Inadequate security measures can lead to various risks, including potential breaches, loss of user funds, reputational damage and more. To sum up: Launching without an audit could put the project at risk of non-compliance, leading to legal issues and financial penalties.”

Furthermore, relying solely on white hat hackers may lack the accountability and quality control measures typically associated with professional audits. Auditing firms follow established methodologies, standards and best practices in security testing.

They also adhere to industry regulations and guidelines, ensuring a consistent and rigorous evaluation of the project’s security posture. In contrast, relying on ad hoc assessments by individual white hat hackers may result in inconsistent methodologies, varying levels of rigor and potential gaps in the security assessment process.

Moreover, the legal aspects surrounding the actions of white hat hackers can be ambiguous. While many projects appreciate and reward responsible disclosure, the legal implications can vary depending on the jurisdiction and project policies.

White hat hackers may face challenges in claiming rewards, receiving proper recognition, or even encountering legal repercussions in some cases. Without clear legal protection and well-defined frameworks, there can be a lack of trust and transparency between the project and the hackers.

Lastly, relying solely on white hat hackers may result in a narrower range of expertise and perspectives than a comprehensive audit. Auditing firms bring specialized knowledge, experience and a systematic approach to security testing.

They can identify complex vulnerabilities and potential attack vectors that individual hackers may miss. By skipping audits, projects risk not uncovering critical vulnerabilities that could undermine the system’s security.

Le said, “Launching crypto projects without proper security audits and relying solely on white hat hackers carries significant risks and downsides.”

Le stressed that proper security audits conducted by experienced professionals “provide a systematic and thorough evaluation of a project’s security posture.” These audits help identify vulnerabilities, design flaws and other potential risks that might go unnoticed.

“Neglecting these audits can result in serious consequences, including loss of user funds, reputational damage, regulatory issues and even project failure,” Le said. “It is essential to adopt a balanced approach that includes both bug bounty programs and professional security audits to ensure comprehensive security coverage and mitigate potential risks.”

Recent: Animoca still bullish on blockchain games, awaits license for metaverse fund

While involving white hat hackers and the community in security testing can provide valuable insights and contributions, relying solely on them without proper audits presents significant downsides.

It increases the risk of exploitation, can result in incomplete or biased security assessments, lacks accountability and quality control, offers limited legal protection, and may lead to the oversight of critical vulnerabilities.

To mitigate these downsides, crypto projects could prioritize comprehensive security audits conducted by reputable professional auditors while still leveraging the skills and enthusiasm of the community through bug bounty programs and responsible disclosure initiatives.

Collect this article as an NFT to preserve this moment in history and show your support for independent journalism in the crypto space.

Cryptocurrency

Ethereum (ETH) Price Decline, Recent Cardano (ADA) Predictions, and More: Bits Recap August 1

letizo News

Published

on

TL;DR

  • ETH slumped by 6% amid the broader market correction, but whale accumulation, a nine-year low in exchange balances, and steady ETF inflows hint at a possible rebound in the near term.

  • ADA dropped even more, yet analysts remain bullish, with some predicting a surge beyond $4 if the asset clears key resistance at $0.92.

  • BTC briefly dipped below $114,500, but an RSI near 30 suggests oversold conditions, while optimistic traders eye a breakout to $145K-$150K.

ETH Heads South

The past several hours have not been pleasant for the cryptocurrency market, which has registered a significant pullback following the latest tariffs implemented by the Trump administration.

Ethereum (ETH) is among the losers with its price dropping by 6% on a daily scale to around $3,600 (per CoinGecko’s data). Historically, August has tended to be a bearish month for the asset, with gains recorded only in 2017, 2020, and 2021. It will be interesting to see if this year proves to be among the exceptions.

ETH Monthly Returns
ETH Monthly Returns, Source: CoinGlass

On the other hand, some key factors suggest that this might be only a temporary correction, followed by another rally. Whales have scooped up thousands of ETH in the past days, signaling strong confidence and reducing the amount of coins available on the open market. 

Additionally, the number of tokens stored on crypto exchanges plummeted to a nine-year low of under 19 million. This means that investors have shifted from centralized platforms toward self-custody methods, which reduces the immediate selling pressure.

ETH Exchange Reserve
ETH Exchange Reserve, Source: CryptoQuant

The flow of capital into spot ETH ETFs remains solid, while those interested in exploring more bullish factors and optimistic price predictions can refer to our article here.

ADA’s Next Targets?

Cardano’s native token has performed even worse than ETH in the past 24 hours, slipping by 8% to approximately $0.72 (its lowest point since mid-July). 

Despite the downtrend, many analysts foresee a renewed uptrend knocking on the door. The popular X user, Ali Martinez, believes ADA’s current price structure resembles that of the last bull cycle, which was later followed by a massive rally. 

Hardy and Smith are also among the optimists. The former claimed ADA’s bull run has yet to begin, while the latter argued that the valuation could skyrocket to a new all-time high above $4 once it surpasses the breakout target of $0.92. 

What About BTC?

The primary cryptocurrency briefly dipped under $114,500 before recovering some of the losses. As of this writing, it trades at around $115,000, representing a 3.2% drop on a daily basis. 

Its negative performance coincides with the broader correction of the cryptocurrency market, as well as the actions of retail investors who appear to have shifted into selling mode.

However, many members of the crypto community believe BTC’s bull run is far from being over. X user CRYPTOWZRD forecasted a pump to $145,000 if it breaks $120,000, whereas Grypto GEMs set a target of $150,000.

Bitcoin’s Relative Strength Index (RSI), which measures the latest speed and magnitude of price changes, supports the bullish thesis. Currently, the ratio is hovering around 30, meaning the asset is oversold and may be due for a resurgence. Conversely, anything above 70 could be interpreted as a precursor of a pullback.

BTC RSI
BTC RSI, Source: CryptoWaves
SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Continue Reading

Cryptocurrency

ETH Price Falls, But Ethereum ETFs Keep Breaking Records

letizo News

Published

on

Ethereum spot ETFs have recorded net positive flows for 20 consecutive trading days.

This accumulation streak, highlighted by a $17 million net intake on July 31, stands in stark contrast to Bitcoin ETFs, which saw a $115 million exit on the same day, their first outflow after five days of gains.

Institutional Appetite

The latest run of 20 days surpassed an earlier one of 19 green days between May 16 and June 12, cut short by $2.18 million in outflows on June 13. This was followed by a few days of intermittent flows before the current spree kicked off in earnest on July 3.

It has since pushed cumulative allocations to $9.64 billion, per SoSoValue data, with July alone seeing $5.41 billion in net capital directed toward ETH ETFs, more than the combined total of the previous 11 months.

BlackRock’s ETHA remains the market leader, attracting $18.18 million on July 31 and now holding $11.37 billion in assets, representing 2.52% of ETH’s market cap. Meanwhile, Grayscale’s ETHE reported $6.8 million in withdrawals, though its $4.22 billion asset base shows its continued relevance. Fidelity’s FETH recorded a $5.62 million boost, bringing its net assets to $2.55 billion.

The momentum is striking when viewed against historical trends. The last recorded outflow was on July 8, after which funds posted some of their largest single-day gains, including $726.7 million on July 16, $602 million on July 17, and $533.8 million on July 22. These inflows helped Ethereum ETF assets climb to $21.52 billion, roughly 4.77% of the cryptocurrency’s market cap.

Ethereum Price Action

Despite the ETF-fueled demand, ETH slipped 2.4% in the last 24 hours to around $3,786, following a brief rally to $3,933 earlier this week. However, the token is up 53% in the past 30 days, outpacing Bitcoin’s rangebound movement between $116,000 and $119,000.

Industry analysts see these ETF flows as structurally bullish. Recently, QCP Capital cautioned that overheated funding rates could introduce near-term resistance around $4,000, but it stressed that continued institutional demand, paired with corporate treasuries like SharpLink Gaming and BitMine accumulating billions in ETH, may underpin further upside.

Meanwhile, on July 31, the total value traded across ETH ETFs stood at $1.28 billion. If this pace holds, it could help ETH challenge its November 2021 all-time high of $4,878 sooner than expected, potentially cementing its role as the frontrunner in an altcoin-led cycle.

SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Continue Reading

Cryptocurrency

BlackRock Ripple (XRP) ETF Coming Soon? Here’s What You Need to Know

letizo News

Published

on

Nate Geraci, President of The ETF Store, believes that the world’s largest asset manager – BlackRock – will file for an XRP ETF.

If true and if history is any indicator, this could have a long-term positive impact on XRP as an asset, following in the footsteps of ETH and even BTC.

BlackRock XRP ETF a Possibility According to Expert

Geraci believes that it’s only logical for BlackRock to file for an XRP ETF. He cited the asset manager’s attempt to position itself as a “thought leader,” and thinks that it wouldn’t make a lot of sense for the financial behemmoth to ignore a top-five non-stablecoin cryptocurrency by means of total market capitalization. He also thinks the firm will file for a spot Solana (SOL) ETF.

He also believes that they will be filing for an index-based crypto ETF:

If launching index-based crypto ETF (which I’m highly confident they will), then you’re launching individual spot ETFs. I get the “BlackRock is all in on ETH,” or “they think XRP is scam.” This is all about business. They open up flank not pursuing additional spot ETFs IMO.

To this, he also added that by failing to add more individual spot ETFs, BlackRrock would essentially send a message to their clients and prospective investors that “there will only ever be two winners in crypto: BTC and ETH.”

He also said that they are still early because one of their main competitors is still following the “blockchain, not bitcoin” meta.

XRP ETFs The New Meta?

It’s perhaps safe to assume that a major deterrent for large-scale asset managers to file for XRP ETFs was the ambiguity surrounding its legal status amid the case between the US Securities and Exchange Commission and Ripple Labs.

Now that this has almost been resolved, and following the Commission’s newfound crypto-oriented focus, investors and asset managers are far more confident in the US-based crypto company. This has also largely been reflected in XRP’s price, which is up by a staggering 400% in the last year.

Multiple companies have already filed for a spot XRP ETF, including Franklin Templeton, Bitwise, Canary Capital, Grayscale, 21Sharse, and WisdomTree.

SPECIAL OFFER (Sponsored)
Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Continue Reading

Trending

©2021-2024 Letizo All Rights Reserved