Aurora pays $6 mn bug bounty to ethical hacker
User funds amounting to $200 million would have been at risk if the ethical hacker pwning.eth had chosen to act otherwise instead of reporting the vulnerability
Prefer us on Google

“Such a vulnerability should have been discovered at an earlier stage of the [defence] pipeline, and we have already started improving our methods to achieve that in the future," said Frank Braun, Aurora’s head of security. “However this event ultimately proves that our security mechanisms work."
He added, “We look at the bug bounty program as the last step in a layered defence approach and will use this bug as a learning opportunity to improve earlier steps, like internal reviews and external audits."
Mitchell Amador, Immunefi’s founder and CEO, praised Aurora, saying, “Hats off to Aurora and pwning.eth for the flawless overall processing of the report. The bug was quickly patched, with no user funds lost."
The bounty payout is one of the largest bounty payouts in DeFi history to date. Another prominent payout was the $10 million bounty paid to an ethical security hacker that discovered a bug in the crypto bridge Wormhole. This bounty was also paid through the Immunefi platform.
Aurora bounty program was launched in collaboration with Immunefi in April 2022 and had rewards ranging between $1,000 to $6 million depending on the severity of the flaw discovered. Jonah Michels of Immunefi said, “at a time of distrust in the markets, it’s important more than ever for Web3 projects to show that they take security seriously."
The writer is the founder at yMedia. He ventured into crypto in 2013 and is an ETH maximalist. Twitter: @bhardwajshash
First Published: Jun 08, 2022, 17:37
Subscribe Now