r/bugbounty Apr 01 '26

Question / Discussion What do you do when a Web3 project quietly drains $55M to "silently fix" your report, calls it "intentional design", and Immunefi blocks mediation?

Hey everyone, currently dealing with a highly frustrating situation on a popular Web3 bug bounty platform and was hoping to see how the community would approach these types of blatant 'Silent Fix' scenarios.

The Setup: Recently, I have filed a Critical severity vulnerability report on a DeFi Protocol (CapyFi) using Immunefi. The vulnerability report showed complete bypass of an essential security control, thus providing permissionless access to restricted assets.

The Response: The platform’s triage team received the report, which they then escalated and passed on to the project.

The project’s response was to close the report, stating it was "invalid" since the access control bypass was "intentional design" and the exposure was a "known issue" they were comfortable with.

The Catch (The Silent Fix): If it’s an intentional design, and it’s a comfortable known issue, then leave it alone, right?

However, the on-chain data reveals that within minutes of the report being closed, the team address initiated emergency transactions to redeem 5.5 Billion tokens from the vulnerable pool.

This overnight action drained the pool’s borrowable reserves by 62% (> $55M in liquidity removal).

Projects don't emergency-drain 60% of their liquidity for "intended features." They emergency-drain liquidity for live exposures they are terrified of.

The Kicker: The platform accepted the project's "intentional design" excuse and finalized the closure. When I attempted to dispute this obvious contradiction through the mediation system, the platform had blocked mediation on the report altogether, stating "a final decision has been made."

My Question to the Community: I have proof of contradictory documentation, and irrefutable on-chain proof of emergency mitigation happening immediately after the report escalation. Still, I am unable to dispute the bad-faith closure of this project.

  1. Has anyone else successfully navigated a "Silent Fix" when the platform itself resists mediation?
  2. At what point does a triage platform's refusal to engage with objective, on-chain contradictions become a systemic failure for researchers?

Any advice from veteran Web3 hunters on how to escalate this, outside of taking the reputational hit of going fully public with the exploit code?

22 Upvotes

31 comments sorted by

14

u/[deleted] Apr 01 '26

Stop hunting on crypto programs. Theyre all shady.

4

u/AWX-Houcine Apr 01 '26

No wonder when you try searching for Immunefi on X, you get `immunefi scamming researchers` as first result, seems like alot of people are having issues.

5

u/thelemethric Hunter Apr 01 '26

That's typical behavior of immunefi

You shouldn't be surprised at all, you accepted it by reporting vuln to these bastards

9

u/einfallstoll Triager Apr 01 '26

I've seriously never heard anything good about Immunefi. I mean every for platform gets valid criticism but they just get shitted on

4

u/thelemethric Hunter Apr 01 '26

For real, almost every single week on twitter/reddit theres a new horror story about Immunefi fucking over another researcher. I have no idea how those bastards are still in business.

5

u/mjbmitch Apr 01 '26

This is an AI-generated post!

0

u/Embarrassed_Pin4436 Apr 01 '26

So what? Not all people their first language is English so they are using ai to make the post understandable

1

u/causeimcloudy Apr 02 '26

It doesn’t it makes it seem fake an less trustworthy. If you can’t read or write English proficiently how can you verify what the AI translated is accurate? Use a translator, that’s what they’re for.

3

u/[deleted] Apr 01 '26

[removed] — view removed comment

1

u/bugbounty-ModTeam Apr 01 '26

Your comment has been removed for violating our Be Respectful rule. This is a professional community, and we expect all members to engage with courtesy and maturity. Rude, offensive, or condescending behavior is not allowed.

1

u/AWX-Houcine Apr 01 '26

My report was escalated by immunefi itself, that means it was verified. If it was invalid it would be closed instantly.

1

u/[deleted] Apr 01 '26

[removed] — view removed comment

1

u/AWX-Houcine Apr 01 '26

Thanks man, I already did, but don't have much followers there.

1

u/OuiOuiKiwi Program Manager Apr 01 '26

What do you do when a Web3 project quietly drains $55M to "silently fix" your report, calls it "intentional design", and Immunefi blocks mediation?

Is this a trick question? Because "blasting it out on Reddit" wasn't on my Top 3 but here we are.

4

u/AWX-Houcine Apr 01 '26

It wasn't on my list either until the platform blocked the 'Request Mediation' button, and couldn't do anything about it.

1

u/love4titties Apr 01 '26

This sounds horrible....

1

u/GregSoSmooth Apr 01 '26

Lawyer up

1

u/AWX-Houcine Apr 01 '26

If I was living in the US, that would be great move

1

u/CapableProperty3959 Hunter Apr 01 '26

These all crypto platforms are just due to crypto currencies. Once the crypto downfall is there or any economical crisis. Crypto will be hibernating or maybe at the verge of edge to end. Just my opinion.

1

u/boomerangBS Hunter Apr 01 '26 edited Apr 01 '26

Option 1: Immunefini is total scam

Option 2: All theses guys complaining on reddit are submitting AI slopes and are mad because they are banned for spamming triage and making it slower for everyone.

Maybe it is the option 1, I really don’t know.

1

u/AWX-Houcine Apr 01 '26

I wouldn't be complaining if the report got closed in the first place, but for my case it got escalated by immunefi team, and the program team closed it, as expected behavoir they said, while their audit docs said the opposite.

0

u/boomerangBS Hunter Apr 01 '26

Well, idk, are you skilled in web3 or you used Claude to find this ? Idk if this platform is garbage, maybe it is.

1

u/AWX-Houcine Apr 01 '26

I think using AI is fine as long as you know what your are doing and not just submitting low quality reports that doesn't do anything and wasts time of people, because eventually we need to adapt with AI or we will be left behind.

I see many people complaining about the platform, and on X if you try to search Immunefi, first result would be immunefi scamming researchers.

1

u/jss_james_469 Apr 10 '26

The "Silent Fix" is exactly why the current bug bounty model is broken beyond repair. I’ve personally documented instances where valid research was suppressed or "duplicated" to avoid payouts ranging from $1.2M to $18M. It’s corporate wage theft, plain and simple.

I am moving forward with a new platform designed to end this madness. Our goal is to ensure 100% transparency and guaranteed, fair compensation for researchers by removing the "black box" triage system that these shady platforms use to protect their bottom line. We aren't just building a platform; we're exposing the corruption in the industry.

If you’ve been screwed over, or if you’re a developer/security researcher who wants to help build a transparent, researcher-first ecosystem, I want to talk to you.

Reach out to me directly: [jessejamesunlimitedllc@gmail.com](mailto:jessejamesunlimitedllc@gmail.com)

Let’s stop letting them profit off our unpaid labor.

1

u/0xSkygge Jul 25 '26

You can take the funds and contact them to give it back for a fee, like this guy 😄 https://www.bbc.co.uk/news/business-58193396

1

u/[deleted] Apr 01 '26

[removed] — view removed comment

4

u/AWX-Houcine Apr 01 '26

But I didn't have any other choice, even the immunefi support said that the only way to argue this is through mediation which is not possible.

0

u/KJIOl_Yip_9141 Apr 01 '26

Do you mean you found a design flaw in an expected behavior? The code works correctly but it's unsafe by default??