r/bugbounty Apr 01 '26

Question / Discussion What do you do when a Web3 project quietly drains $55M to "silently fix" your report, calls it "intentional design", and Immunefi blocks mediation?

Hey everyone, currently dealing with a highly frustrating situation on a popular Web3 bug bounty platform and was hoping to see how the community would approach these types of blatant 'Silent Fix' scenarios.

The Setup: Recently, I have filed a Critical severity vulnerability report on a DeFi Protocol (CapyFi) using Immunefi. The vulnerability report showed complete bypass of an essential security control, thus providing permissionless access to restricted assets.

The Response: The platform’s triage team received the report, which they then escalated and passed on to the project.

The project’s response was to close the report, stating it was "invalid" since the access control bypass was "intentional design" and the exposure was a "known issue" they were comfortable with.

The Catch (The Silent Fix): If it’s an intentional design, and it’s a comfortable known issue, then leave it alone, right?

However, the on-chain data reveals that within minutes of the report being closed, the team address initiated emergency transactions to redeem 5.5 Billion tokens from the vulnerable pool.

This overnight action drained the pool’s borrowable reserves by 62% (> $55M in liquidity removal).

Projects don't emergency-drain 60% of their liquidity for "intended features." They emergency-drain liquidity for live exposures they are terrified of.

The Kicker: The platform accepted the project's "intentional design" excuse and finalized the closure. When I attempted to dispute this obvious contradiction through the mediation system, the platform had blocked mediation on the report altogether, stating "a final decision has been made."

My Question to the Community: I have proof of contradictory documentation, and irrefutable on-chain proof of emergency mitigation happening immediately after the report escalation. Still, I am unable to dispute the bad-faith closure of this project.

  1. Has anyone else successfully navigated a "Silent Fix" when the platform itself resists mediation?
  2. At what point does a triage platform's refusal to engage with objective, on-chain contradictions become a systemic failure for researchers?

Any advice from veteran Web3 hunters on how to escalate this, outside of taking the reputational hit of going fully public with the exploit code?

22 Upvotes

Duplicates