#hackerone

RedPacket SecurityRedPacketSecurity
2026-03-13

HackerOne Bug Bounty Disclosure: authorization-bypass-in-starknet-snap-via-enableauthorize-parameter-leads-to-unauthorized-transaction-signing-aszx - redpacketsecurity.com/hackeron

RedPacket SecurityRedPacketSecurity
2026-03-12
RedPacket SecurityRedPacketSecurity
2026-03-12
RedPacket SecurityRedPacketSecurity
2026-03-12
RedPacket SecurityRedPacketSecurity
2026-03-12
RedPacket SecurityRedPacketSecurity
2026-03-10
daniel:// stenberg://bagder
2026-03-10

allows researchers a certain amount of "trial submissions" even when they have a signal value below the lowest accepted threshold for a specific program.

This effectively makes the signal requirement pointless for an individual project as the worst researcher on the platform might still sneak in and spend their "trials" in your program. Even when they have a signal value way below our requirement.

And they can always just create a new account and become n1nj4hack3er[num++]

RedPacket SecurityRedPacketSecurity
2026-03-09
RedPacket SecurityRedPacketSecurity
2026-03-09
RedPacket SecurityRedPacketSecurity
2026-03-09
RedPacket SecurityRedPacketSecurity
2026-03-05
RedPacket SecurityRedPacketSecurity
2026-03-05

HackerOne Bug Bounty Disclosure: dos-via-unbounded-memory-allocation-in-sendwebstream-on-fastify-v-leads-to-oom-crash-when-backpressure-is-ignored-onlybugs - redpacketsecurity.com/hackeron

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst