官方的 MASTR 标志 MASTR
菜单
阅读文章

钓鱼攻击、漏洞与隐私

Paid promotion · 23 Aug 2026

I’ll focus more heavily on bug bounties again. Unless this space decides that this public work, which depends entirely on support, matters enough to keep alive.

原文为英语,导航提供七种语言。

01

查看 X 原帖 ↗

I thought this was a strong investigation that revealed a lot.

I know it was long, but until a few months ago, work like this would easily go viral on my account.

That probably tells me where my time is better spent.

I’ll focus more heavily on bug bounties again. Unless this space decides that this public work, which depends entirely on support, matters enough to keep alive.

I stopped some time ago with bug bountys because I simply no longer had the time, and because too many teams failed to honour their word.

You could spend days tracing, documenting and proving a vulnerability, only to hear excuses as soon as payment was due.

I’ve started again, so let’s see how it goes.

Last week alone, I submitted 4 unsolicited vulnerability reports.

Across these 4 live apps and websites where users are actively connecting their wallets, I found 4 critical, 12 high and around 35 medium severity issues.

None of these assessments were commissioned.

2 projects have active bug bounty programs.

The other 2 stated that they would reward valid findings and the work behind them.

At a time when we are seeing more breaches, hacks and security loopholes than ever before, everyone should take this seriously.

Let's see.

相关研究

钓鱼攻击、漏洞与隐私

Privacy, surveillance and control

A discussion of surveillance, data collection and the relationship between privacy and personal autonomy.

原创文章4 min
MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包