5,000USDC Total Prizes | ||
3,000 USDC 1st 1,500 USDC 2nd 500 USDC 3rd |
24
SUBMISSIONS
Syncing...
REMAINING
REDACTED TRACK
This is a track for the Redacted hackathon, hosted exclusively on Superteam Earn.
View All TracksSKILLS NEEDED
CONTACT
RELATED LIVE TRACKS
Many web3 projects do not pay enough attention to web2 security and fall victim to simple hacks through web2 components. As an example, several weeks ago time.fun was ethically hacked through their web2 components. The purpose of this bounty is to bring attention to this problem and highlight current trends, some common web2 security issues, which can be exploited in web3 scenarios, and a general conclusion on what we can do better as an industry.
Refer to the process below on what you should do. For additional details refer to the Deliverables section
Pick 2 web2 security vulnerabilities, which could be exploited in web3 scenarios in off-chain components (relayers, signers, any other backend etc).
Do a research into them
Prepare one big lab or two small labs for the web2 security vulnerabilities you picked.
Write a long-form research article to highlight the importance of paying attention to web2 security in web3, which goes over
Current trend (maybe you can refer to some other real-world incidents)
Explaining 2 security vulnerabilities you picked and possible remediations.
Conclusion and what we as an industry can do better in general to protect against web2 security issues in web3
The long-form research article posted on a blogging site (e.g. Medium, Substack, Notion, etc.) that is publicly viewable upon deadline, which covers:
The current trend of web3 projects not paying enough attention to web2 security. You can highlight some real-world incidents
2 web2 security vulnerabilities and their exploitability in web3 scenarios in off-chain components with possible remediations. You should refer to the labs you prepared as an example and optionally other real-world hacks to prove a point.
Conclusion and general practical recommendations to the industry on how we can get better protection against web2 security issues.
One big lab or two small labs on web2 security vulnerabilities you picked. The code has to be uploaded to Github, Gitlab, Bitbucket, or any other version control system of your choice. It has to be publicly viewable upon the deadline
Realism: whether the examples you showed are realistic.
Accuracy: factual accuracy of the information and the relevance of the data used
Resources: inclusion of resources to support your claims
Writing Style: quality, readability and engagement level of your content
Rich Media & Presentation: use of data dashboards, original charts, etc.
Reproducibility: ease of launching labs and reproducing issues
Brownie points for tweeting about the bounty/your submission and tagging @guvenkaya_sec, @timurguvenkaya, @heliuslabs and @SuperteamEarn in your tweet.
Please review the reasons why your submission will get rejected either through an article or a lab
Article:
If it is not written in English.
If any of the vulnerabilities you picked can be only exploited through phishing. For example, exploiting dev devices to inject malicious code on the frontend
If any of the vulnerabilities you picked refer to a supply chain attack. For example, finding a bug in a dependency used by many projects and by doing that harming the main project. We want to focus on direct exploitation.
If any of the examples do not showcase vulnerability in the web3 scenario. For example, simply SQL injection in an isolated backend does not count if it does not interact with blockchain or smart contracts and SQL injection does not lead to any loss of funds or reliability of the whole web3 system.
If any of the examples refer to the exploitation through leaked credentials
If the contents of the submission are less than 1,000 words
If it is found to be plagiarized or stolen
If it fails to include and cite proper references
Your submission is not publicly viewable on and after the submission deadline. Submissions of private links will not be eligible.
Lab(s):
If it does not have a README or it is not written in English.
If it lacks any guidelines to launch a lab and steps to reproduce issues
If it is found to be plagiarized or stolen
If it fails to include and cite proper references in the code or README
Your submission is not publicly viewable on and after the submission deadline. Submissions of private links will not be eligible.
The total prize for this bounty is 5,000 USDC, and it will be distributed based on the judges' decision as:
🥇1st Place - $3,000 USDC
🥈2nd Place - $1,500 USDC
🥉3rd Place - $500 USDC
Time.fun vulnerability disclosure: https://x.com/publicqi/status/1897124894229639418
OWASP Top-10: https://owasp.org/www-project-top-ten/
CWE Top 25: https://cwe.mitre.org/data/definitions/1430.html
SKILLS NEEDED
Content
Blockchain
Backend
CONTACT
Reach outif you have any questions about this initialBounty