Posts  / #POST-230433
REDDIT

A vulnerability with a potential impact of $200,000.

Hello,

​

I am a security researcher who discovered a vulnerability affecting Bounce Finance, and I would like to bring attention to what appears to be a significant lack of accessible security disclosure channels.

​

I have made extensive efforts to contact Bounce Finance through every available method in order to report the vulnerability responsibly and discuss a potential reward. However, I have been unable to establish direct communication. There does not appear to be an active bug bounty program, and the email addresses I found seem to be inactive or unavailable.

​

I have also attempted to reach out through comments on their X (Twitter) account and other public communication channels. Despite these efforts, I have not received a response from the appropriate team.

​

When I attempted to warn a Telegram channel moderator, I was told that I could simply provide the vulnerability details to them and that they would forward the information to the team. This approach concerns me because it does not provide a secure or verifiable disclosure process. Without direct communication with the responsible security team, I cannot be certain that the information will be handled properly.

​

I repeatedly requested direct contact with the relevant security personnel, but my messages were ignored and no response was provided.

​

The vulnerability is serious and, based on my assessment, could potentially result in losses exceeding $200,000 USD if exploited. My intention is to disclose the issue responsibly and help protect users and their funds, while also receiving fair recognition and compensation for my work.

​

Thank you for taking the time to read this message.

​

I believe the community should be aware of the apparent lack of a clear and responsive vulnerability disclosure process at Bounce Finance.