Not long ago, we received a message from one of our users. He reviewed our smart contract on Base and discovered a vulnerability:
The issue allows an attacker to repeatedly extract funds that have already been paid out to investors through the secondary market, without any admin keys or flash loans.
On top of that, he shared a full technical report and the exploit code with us, which helped our developers fix the vulnerability.
🤩 We admit that our platform isn't perfect, and bugs may appear when we add new features and functionality to 8lends. Our developers are professionals, but even Google, Facebook, Microsoft, Apple, Netflix, Tesla, and other major companies have bugs and bug bounty programs.
So, no one is completely safe from such bugs. But every serious company is ready to fix them and reward the people who find them.
🤩 That's why we're launching our own Bug Bounty Program.
The reward will depend on the complexity and severity of the bug.
🗯️ If you find one, send it to our email: support@8lends.io
