{"id":810098,"date":"2024-12-04T22:45:28","date_gmt":"2024-12-05T04:45:28","guid":{"rendered":"https:\/\/newsycanuse.com\/index.php\/2024\/12\/04\/record-breaking-2-million-bounty-offered-to-crypto-com-hackers\/"},"modified":"2024-12-04T22:45:28","modified_gmt":"2024-12-05T04:45:28","slug":"record-breaking-2-million-bounty-offered-to-crypto-com-hackers","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2024\/12\/04\/record-breaking-2-million-bounty-offered-to-crypto-com-hackers\/","title":{"rendered":"Record-Breaking $2 Million Bounty Offered To Crypto.com Hackers"},"content":{"rendered":"<div>\n<figure role=\"presentation\"><figcaption><fbs-accordion><\/p>\n<p>HackerOne and Crypto.com announce biggest ever bug bounty.<\/p>\n<p><\/fbs-accordion><small>getty<\/small><\/figcaption><\/figure>\n<p>With 100 million users across 90 countries worldwide, Singapore-based Crypto.com is one of the world\u2019s biggest crypto trading platforms. As you might imagine, then, trust is a central pillar supporting everything the organization does, and the foundations of that trust are built around security and privacy. This security-first philosophy is highlighted in the promise that security and privacy are built into the business by design and default. \u201cWe drive a zero trust, defense in depth security strategy across our systems and platforms,\u201d Crypto.com states, \u201cto continually strengthen our security posture, we invest heavily in ongoing security and privacy awareness training for all staff.\u201d And now it\u2019s investing heavily in hackers, to the record-breaking tune of $2 million. Here\u2019s what you need to know.<\/p>\n<p><a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/11\/29\/new-warning-as-venture-capitalist-scammers-net-1-billion-in-crypto\/\" target=\"_blank\" aria-label=\"Venture Capitalist Attacks Net $1 Billion In Crypto\u2014What You Need To Know\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/11\/29\/new-warning-as-venture-capitalist-scammers-net-1-billion-in-crypto\/\"><span><span>Forbes<\/span><span>Venture Capitalist Attacks Net $1 Billion In Crypto\u2014What You Need To Know<\/span><small>By <span>Davey Winder<\/span><\/small><\/span><span><span><\/span><\/span><\/a><\/p>\n<h2>Crypto.com Ups The Ante When Investing In Hackers To Find Security Issues Before They Can Be Exploited By Cybercriminals<\/h2>\n<p>Crypto.com is not new to the world of bug bounty platforms; it has had a presence on the HackerOne platform since May 2018, after all. In that time, it has paid out a total of $539,130 in <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/08\/28\/google-chrome-hackers-offered-new-250000-payday\/\" target=\"_self\" title=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/08\/28\/google-chrome-hackers-offered-new-250000-payday\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/08\/28\/google-chrome-hackers-offered-new-250000-payday\/\" aria-label=\"bounties to hackers\">bounties to hackers<\/a>, with the top bounty range, according to <a href=\"https:\/\/hackerone.com\/crypto?type=team\" rel=\"nofollow noopener noreferrer\" target=\"_blank\" title=\"https:\/\/hackerone.com\/crypto?type=team\" data-ga-track=\"ExternalLink:https:\/\/hackerone.com\/crypto?type=team\" aria-label=\"HackerOne\u2019s own statistics\">HackerOne\u2019s own statistics<\/a>, being in the $3,759 &#8211; $40,000 bracket. That could all be set to change, and how.<\/p>\n<p>That existing bug bounty program is being updated so as to increase the maximum amount payable to hackers who are successful in finding certain types of security vulnerabilities is now a truly whopping $2 million. In case you need some perspective for just how important a milestone this is, it represents the biggest bug bounty ever offered by HackerOne since it was founded in 2012.<\/p>\n<p><a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/11\/27\/the-us-government-confirms-it-hacked-itself-12-times\/\" target=\"_blank\" aria-label=\"The U.S. Government Just Hacked Itself\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/11\/27\/the-us-government-confirms-it-hacked-itself-12-times\/\"><span><span>Forbes<\/span><span>The U.S. Government Just Hacked Itself<\/span><small>By <span>Davey Winder<\/span><\/small><\/span><span><span><\/span><\/span><\/a><\/p>\n<p>\u201cSecurity and compliance are at the foundation of everything we do at Crypto.com,\u201d Kris Marszalek, CEO of Crypto.com, said, \u201cas our business and the industry continue to grow, it\u2019s critically important that we remain focused on our core principles, and this new bounty program does that by setting a new bar.\u201d Setting a new bar is something of an understatement in my opinion, this new bounty ceiling lays down a challenge to other organizations that asks how seriously do they really take security beyond the buzzwords and marketing?<\/p>\n<h2>Raising The Standard For How Organizations Should Engage With And Reward Hackers<\/h2>\n<p>If you are not used to the business of hacking then discovering that HackerOne has a chief hacking officer might come as something of a surprise, but here we are. That position his held by Chris Evans who is also the more commonly held chief information security officer. \u201cThe top programs on our platform do not just follow our best practices,\u201d Evans said, \u201cbut continuously raise the standard for how all organizations should engage with and reward ethical hackers.\u201d<\/p>\n<p>Crypto.com has something of a track record when it comes security assurance, what with being the first \u201cvirtual asset platform\u201d to gain multiple security certifications across all platforms. But chief information security officer, Jason Lau, said \u201cwhile we have dedicated significant efforts to achieve top-tier security certifications, maintaining security assurance requires continuous focus and improvement.\u201d<\/p>\n<p><a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/11\/27\/is-your-router-in-the-matrix-35-million-devices-under-blue-pill-attack\/\" target=\"_blank\" aria-label=\"Are You Already In The Matrix\u201435 Million Devices Under Blue Pill Attack\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/11\/27\/is-your-router-in-the-matrix-35-million-devices-under-blue-pill-attack\/\"><span><span>Forbes<\/span><span>Are You Already In The Matrix\u201435 Million Devices Under Blue Pill Attack<\/span><small>By <span>Davey Winder<\/span><\/small><\/span><span><span><\/span><\/span><\/a><\/p>\n<p>Which is why Crypto.com has been a respectful partner with the hacking community, which it sees as an extension to its internal security team, through the HackerOne platform. \u201cDeepening our relationship with HackerOne through this milestone,\u201d Lau concluded, \u201cand setting this landmark bounty underscores our commitment to enhancing safeguards and consumer protection.\u201d<\/p>\n<h2>Go Get \u2018Em, Hackers\u2014How To Earn That $2 Million Crypto.com Bounty<\/h2>\n<p>Which just leaves the question of whether any hackers have what it takes to grab that $2 million bounty? According to the rules of engagement for this extreme bounty range, the $2 million reward is for in-scope vulnerabilities against the platform that \u201ccould result in a significant loss of funds or a data breach.\u201d What Crypto.com doesn\u2019t do, however, is outline precisely what criteria need to be met as, it said, these are extreme edge cases. Broadly speaking, though, hackers might expect to get the big payout, in a combination of traditional fiat funds and cryptocurrencies, for finding vulnerabilities that \u201ccould result in a quick and immediate loss of over $1 million in funds\u201d to Crypto.com or its users, or that could dump customer information en masse. Go get \u2018em, hackers.<\/p>\n<p><a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/11\/21\/now-hackers-are-using-snail-mail-in-cyber-attacks-heres-how\/\" target=\"_blank\" aria-label=\"Now Hackers Are Using Snail Mail In Cyber Attacks\u2014Here\u2019s How\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/11\/21\/now-hackers-are-using-snail-mail-in-cyber-attacks-heres-how\/\"><span><span>Forbes<\/span><span>Now Hackers Are Using Snail Mail In Cyber Attacks\u2014Here\u2019s How<\/span><small>By <span>Davey Winder<\/span><\/small><\/span><span><span><\/span><\/span><\/a><\/p>\n<\/div>\n<p><a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2024\/12\/03\/record-breaking-2-million-bounty-offered-to-cryptocom-hackers\/?ref=biztoc.com\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><br \/>\n Davey Winder<\/p>\n","protected":false},"excerpt":{"rendered":"<p>HackerOne and Crypto.com announce biggest ever bug bounty. getty With 100 million users across 90 countries worldwide, Singapore-based Crypto.com is one of the world\u2019s biggest crypto trading platforms. As you might imagine, then, trust is a central pillar supporting everything the organization does, and the foundations of that trust are built around security and privacy.<\/p>\n","protected":false},"author":1,"featured_media":810099,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[308,4368],"tags":[],"class_list":{"0":"post-810098","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-million","8":"category-record-breaking"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/810098","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=810098"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/810098\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/810099"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=810098"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=810098"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=810098"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}