Hi, beautiful job, quite impressive digging.
I’ll be glad to be a lucky dude receiving 0.69 eth from this. History is made of small traces everywhere right ?
Dear white hat, it is so great to see the progress you and the team have made towards negotiating your white hat bounty fee. Thank you for proving that the trust we had in you was not misplaced. So many of the victims I ve talked to are elated that we are approaching the end of this ordeal and being one step closer to reacquiring our rescued funds. One mentioned that he is now finally able to get more than 2 hours of sleep per day. We look forward to the day we can resume our normal daily lives.
It seems like you feel you deserve more than 10%. However, the standard industry maximum is 10%, it is the highest amount the team can offer. One million and one hundred thousand american dollars is an incredible amount that many in the world will never see in their lifetimes, could you have imagined that you would be turning down such a generous offer 5 years ago or even one month ago?
By accepting the offer, you will be liberated from a lifetime of guilt, the burden of paranoia that lingers endlessly in the back of your mind, and the anxiety of having everything seized at any moment. Furthermore, you will be able to spend your reward freely without stress, able to off-ramp to your bank account effortlessly without scrutiny, and to interact with defi protocols without the possibility of being blacklisted and tracked down. If you continue the development of your already advanced solidity skills, earning even more is an inevitability as a future developer, auditor, or white hat.
You are about to make a decision that will define the rest of your life. We hope that you will be able to look back on your decision with pride, dignity, and a clear conscience.
I wonder how many people who have made mistakes in the past would dream to be in the position you are in right now, the crossroads between right and wrong, and how they would act differently if granted the ability to choose again given everything they knew now?
God bless
Hello. As you know two days ago we extended you a counter-offer off chain. We are extending this same offer on chain. We appreciate your effort as a white hat and propose to offer the industry standard 10% bounty: $1.1m. Any more than this is off the table and asking for more will lead people, including victims and law enforcement, to misinterpret your behaviour as black hat extortion. Should you accept this offer we will make a proposal for the DAO to be voted on as ultimately these funds will come from the DAO. We ask for a show of good faith in the meantime that you assist the users who are now close to liquidation due to the recent drop in ETH. You can find a list of the affected users in our Post Mortem.
Dear white hat, I think you've done such a great job at exposing the mistakes of the team that a blind man can see what went wrong and where the responsibility lays. They will forever be known as the devs who deployed unaudited code containing such amateur mistakes, forever haunted by the gnawing uncertainty in each smart contract they try to write, everyone that knows them will never look at them the same again, any insight they have on smart contract security will never be taken seriously by professionals, what else can be achieved by a kyc online conference?
I can say for certain that any competent dev teams watching what has unfolded will not be acting so irresponsibly in the future. For that, the smart contract development community and future users of DEFI should be thankful. What would you would you like to see before a contract is deployed on mainnet? Many would benefit from your wisdom.
Luckily for everyone involved, you were the one who found the bugs and rescued the funds. We as victims are grateful for your assurances. It seems like you want to return our rescued funds, however, we watched as you stored them in tornadocash, how are we supposed know that the funds will be returned? Furthermore, if our funds are not returned (subtracting your white hat reward), your white hat intentions, kindness, and generosity will never be recognized. Two wrongs don't make a right. To do the right thing even when we faced with injustice or the feeling like we've been wronged is one of life's toughest challenges, we believe you possess the integrity to push through and accomplish your original pure intentions.
God bless
I understand your motivation and reasoning, but this kind of action only really hurts the users. Yes, the protocol's reputation can be damaged, but crypto has an extremely short memory, and only the users who lost ETH will remember. I think bug bounties should be substantially increased to reflect the VAR, but if our mutual goals are to increase the security of DeFi, this approach can backfire. I know you want to hold the devs accountable, but this only harms those that you're allegedly trying to protect (the users) and reflects poorly on DeFi in general. Please return the funds to the affected users.
Dear you Prisma pals, you have never shown good faith! I m so disappointed with all you have done. This is just a compulsory move that you must have done! You, once again, didn t show 3 factor that I mentioned. Don t try to escape from your mistakes and to get rid of your responsibilities. If I didn t do it, others, blackhats, or sth may have done it. ***Or in some case, it could have been your perfect backdoor***. Once again, no professional developers can easily make that mistake!
Before I see what Im willing to do, do the rest! Don t play with your users time! I like to see your faces lying sincere words. Before the conference, I hope you could spend time thinking thoroughly and sincerely of what mistakes you made, and dont just thinking of pushing me and wasting ppls time.
Dear others, stay assured, you ll be fine. If I m a blackhat, I would have walked away. I m not better off from this. I dont want anything like this stupid to happen again in DEFI, and I just want ppl who made mistakes to take their responsibilities, not blaming others.
We have removed the language you disliked from the blog post as a final show of good faith. But there is little evidence that we can judge you on that you are sincere in your intention to return the assets. Most genuine white hats would have returned at least some of the funds by now. If you do not trust us to manage the return of user assets, please transfer them instead to a respected public third party. Or send them back to affected users directly yourself. But you should do so immediately to prevent further harm to the people you claim to want to protect.
From what i know already, you don t have sincerity (you didn't reply to the message early and didn't answer to the point), gratitude (you didn't thank me and the user for waiting), and remorse (you didn't apologize to users, and did not offer solutions or improvement plans). So, it's hard for me to hand over everything to you without knowing who you are. In addition, I am very dissatisfied with the words "exploit", "attack", etc.. that you wrote in the post-mortem, because in reality, my tx was purely doing the same as everyone else, and all have agreed to the terms of the smart contract you deployed. Once again, I emphasize, my actions are completely whitehat, I don't want to waste anyone's time. You guys are the ones who wasted the time because it took dozens of hours to reply to my message.
Your team is experienced, so I don t think this bug can be easily missed out like that. Now, I need to clarify that you guys are really good guys before seeing what I can do. Your team need to do an online press conference, in which all of your team must show their faces with ids (it s like KYC), and send apologies and thanks to all of your users, your investors, and me. During that session, you must specifically present the mistake you made, which party audited the smart contract, and your plan to improve security in the future (what you would do before deploying a new contract, how you react when an something you don t expect comes, etc.). Also, you need to admit that I have no responsibilities in this, and I m purely helping you guys to fix your mistakes. Out of that, you also need to change all the terms that are accusatory in the post-mortem within 12 hrs.
I'm sorry to have to do this, but in reality, many teams have acted extremely irresponsibly without facing any significant consequences. Let s settle it this week.
Last but not least, don t blame a whitehat like me because you guys made the mistakes and consider the tx illegal. It s dictatorial. You cannot agree something with others, and then judge it s wrong or it s true. No human rights. You should have been more careful before deploying your contract. I hope this would help ppl be more careful participating in defi, the teams would be more responsible, and everyone would change their minds about things like this.
I look forward to your online conference. After it happens, the amount I would keep, and the amount that I can send to you would be discussed (stay assured, most of it would be returned) and the notes would be sent to your email.
I am one of the victims in this exploit and I incurred HUGE loss (check the loss under this DM address), because of the stupid negligences in the Prisma contract. And I believe your act DID INDEED RAISE A TREMENDOUS AWARENESS of crypto users like me in the whole and broader crypto community, who should not have placed their naive trust like this. This incident taught me a SERIOUS lesson of more awareness of contract security. If you are truly wearing the whitehat, do consider the normal users like me who will be negatively impacted in their real lives. Please do the right thing.
We appreciate developers have a responsibility to take best efforts to ensure their smart contracts do not have vulnerabilities. We have always taken that responsibility seriously, and tried to ensure the smart contracts we helped develop were secured by numerous audits. In this instance a small part of the code was missed from the audit process. Once the funds are returned we will take some time to reflect on what happened here. Ultimately it is good you are ready to move to the next step and do the right thing for users. The longer this goes on the more harm there is to users and the bigger the risk becomes that your white hat starts to look like something else. From what we know already it is clear that is not your intention. Let us settle this today. Send the assets back to this address: 0xD0eFDF01DD8d650bBA8992E2c42D0bC6d441a673. You can contact us at the aforementioned email address to discuss a bounty.
Hey, I really respect that you're a white hat and your attempts to open communications with the prisma team to return the funds.
As a victim, I'm glad the exploitable funds are in your safe hands. I can't speak for the prisma team as I've recieved no response via dms, I do aknowledge that it is a difficult time for them too. It seems like your original intentions were pure, as victims, we pray that you do not stray from them, while you fight to raise better awareness for smart contract security standards, questionable developer attitudes, and accountability.
At the end of the day, we are the innocent users, many of whom have families to support, and the funds lost were a product of relentless hours of tedious labour. Many just followed the instructions on the website and with no smart contract knowledge, how were we supposed to know that a large proportion of their networth would be subject to the vulnerability once we migrated?
God bless
Before moving to the next step, I would like to move the funds to a safer place, and please answer my questions. 1, What do you think of the term "Smart Contract"? 2, Have the contract been audited before it was deployed? 3, What are the responsibilities of developers in cases like this? Im not doing this for anything but to raise better awareness on serious contract audits, on developers attitudes towards their work, and on projects responsibility.
Before moving to the next step, I would like to move the funds to a safer place, and please answer my questions. 1, What do you think of the term "Smart Contract"? 2, Have the contract been audited before it was deployed? 3, What are the responsibilities of developers in cases like this? Im not doing this for anything but to raise better awareness on serious contract audits, on developers attitudes towards their work, and on projects responsibility.