frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

I just got banned by Immunefi for reporting a real replay attack on LayerZero V2

5•tangou•13h ago
I just got banned by Immunefi for reporting a real replay attack on LayerZero V2.

I discovered that lzReceive() allows infinite replays of valid cross-chain messages, due to the lack of guid tracking. This results in repeated token crediting — a critical flaw.

My PoC used real deployed contracts, no forged data. The vulnerability is 100% reproducible.

Instead of investigating, Immunefi rejected my report without a technical rebuttal — and banned me for "complexity poaching".

Full Story: https://medium.com/@tangouvitch/immunefi-banned-me-for-reporting-a-real-replay-attack-in-layerzero-v2-71d5ee0ff102

Do you think this is a valid bug? Was the ban justified? Should Immunefi be held accountable?

Curious to hear what the Ethereum community thinks.

Comments

lompad•13h ago
Interesting, can this directly be used to make money? Maybe by the employee reading your report?

Edit: Maybe send a report to steve from grc, he loves those kinds of stories.

I'm Peter Roberts, immigration attorney who does work for YC and startups. AMA

145•proberts•14h ago•249 comments

Ask HN: Any active COBOL devs here? What are you working on?

230•_false•16h ago•171 comments

Ask HN: Will AI models over time converge into the same system?

6•ThinkBeat•4h ago•6 comments

Ask HN: What Pocket alternatives did you move to?

112•ahmedfromtunis•1d ago•130 comments

Ask HN: OpenAI zero'd balance (actual money, not free credits) after inactivity

5•footempbar•10h ago•3 comments

Ask HN: Does anyone have OpenBSD projects looking for unpaid/paid help?

6•nhgiang•18h ago•1 comments

Ask HN: GCP Outage?

86•grilledchickenw•14h ago•40 comments

Ask HN: What's Your Useful Local LLM Stack?

77•Olshansky•3d ago•48 comments

Ask HN: Where do you guys find audiobooks?

24•niksmac•14h ago•54 comments

Ask HN: How did Soham Parekh get so many jobs?

319•jshchnz•2w ago•419 comments

Gmail's backup codes are useless to access account

99•Andrew_nenakhov•13h ago•95 comments

Tell HN: Notion Desktop is monitoring your audio and network

414•HoyaSaxa•1d ago•168 comments

Ask HN: Changing Developer Career Specialty

8•Rick76•1d ago•2 comments

Ask HN: Cursor is using 269,738 tokens to edit 1200 token file

4•sarpdag•18h ago•4 comments

Ask HN: Is it time to fork HN into AI/LLM and "Everything else/other?"

506•bookofjoe•3d ago•368 comments

Ask HN: How do you find free academic/scientific material?

5•codeful•1d ago•3 comments

Ask HN: What is the state of support for mutable torrents?

5•absurdistan•1d ago•1 comments

I just got banned by Immunefi for reporting a real replay attack on LayerZero V2

5•tangou•13h ago•1 comments

Ask HN: How are you tracking dev productivity without feeling micromanaging?

12•kimzhang•2d ago•10 comments

Ask HN: Is OpenAI Acquiring Cursor?

9•schappim•1d ago•6 comments

Ask HN: How do you stay on top of AI tech?

15•kleiba•3d ago•18 comments

Ask HN: What should we do about state ID legislation?

9•VerdisQuo5678•1d ago•8 comments

How big is carpooling market?

4•rutvik2601•1d ago•6 comments

Google raising Nest Aware Plus pricing by 25%

10•corywatilo•2d ago•7 comments

Ask HN: Developer-as-a-Service?

3•gerardojbaez•1d ago•13 comments

Ask HN: What is the best way to learn 3D modeling for 3D printing?

21•wand3r•3d ago•21 comments

AIHint an open standard for signed verifiable metadata readable by AI on the web

2•aihint•1d ago•1 comments

Tell HN: Humanloop acquired, sunsetting Sept 8th

12•BillinghamJ•1d ago•6 comments