OpenBounty, linked to CertiK, faces backlash for publicly disclosing vulnerability reports from various projects. This controversial practice reveals threat levels and exact locations of vulnerable code.
Cybersecurity expert Pascal Caversaccio has called for a boycott of CertiK, emphasizing the significant security risks posed by such disclosures. Developers argue that OpenBounty should collaborate privately with affected projects instead.
OpenBounty has been accused of unauthorized data publication, including information about Uniswap and Compound protocol. Legal experts warn of potential repercussions if the platform continues without explicit permissions.
CertiK clarified that OpenBounty has been independent since 2020, though connections remain. This controversy highlights the delicate balance between transparency and security in the crypto world.
Long-term, platforms like OpenBounty must navigate these challenges to maintain credibility and effectiveness.