$6M Bounty Paid to White Hat Hacker Likely Averts Sizable DeFi Hack

Developers behind the Aurora protocol acknowledged they should have spotted the vulnerability much earlier

article-image

Blockworks exclusive art by axel Rangel

share

key takeaways

  • No user funds were lost or stolen before the loophole was discovered
  • Up to $200 million worth of Aurora users’ funds could have been hacked if this bug wasn’t fixed

It was almost the next market-moving DeFi hack. 

Aurora, an Ethereum Virtual machine built on the NEAR Protocol, recently paid a $6 million reward to a so-called white hat hacker for identifying a key bug. 

The hacker, known as pwning.eth, uncovered in April a critical vulnerability in Aurora’s system, which could have jeopardized up to $200 million of funds. Virtual machines power smart contracts, or transactions executed in code on the blockchain without intermediaries, on Ethereum. Aurora paid the bounty through the Immunefi platform. 

It marks one of the largest-ever known bounty payouts in DeFi (decentralized finance) history. Last month, crypto bridge Wormhole — which connects different blockchains — paid $10 million to an ethical security hacker that also discovered a bug through Immunefi’s platform.

“Such a vulnerability should have been discovered at an earlier stage of the [defense] pipeline and we have already started improving our methods to achieve that in the future,” Frank Braun, Aurora’s head of security, said in a statement Tuesday. 

Added Braun: “However this event ultimately proves that our security mechanisms work.”

The bug was initially flagged via Immunefi — crucially, before any funds were stolen. Aurora’s bounty program with Immunefi was launched in April 2022, with rewards ranging from $1,000 to $6 million, depending on severity. 

Jonah Michaels, a spokesperson for Immunefi, told Blockworks that at “a time of distrust in the markets, it’s important more than ever for Web3 projects to show that they take security seriously.”

On Immunefi’s platform, security researchers review code and disclose vulnerabilities. Through its programs with DeFi projects, Immunefi said it paid over $40 million in bounties to friendly hackers — claiming to have prevented over $20 billion in potential damages.

Aurora’s goal is to provide application developers the means to operate on Ethereum-compatible platforms under the governance of the decentralized Aurora DAO. Aurora’s scaling solution is currently responsible for $373 million of NEAR’s $786 million in total value locked, according to data provider DefiLlama.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Explore the growing intersection between crypto, macroeconomics, policy and finance with Ben Strack, Casey Wagner and Felix Jauvin. Subscribe to the Forward Guidance newsletter.

Get alpha directly in your inbox with the 0xResearch newsletter — market highlights, charts, degen trade ideas, governance updates, and more.

The Lightspeed newsletter is all things Solana, in your inbox, every day. Subscribe to daily Solana news from Jack Kubinec and Jeff Albus.

Tags

Upcoming Events

Javits Center North | 445 11th Ave

Tues - Thurs, March 18 - 20, 2025

Blockworks’ Digital Asset Summit (DAS) will feature conversations between the builders, allocators, and legislators who will shape the trajectory of the digital asset ecosystem in the US and abroad.

recent research

Research Report Templates (1).jpg

Research

With $13B in tokenized assets, strong institutional partnerships, and a clear first-mover advantage in the RWA space. The platform's methodical approach to regulatory compliance, coupled with its hybrid public-private architecture, positions it uniquely to capture significant market share in the emerging tokenization landscape. While current fee generation primarily stems from metadata transactions, the planned launch of Figure Markets, major exchange listings, and comprehensive market-making initiatives in 2025 could serve as powerful catalysts for growth.

article-image

Perena is built on the premise that as stablecoins proliferate, liquidity could fragment, and stablecoins aren’t useful if they aren’t liquid

article-image

From hackathons to trading tools and DAO governance, AI agents are redefining how we build and innovate

article-image

CME’s large bitcoin contracts are so big that investors are turning to micro bitcoin contracts

article-image

The third-largest stablecoin is going multichain for the first time in its seven-year history

article-image

Nano Labs’ news release notes confidence in bitcoin being “a reliable store of value amidst its rising global adoption”

article-image

Several big companies report third quarter earnings this week, likely moving markets