| Finding | Target | Severity | Est. Payout | Status |
|---|---|---|---|---|
| Centrifuge V3.1 Gateway.retry duplicate-execution | Centrifuge Protocol | HIGH | $15-50K DAI | Disclosed - awaiting acknowledgement |
| Date | Target | Reason | Saved |
|---|---|---|---|
| 2026-05-09 | dYdX v4 Cantina (Cosmos hook ordering) | Architecture mismatch - dYdX uses direct keeper imports + ABCI order, not hooks pattern. Banked sub-rule under Rule 36. | Cantina submission slot + 4-6h Buddy time |
| 2026-05-08 | Fireblocks MPC Bugcrowd | Pattern A docs explicitly require event_id dedup (Rule 34 sub-rule) | Bugcrowd submission slot |
| 2026-05-08 | Centrifuge V3.1 Sherlock contest 1028 | Contest finished Nov 17 2025 (Rule 35) | Sherlock submission slot - pivoted to direct disclosure |
| 2026-05-08 | Babylon Phase-2 cycles 1+2 | Disclosed GHSAs already public + Skeptic gate 4 unconfirmed | 2 Sherlock submission slots |
| 2026-05-08 | Kinepolis Lane B | Capacitor APK region-locked + OIDC findings only P5 informational | Intigriti submission slot |
| 2026-05-08 | TrueLayer cycle 2 weaponize | TrueLayer docs explicitly require event_id dedup (Rule 34 sub-rule founder) | Intigriti submission slot |
| 2026-05-08 | OpenSea + Auth0 + Adstruc sourcemaps | Tier B classified (no secrets in compiled bundles per Rule 34 logic) | 3 Bugcrowd/H1 submission slots |
| 2026-05-07 | Venly Intigriti actuator cluster | Banner-grabbing class explicitly OOS in Venly OOS list (Rule 33 founder) | Intigriti submission slot |
| # | Rule | Date | Summary |
|---|---|---|---|
| RULE 36 | Lane B pattern saturation landscape | 2026-05-08 | Track which primitives are saturated vs fresh. Spend ~50% time on novel primitive discovery. |
| RULE 35 | Verify Sherlock contest STATUS first (Step -1) | 2026-05-08 | Sherlock contest pages SPA-rendered, can't auto-extract. Browser-verify Open/Judging/Finished before scope work. |
| RULE 34 | Information-disclosure findings need exploitable follow-on (Tier A/B) | 2026-05-08 | Generalizes Rule 33 to sourcemap/openapi/banner/verbose-error/.env classes. Pure disclosure = OOS-class on most programs. |
| RULE 33 | Actuator findings need exploitable endpoint | 2026-05-07 | Pure /actuator+/info = banner-grabbing class = OOS. Need /env, /heapdump, /loggers, /shutdown to be Tier A. |
| Tier | EYE | Type | Target | Detected |
|---|---|---|---|---|
| Tier-2 | EYE 10 | all-a-records-migrated | itunes.apple.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | chrome.google.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | www.shffls.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | wiki.atom-lens.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | www.assurancewireless.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | tfb.t-mobile.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | devedge.t-mobile.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | account.t-mobile.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | sprint.com | 1h ago |
| Tier-2 | EYE 1 | state-transition | - | 4h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | www.yeswehack.com | 7h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | itunes.apple.com | 7h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | docs.immutable.com | 7h ago |
| Tier-2 | EYE 10 | cname-migration-detected | api.pinterest.com | 7h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | api.pinterest.com | 7h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | auth.immutable.com | 7h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | www.sophos.com | 7h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | docs.sophos.com | 7h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | wiki.atom-lens.com | 7h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | devedge.t-mobile.com | 7h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | account.t-mobile.com | 7h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | sprint.com | 7h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | www.yeswehack.com | 13h ago |
| Tier-2 | EYE 10 | cname-migration-detected | api.pinterest.com | 13h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | api.pinterest.com | 13h ago |
| Host | Path | Size | Files | Recovered |
|---|---|---|---|---|
| marketplace.auth0.com | /_next/static/chunks/pages/index-f374b1d... | 0.5 KB | 1 | 21h ago |
| marketplace.auth0.com | /_next/static/chunks/framework-67c9938e3... | 183.8 KB | 9 | 21h ago |
| wallet.opensea.io | /assets/index-DGk1JYWX.js.map | 9197.9 KB | 1237 | 21h ago |
| marketplace.auth0.com | /_next/static/chunks/webpack-5aadf7b0e00... | 13.4 KB | 21 | 1d ago |
| marketplace.auth0.com | /_next/static/chunks/main-7e69766e8eff35... | 656.8 KB | 134 | 1d ago |
| clients.adstruc.com | /static/js/main.45ab4b31.js.map | 15953.6 KB | 2141 | 1d ago |
| wallet.opensea.io | /assets/index-BWT8Nbv7.js.map | 9197.9 KB | 1237 | 1d ago |
| Cluster | Members |
|---|---|
| FDJ-Kindred | 16 |
| ByteDance-TLB | 8 |
| Atlassian-Edge | 7 |
| Salesforce-Experience-Cloud | 6 |
| Apple-Geneva-Staging | 5 |
| Intergamma | 4 |
| IDnow | 2 |
| Mozilla-allizom-Staging | 2 |
| AutoDiscovered-GitRepo-intergamma/shopfront | 2 |
| Host | Note | Detected |
|---|---|---|
| - | state changed suspended->active | 4h ago |
| - | state changed suspended->active | 1d ago |
| - | state changed active->suspended | 1d ago |