Just to make sure I understand correctly: all in-scope repositories for the bug bounty program have now published the advisories that were in scope when the program ran, with most of them having been published about a month ago.
Is there any reason for the remaining delay? It feels like the researchers may have been overlooked, so a short update would be really appreciated. I’m not trying to rush anything—I’d just like to understand where things currently stand.
I’ve also seen quite a few discussions about the new bug bounty program and how to set it up, so in my opinion it would be good to close out the previous program first before moving forward.
Here’s a short update of what I know. (but I’m not the closest to all of this work)
A third-party reviewer has delivered the majority of the GHSA details to ZCG, but it hasn’t been quite finalized yet. Payments will be made once everything has been finalized and collected.
In my view the main reason for the delay has been that core developers were stretched thin across development work, Ironwood, and other priorities. Things started moving in the right direction again a few weeks ago once the 3rd party reviewer began their work.
Even though the total bounties value will be higher than the initial program was set to, all eligible bounties that were submitted during the program will be paid once everything is finalized.
Maybe someone else can give some sort of timeline, but I personally don’t know how long it will take.
Thanks for the clarification, I really appreciate you taking the time to share what you know. It’s reassuring to have a bit more context on the situation, and I completely understand that things have been busy. Hopefully everything can be wrapped up smoothly when the time is right.
Hi, I also wanted to ask for clarification regarding a lightwalletd report I submitted before the bounty program was closed.
The vulnerability was confirmed, fixed, and later publicly disclosed, and I received full researcher credit for it.
Since the report was submitted while the ZCG vulnerability bounty program was still active, could ZCG clarify whether it is still being evaluated for a bounty under the previous program terms, and who is responsible for the final severity and payout decision?
Hi ouicate, were you credited for this? You can through the replies and mentions in that GitHub. Seems Zcash team will clarify who owns the report in due time.
@ouicate I think you should look at this again GHSA-h8m8-844p-v3m9 . What do you think? In terms of credit, I can clearly see my name been credited for the report.
I am just saying, maybe Zcash team will clarify more, don’t you think it will be nice to get more clarification? I will also need more clarification and how it works.
I think the credit is actually pretty clear in the advisory @prince. It says the issue was reported by you with a PoC, while the false close-to-tip status and false readiness result were independently reported by me.
This is pretty normal and has happened multiple times with other GHSAs and researchers when closely related issues are found, but with different attack vectors or root causes. They can be bundled into a single advisory while still crediting each researcher separately, and in many cases, the bounty is split accordingly.
So I think it’s best to let the @ZCG work it all out. As @zerodartz explained earlier, they’re already working on it, so there’s no need to rush. I trust they’re handling it properly, and if you can be a little patient, I’m sure it’ll work out well for you. Congrats again!