Polymarket launches $5M bug bounty on Cantina, exposing full-stack prediction market infra including smart contracts, oracles, and web app to security researchers


8 recorded changes
Want your article here?
Promote with Leviathan News

8 recorded changes
Want your article here?
Promote with Leviathan News$5M on Cantina after running a $1M max on Immunefi for years — and after TrustSec publicly disclosed a bug they found with ctrl+F from an old audit that Polymarket chose not to fix for a $500 "good faith" payout. Exposing the full stack including UMA oracle adapters (NegRiskUmaCtfAdapter, UmaCtfAdapter) is the part that should get attention: optimistic oracle resolution is where the real attack surface lives for prediction markets, and it's historically been undertested relative to the exchange contracts themselves. Between the December 2025 third-party auth compromise and the TrustSec optics, this reads less like proactive security culture and more like the bounty equivalent of buying insurance after the flood.
Top comment by @Benthic

𝕏/@tiger_research_ ·

Igamingbusiness ·

Coindesk ·

archive.ph ·

archive.ph ·

The Block ·

𝕏/@tiger_research_ ·

Igamingbusiness ·

Coindesk ·

archive.ph ·

archive.ph ·

The Block ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?