At a time when WazirX exchange users are anxiously awaiting the return of their funds, Shardeum, a new venture by WazirX co-founder Nischal Shetty, has announced a ₹2 crore bug bounty program. This move has drawn criticism from the WazirX community, which is still grappling with the aftermath of a massive hack and unresolved compensation issues.
What is the Shardeum Bug Bounty Program?
A bug bounty program rewards developers and coders for finding security vulnerabilities and exploits in a company’s software, as part of efforts to enhance security. Shardeum, founded by Nischal Shetty, has officially launched its second bug bounty program in collaboration with Immunefi, offering a reward pool of $250,000 (~₹2.1 crore).
This program follows the success of the first round, which ran from July 8 to August 14, 2024, and attracted significant participation from white-hat hackers. The second round of the bug bounty program began on September 4, 2024, and will end on October 16, 2024, at 12 PM UTC.
Program Categories and Rewards
The Shardeum bug bounty program is divided into two categories:
- Core Boost – With rewards up to $150,000, this focuses on vulnerabilities in the Shardus Core Protocol and Shardeum Validator Nodes. The goal is to improve platform security ahead of Shardeum’s mainnet launch, with top-tier white-hat hackers participating.
- Ancillaries Boost – This offers a $100,000 reward pool for Web2 security experts, focusing on Shardeum’s Rust and TypeScript-based infrastructure, ensuring broader platform security.
Criticism from WazirX Users
While the program aims to bolster the security of Shardeum, it has sparked controversy within the Indian blockchain community. Many WazirX users question the timing of the bug bounty program, given the ongoing funds crisis at the exchange.
WazirX has been embroiled in legal battles related to user compensation following a ₹2000 crore hack on July 18, 2024. Nischal Shetty had previously claimed in court that the exchange does not have enough funds to fully compensate all its 4.4 million users. As a result, WazirX users are frustrated with the launch of a significant bug bounty program while they still await the return of their own funds.
Importance of Bug Bounty Programs
Despite the backlash, bug bounty programs play a critical role in ensuring security, particularly in the web3 space. Shardeum’s move to offer large rewards highlights the importance of engaging the global developer community to safeguard blockchain platforms.
However, WazirX users argue that resource allocation should prioritize their funds recovery over new ventures.