I've been waiting for over 28 days for a large vulnerability to be fixed in one of the largest apps on SOL
At this point, it's becoming a joke - I can't even get a response from their security team at this point in terms of update.
🧵/1 So lets break this down
Firstly let's make this clear - Everything was reported for FREE in my spare time.
It was made clear to @phantom multiple times i don't want payment, I just want the issue fixed!!!
I reported some even more serious Vulns about 6 months ago to
👋🏼 Ron here, Head of Security @phantom. First of all, I want to reassure everyone that security is our top priority at Phantom and that there is no vulnerability that puts user funds at risk.
The issue @CloakdDev is referring to involves being able to freeze a user’s Phantom
Spent the day building out an anti-rug #SOL meme coin dashboard 🫡
Pop in the token mint & it will fetch all the info around the token & LP pools to help keep you safe!
Check it out at rugcheck.xyz$guac$mayo$king$poor
FALSE. If this is the way Phantom wants to handle security vulnerabilities I suggest you all move away asap
This directly impacts users and can cause loss of funds via multiple vectors
Security is our top priority at Phantom. We apologize for not communicating better.
We have investigated your report and have a different perspective on its severity.
We believe it does NOT make user funds vulnerable in any way.
🧵/7 - Fin
I'm not going to engage further with @phantom as they are clearly more interested in social media posts rather than actually fixing issues so we will leave it here.
To those saying "just exploit it bro" etc ;
- No, I'm here to help the community not hurt users
- We
Imagine being @phantom and not taking security seriously
That’s 2 sec researchers now (who have previous successful precedent around vulns) that are stating you don’t take anything seriously
And they still have the Gaul to say no used funds are affected?
Retardio
Going to call bullshit on this too. We have reported numerous bugs to you over our tenure that go with complete radio silence. You are the most difficult platform to get through to in almost any format.
What am i up too?
- @alpha_batem: Metaverse infrastructure & no-code metaverse creator
- @Blok_Host: Decentralised Web Hosting powered by SHDW/IPFS
- @Liquify_NFT: Instantly buy & sell NFT's for the best price
@hey_wallet send 100000 FRONK to the first 1000 retweets and follows
Crazy to think 2 years ago every VC was calling SOL a dead chain & Polygon the next big thing
Meanwhile the SOL dev community was the most cohesive & active during that time
Soo many innovations good, bad & ugly from founders willing to take the risk got us to where we are
🧵/5 - Now lets address all the inaccuracies in Ron's post
(Great job on that one, @phantom marketing team - I like the SMB3 touch)
The fact they will post blatant lies & exaggerations tells you everything about this team.
"freeze a user’s Phantom app by sending it thousands
🎉 Introducing Fluxbot - The Solana Telegram Bot
Ever been on the move and needed to ape/dump a token?
Fear no more, as Fluxbot allows you to do everything from your Telegram app!
Features:
* Token Swap & SOL Transfer
* Slippage & Priority Fee Support
* Powered by Jupiter v5