418sec / huntr

Public Roadmap | huntr.dev
https://huntr.dev
265 stars 90 forks source link

Confusion around how prize pot freezing works #2199

Closed JamieSlome closed 2 years ago

JamieSlome commented 2 years ago

Reference: https://www.huntr.dev/bounties/ea82cfc9-b55c-41fe-ae58-0d0e0bd7ab62

Screenshot 2022-03-07 at 09 53 33
ysf commented 2 years ago

The main problem I see here is that researchers will benefit from holding back an issue until the prize pot has been filled again. This can result in an cascade over and over again. With lot of submissions when the prize is available and more people holding back for the next round.

I don't have a solution for this, I just can just deconstruct it. And of course would've liked to get a bounty for a critical issue in a big project.

psmoros commented 2 years ago

Underlying issue persists but freezing has been deprecated

ysf commented 2 years ago

Can you elaborate more? I'm still missing answers to the questions raised.