Is the security/VRP team actively monitoring security-reports@storj.io?

Hey Storj community,

Quick question has anyone here had experience submitting vulnerability reports to the Storj security team?

I’ve submitted multiple reports over the past few weeks to there reporting mail but haven’t received any acknowledgment or response. Wanted to check if this is a known issue or if there’s a better channel to reach the security team.

Not looking to discuss any specifics here just want to make sure the reports are actually being received and reviewed by someone.

Anyone from the Storj team able to help redirect this?

Thanks

Are these reports AI generated/assisted? Maybe lack of the response is the response?

Thank you for your post and for taking the time to submit reports.

Our security team actively monitors security-reports@storj.io and reviews every submission. However, we have recently seen a high volume of AI-generated reports that contain numerous hallucinations, lack supporting evidence, or describe non-issues. These require significant triage time, which can delay responses to substantive reports.

If your submissions include clear steps to reproduce, relevant logs, or other evidence, we’ll prioritize and respond promptly.

Bug bounties should have a refundable submission fee. You want to submit a security bug? Pay.

If the bug is real, you get the fee back and the bounty process starts.

If it is unsupported, non-reproducible garbage, the fee is retained.

Free intake lets every schmuck with a ChatGPT subscription and poor prompting skills dump homework on the security team. Zero risk high reward someone else does all the work. That is an asymmetric value proposition borderline abuse.

But you may miss a real bug! No. Security team can pay for ChatGPT too.

I love this so much. Over the next few months the program will continue to evolve.

-Dominick

Payable in STORJ tokens.

No the reports are not AI generated the findings were manually researched, validated, and reproduced by me, with exploitation evidence and screenshots included in every submission.

If AI was doing all the hacking for me, I probably wouldn’t be here asking whether the security team received the reports.

There were AI generated bug reports in the recent past, with no real value, so that’s why AR asked. And it’s a very common theme these days.
Thanks for making the good choise and report your findings in the proper manner.

Hello @sn0x-sharma,
Welcome to the forum!

Thank you for your efforts! I think the Security team would find them.