YouMind
Sign in

Immunefi: When Responsible Disclosure Fails

@LoopGhost007
ENGLISHOct 09, 2026
164K
119
10
10
27

TL;DR

LoopGhost, a prominent blockchain security researcher, alleges that Immunefi representatives ignored his requests to report a high-severity vulnerability and eventually blocked him, undermining the platform's role in facilitating responsible disclosure.

Immunefi is blocking Responsible Vulnerability Disclosure. I have a HIGH-Severity Vulnerability ready to report, and now I'm blocked.

@immunefi @yassine3eth, what exactly do you expect security researchers to do when every available path to responsible vulnerability disclosure is closed?

Is the message you're sending to the whitehat community that exploiting your clients' protocols is easier than responsibly reporting vulnerabilities because your disclosure system is fundamentally broken?

I never thought I'd have to write something like this about a platform whose entire purpose is to protect blockchain protocols through responsible security research.

But after months of broken promises, unanswered messages, and now being blocked by the very person who promised to help me disclose vulnerabilities, I feel I have no other option than to make this public.

1. Months of promises, absolutely no resolution

I was banned from Immunefi in the past over allegations concerning my use of AI in vulnerability reports.

Since then, I've made repeated attempts to resolve the situation in good faith, demonstrating my legitimate security research experience, professional track record, and commitment to responsible disclosure.

For months, I was repeatedly told that I would receive an answer "next week."

On August 15, Yassine, an Immunefi representative who had been handling my case, personally acknowledged the delays and promised that my situation would receive a proper review by the end of September.

He explicitly stated that he did not want to keep providing uncertain deadlines and that the end of September should be considered the next realistic update window.

That deadline has now passed without the promised resolution or even a substantive update.

Every single promise Yassine made throughout this process has turned out to be empty.

Not once has he provided a meaningful explanation, a concrete status update, or any indication that my case was actually being reviewed. Just repeated assurances that I would hear back soon, followed by silence, missed deadlines, and ultimately being blocked.

Months of patience and good-faith communication, without even the courtesy of a proper response.

I find this behavior absolutely unacceptable, especially coming from someone representing a platform whose entire business depends on trust between security researchers and the protocols they protect.

And the worst part? I wasn't even asking for preferential treatment. I was simply asking Immunefi to honor its own commitments.

LoopGhost - inline image

2. Immunefi explicitly offered to help me report vulnerabilities while banned

On August 24, Yassine made another important commitment.

He told me:

"If you have any BBP you were looking to send a report for please let me know that."

In other words, although my account remained banned, Immunefi was offering me an alternative way to responsibly disclose vulnerabilities affecting protocols listed on its platform.

I appreciated that offer and trusted it.

LoopGhost - inline image

I subsequently contacted him about a vulnerability I wanted to report.

I was told that I would receive an answer the following day so I could proceed with the disclosure.

That answer never came.

Despite multiple attempts to follow up, I received no meaningful response or assistance.

Think about what this means.

A researcher attempting to responsibly disclose a security vulnerability was explicitly offered an alternative reporting channel by Immunefi, only for that channel to become completely unresponsive when it was actually needed.

This is no longer just about my account.

This is about the security of the protocols relying on Immunefi to facilitate responsible vulnerability disclosure.

3. I have now discovered another exploitable HIGH-severity vulnerability

More recently, I discovered another exploitable HIGH-severity vulnerability affecting a protocol currently listed on Immunefi.

The vulnerability has been investigated, and my report is ready for responsible disclosure.

I attempted to contact the protocol through its direct security contact, but received no response.

The only other reporting channel I know of is Immunefi, where my account remains banned.

Given Yassine's previous offer, I reached out to him again over the past few days, hoping he could help me submit the vulnerability and prevent a potential security incident.

Once again, I received no response.

Today, I opened our conversation to follow up one more time.

And I discovered something unbelievable.

Yassine had BLOCKED me.

LoopGhost - inline image

Let that sink in.

A security researcher discovers an exploitable HIGH-severity vulnerability affecting one of Immunefi's listed protocols.

He attempts to contact the protocol directly.

He receives no response.

He then contacts the Immunefi representative who personally promised to facilitate vulnerability submissions while his account remained banned.

And instead of receiving help, he discovers that the representative has blocked him.

How exactly is this protecting Immunefi's clients?

4. My track record speaks for itself

Before anyone questions whether I'm a legitimate security researcher, I think some context is important.

I'm LoopGhost, an independent blockchain security researcher.

  • Top 100 all-time researcher on HackenProof.
  • Approximately $300,000 in security research earnings in 2026 alone.
  • Extensive contributions to private bug bounty programs, vulnerability research, and blockchain security.
  • Multiple critical vulnerabilities identified and responsibly disclosed across blockchain ecosystems, including findings that exposed millions of dollars in assets to potential losses.

My research, public advisories, and security contributions are documented on GitHub:

https://github.com/loopghost

I've worked directly with blockchain teams to investigate, reproduce, and mitigate critical vulnerabilities, including protocol-level issues with potentially catastrophic financial consequences.

My work is independently verifiable.

I'm not someone trying to bypass a platform's rules to submit low-quality reports.

I'm a security researcher who has repeatedly demonstrated his ability to identify serious vulnerabilities and help protocols fix them before attackers can exploit them.

And throughout this entire dispute, I have remained patient, professional, and committed to responsible disclosure.

I have not retaliated against Immunefi or any of its clients, nor do I have any intention of doing so.

5. What message is Immunefi sending to the whitehat community?

This is the question I genuinely want Immunefi to answer.

What exactly are researchers supposed to do when they discover an exploitable vulnerability affecting one of your clients, but your platform prevents them from reporting it, your alternative disclosure channel doesn't respond, and the representative who promised to help them ultimately blocks them?

Is this really the incentive structure Immunefi wants to create?

Are researchers supposed to conclude that responsible disclosure is pointless?

Is the message that exploiting a protocol is easier than trying to protect it?

Let me be absolutely clear: I have no intention of exploiting this vulnerability. My goal has always been, and remains, to have it responsibly disclosed and mitigated before anyone else discovers it.

But a security platform should never create a situation where a researcher willing to disclose a serious vulnerability cannot find a functioning reporting channel.

Immunefi publicly positions itself as a platform connecting security researchers with protocols to prevent exploits.

Yet my experience has been the exact opposite.

Months of delays. Repeatedly missed commitments. An alternative reporting process that failed when I tried to use it. And now, being blocked while attempting to disclose another serious vulnerability.

How can protocols trust a vulnerability disclosure system that fails to receive reports from researchers actively trying to protect them?

6. What I'm asking Immunefi to do

I'm not asking for preferential treatment.

I'm asking for three very reasonable things:

  1. An immediate, functioning, confidential channel to submit the HIGH-severity vulnerability I have identified, with confirmation that the report has been received and forwarded to the appropriate security team.
  2. A proper review of my account suspension, as repeatedly promised over the past several months.
  3. An explanation of how Immunefi intends to prevent situations like this, where researchers attempting responsible disclosure are left without a working reporting channel.

I have waited patiently for months. I have respected the process. I have repeatedly tried to resolve everything privately.

Making this public was not my preferred option.

But at this point, I genuinely don't know what else I'm supposed to do.

@immunefi @MitchellAmador there is an exploitable HIGH-severity vulnerability affecting a protocol listed on your platform. I am ready and willing to report it responsibly.

Your listed protocol has not responded to my security contact attempts. Your platform prevents me from submitting. And the representative who personally offered to help me has now blocked me.

What exactly do you expect me to do?

Your clients deserve a functioning vulnerability disclosure process.

And the security researchers working to protect them deserve better than silence and broken promises.

I want this vulnerability responsibly disclosed and fixed. Please provide a working channel so that can happen.

LoopGhost

https://github.com/loopghost

One-click save

Use YouMind for AI deep reading of viral articles

Save the source, ask focused questions, summarize the argument, and turn a viral article into reusable notes in one AI workspace.

Explore YouMind
For creators

Turn your Markdown into a clean 𝕏 article

When you publish your own long-form writing, images, tables, and code blocks make 𝕏 formatting painful. YouMind turns a full Markdown draft into a clean, ready-to-post 𝕏 article.

Try Markdown to 𝕏

More patterns to decode

Recent viral articles

Explore more viral articles