Whitehat researcher disclosed uninitialized admin slot vulnerability in DABE protocol on Arbitrum, requesting bounty settlement and handover coordination.
Security & Exploits ·
A security researcher posted an on-chain message to the DABE protocol contract on Arbitrum, claiming to have identified and secured an uninitialized admin slot vulnerability. The researcher referenced a HackenProof report documenting the issue and indicated willingness to coordinate a responsible disclosure process in exchange for a bounty settlement.
The vulnerability appears to center on an administrative function that was left uninitialized within the protocol's smart contract architecture. The researcher's approach—posting the disclosure directly on-chain to the affected contract address—reflects a whitehat practice of notifying the project while seeking compensation for identifying the flaw before it could be exploited maliciously.
The message does not specify the scope of the vulnerability, the bounty amount being requested, or whether DABE protocol developers have acknowledged or responded to the disclosure. The status of any subsequent negotiations or remediation remains unclear.