<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: usmannk</title><link>https://news.ycombinator.com/user?id=usmannk</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 13 Jun 2026 17:38:07 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=usmannk" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by usmannk in "Compiler Bug Causes Compiler Bug: How a 12-Year-Old G++ Bug Took Down Solidity"]]></title><description><![CDATA[
<p>This is about a language compiler bug. There are no takeaways about smart contracts here.</p>
]]></description><pubDate>Fri, 15 Aug 2025 18:59:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=44916216</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=44916216</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44916216</guid></item><item><title><![CDATA[New comment by usmannk in "Flipper Zero dark web firmware bypasses rolling code security"]]></title><description><![CDATA[
<p>which slide suggests this? i didnt find anything suggesting you could start a car with rollback</p>
]]></description><pubDate>Fri, 08 Aug 2025 03:06:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=44832982</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=44832982</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44832982</guid></item><item><title><![CDATA[New comment by usmannk in "QSBS Limits Raised"]]></title><description><![CDATA[
<p>you spooked me but indeed it's in the final version: <a href="https://www.congress.gov/bill/119th-congress/house-bill/1/text" rel="nofollow">https://www.congress.gov/bill/119th-congress/house-bill/1/te...</a><p>> Sec. 70431. Expansion of qualified small business stock gain exclusion.</p>
]]></description><pubDate>Sun, 06 Jul 2025 01:20:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=44476980</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=44476980</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44476980</guid></item><item><title><![CDATA[New comment by usmannk in "Stoop Coffee: A simple idea transformed my neighborhood"]]></title><description><![CDATA[
<p>aha! i geoguessed it. i live only 2 blocks away. would love if someone could email me the whatsapp link. usmann@usmannkhan.com</p>
]]></description><pubDate>Wed, 26 Mar 2025 02:03:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=43478099</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=43478099</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43478099</guid></item><item><title><![CDATA[New comment by usmannk in "Stoop Coffee: A simple idea transformed my neighborhood"]]></title><description><![CDATA[
<p>hi neighbor! i had the same thought.. looks so familiar. must be nearby</p>
]]></description><pubDate>Wed, 26 Mar 2025 01:19:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=43477874</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=43477874</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43477874</guid></item><item><title><![CDATA[New comment by usmannk in "Advent of Code 2024"]]></title><description><![CDATA[
<p>dont you find all the string parsing and manipulation to be quite painful in Swift? I tried to do AoC in Swift before and that put me off a lot. I liked doing little functional one liners but a week from now the parsing burden will be too high.</p>
]]></description><pubDate>Sun, 01 Dec 2024 21:11:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=42290760</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=42290760</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42290760</guid></item><item><title><![CDATA[New comment by usmannk in "Sei pays out $2M bug bounty"]]></title><description><![CDATA[
<p>1. This is really hard to enumerate. I basically am always doing recon and don't do it 1 target at a time either. I'd been looking at Sei's V2 upgrade code on and off for months, and made my report when they merged the v2 branch to master (this action put the code in-scope for a bounty). I'd found a handful of other critical bugs on the way but they were fixed eventually either in the course of normal development or audits. I definitely spent upwards of 40 very focused hrs in total investigating this codebase along with its dependencies Cosmos/Tendermint. Probably much more time less focused. Cosmos&TM are quite big. But those dependencies are used in many other projects too, so it can't be purely accounted towards time on Sei.<p>2. I am a very experienced security researcher/pentester/whatever we want to call it, specifically in the blockchain niche. I'm OK at the other stuff (reversing, cryptography, web, mobile, etc). Networking probably alright? I'm comfortable saying I have a good mind for security and a wide knowledge of the basics in many fields, then a very deep knowledge of a select few areas.<p>3. Idk, a lot! Upwards of 20 for sure.</p>
]]></description><pubDate>Wed, 19 Jun 2024 03:41:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=40724554</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40724554</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40724554</guid></item><item><title><![CDATA[New comment by usmannk in "Sei pays out $2M bug bounty"]]></title><description><![CDATA[
<p>The answer to this question is out there, but the reports are not published yet.<p>I caution readers to not make rash judgements on their skill like this though. These bugs are really hard to find, and it was a minor miracle that I noticed these ones at all. I actually had a whole list of critical bugs in this codebase ready to report before the V2 upgrade was merged to master (which would put it in scope for a bounty). However the auditors managed to find every single bug on my list. I only noticed the ones that eventually made it here later, by a stroke of luck, and after I had already spent a ton of time looking at this codebase without noticing them.</p>
]]></description><pubDate>Tue, 18 Jun 2024 01:51:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=40713312</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40713312</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40713312</guid></item><item><title><![CDATA[New comment by usmannk in "Sei pays out $2M bug bounty"]]></title><description><![CDATA[
<p>Typically networking. I spent some time working at a reputable firm in this space as well.<p>One way to do this is to show some chops on the competition sites and then move to one of the organized freelance firms like Spearbit or yAudit. In doing all of these things you'll inevitably meet more people, build a specialty, get some reputation, etc.</p>
]]></description><pubDate>Mon, 17 Jun 2024 22:08:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=40711655</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40711655</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40711655</guid></item><item><title><![CDATA[New comment by usmannk in "Sei pays out $2M bug bounty"]]></title><description><![CDATA[
<p>Projects are free to change their terms and the page you link has been updated since I submitted my reports. The maximum was lowered to $1M and payment currency changed from USDC to SEI.</p>
]]></description><pubDate>Mon, 17 Jun 2024 21:31:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=40711302</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40711302</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40711302</guid></item><item><title><![CDATA[New comment by usmannk in "Sei pays out $2M bug bounty"]]></title><description><![CDATA[
<p>Wire fraud, at minimum. This would constitute direct theft. Very similar cases have been tried and convicted several times now.</p>
]]></description><pubDate>Mon, 17 Jun 2024 21:27:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=40711274</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40711274</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40711274</guid></item><item><title><![CDATA[New comment by usmannk in "Sei pays out $2M bug bounty"]]></title><description><![CDATA[
<p>1. Yes, they sent me 2,000,000 USDC.<p>2. Well, I'm currently not employed full time and I do spend a lot of time bounty hunting. But I mix it in with other things as well, like competitive security reviews on <a href="https://sherlock.xyz" rel="nofollow">https://sherlock.xyz</a> or <a href="https://cantina.xyz" rel="nofollow">https://cantina.xyz</a> and private contracted security reviews.</p>
]]></description><pubDate>Mon, 17 Jun 2024 20:34:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=40710749</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40710749</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40710749</guid></item><item><title><![CDATA[New comment by usmannk in "Sei pays out $2M bug bounty"]]></title><description><![CDATA[
<p>Right, yeah. I estimated that a savvy attacker might have been able to get out with 50 or even 100m from this, but they would also go to jail. So...</p>
]]></description><pubDate>Mon, 17 Jun 2024 20:22:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=40710616</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40710616</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40710616</guid></item><item><title><![CDATA[New comment by usmannk in "Sei pays out $2M bug bounty"]]></title><description><![CDATA[
<p>It was advertised in advance, but the real gamble is on if they'll pay. If you go to my other blogpost linked in OP, you can see a case where I was owed 500k and paid 60k.<p>You're right though that it's a lot of risk. It's not something that most of the leaderboard works full time on, though some of us do. The immunefi homepage has a list of all the bounties on offer.</p>
]]></description><pubDate>Mon, 17 Jun 2024 20:21:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=40710606</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40710606</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40710606</guid></item><item><title><![CDATA[New comment by usmannk in "Sei pays out $2M bug bounty"]]></title><description><![CDATA[
<p>It's up there but not singularly so. Twice there have been $10M! You can see the leaderboard where the majority of crypto bounties are represented here (<a href="https://immunefi.com/leaderboard/" rel="nofollow">https://immunefi.com/leaderboard/</a>) but you have to search around for the actual reports.</p>
]]></description><pubDate>Mon, 17 Jun 2024 20:19:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=40710589</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40710589</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40710589</guid></item><item><title><![CDATA[New comment by usmannk in "Sei pays out $2M bug bounty"]]></title><description><![CDATA[
<p>Hey OP here, thanks for posting. Happy to answer any questions.</p>
]]></description><pubDate>Mon, 17 Jun 2024 20:17:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=40710576</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40710576</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40710576</guid></item><item><title><![CDATA[New comment by usmannk in "Sei pays out $2M bug bounty"]]></title><description><![CDATA[
<p>This one was actually USDC! Regulated, unmagic, dollar-backed beans.</p>
]]></description><pubDate>Mon, 17 Jun 2024 20:16:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=40710568</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40710568</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40710568</guid></item><item><title><![CDATA[New comment by usmannk in "How Safe Is SF?"]]></title><description><![CDATA[
<p>this data would leave you thinking valencia st is worse off than soma</p>
]]></description><pubDate>Thu, 16 May 2024 21:16:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=40383295</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=40383295</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40383295</guid></item><item><title><![CDATA[New comment by usmannk in "Why is 1 GB equal to 10^9 bytes instead of 2^30?"]]></title><description><![CDATA[
<p>why does the hardware addressability reasoning hold for RAM but not SSDs?</p>
]]></description><pubDate>Wed, 10 Apr 2024 13:27:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=39990477</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=39990477</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39990477</guid></item><item><title><![CDATA[New comment by usmannk in "Financial systems take a holiday"]]></title><description><![CDATA[
<p>> Technologists describe their systems as having “uptime” and measure it in “nines”, such as “We have five nines of uptime”, which means that a system has 99.999% uptime or, equivalently, about five minutes of downtime per year. Five nines is admirable in many circumstances and would be considered _disastrously_ below expectations for e.g. Google Search.<p>This seems wrong? 5 9s is probably a reasonable benchmark or even unattained goal for Google Search, right?</p>
]]></description><pubDate>Thu, 29 Feb 2024 22:04:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=39555817</link><dc:creator>usmannk</dc:creator><comments>https://news.ycombinator.com/item?id=39555817</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39555817</guid></item></channel></rss>