陈剑Jason
陈剑Jason|Sep 09, 2026 04:16
Regardless of black or white hats, making money is a good hat The cryptocurrency circle is definitely the best place to reward programmers. I have seen many people accuse this group of white hat hackers of being too black and secretly withholding 15% of BTC. This reminds me of the farmers and snakes who were reported and shut down by Century Home on China's largest white hat community, Yunyun Network. Founded in 2010, Uyun.com was the largest security community at that time. At that time, when the Internet was growing wild in China, it provided free vulnerability reports to many companies, including NetEase, Alipay, JD, Tencent, 12306, and so on. Uyun.com found hidden dangers such as data leakage. After discovering these vulnerabilities, traditional hackers either directly attacked for profit or extorted money from the company. However, the white hats of Uyun.com were motivated by the spirit of "chivalrous men" to maintain Internet security, and would not make a profit. They only occasionally met a few conscientious companies to give thanks. However, because their own technology is good, they have their own jobs, so this seems like Public welfare can also be maintained. The turning point came in 2015, when a white hat member of the community, Yuan Wei, discovered a vulnerability in the marriage and dating company Century Home. According to the rules, in order to ensure the authenticity of the vulnerability, it was necessary to conduct a "test attack" verification before submitting it to Yunyun.com and the corresponding company for processing. At that time, Yuan Wei did indeed obtain some data to prove the existence of the vulnerability, so he submitted it to Yunyun. Subsequently, Century Home also fixed the vulnerability and expressed gratitude to Yuan Wei. It was originally a very normal behavior, but a month later, Century Home suddenly backstabbed and reported to the police that their company's data had been illegally invaded. The police arrested Yuan Wei, which caused a huge shock to the entire white hat circle in an instant. According to the white hat workflow, discovering vulnerabilities → testing vulnerabilities → proving vulnerabilities is necessary, otherwise how do I know if the vulnerability is valid? It's like I found a key and thought it might be my neighbor's, so I tried to open the neighbor's door with the key and sure enough, it opened. So I called the neighbor and said that I had lost your key and wanted to get it from me. According to the company's logic, you invaded my system through a vulnerability without my permission. That is to say, the neighbor directly reported to the police that his keys had been taken away and even opened the door to take a stroll. Who knows why An is so worried about stealing anything? Call the police and arrest him before we talk! Then something even worse happened. The entire Yunyun website suddenly announced that it had entered a maintenance state and had never resumed operations. There were also reports online that the core founding team of Yunyun website was taken away by the police for investigation. At the same time, several other white hat platforms, including the vulnerability box, also stopped related businesses. The entire Chinese white hat ecosystem was comprehensively hit.
+4
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads