Bug bounty submission via Hats - no response for 7 days

Hello Safe team,

I submitted a bug bounty report via Hats Finance (project: Safe).
It has been 7 days without any response to my emails and submissions.

Per the Hats process, if no feedback is received within the expected timeframe, the next step is to request escalation. I am therefore making this note publicly to ensure proper tracking and transparency.

Could you please confirm:

  1. Whether my submission has been received and is under review.

  2. The expected timeline for classification and payout decision.

I have followed the responsible disclosure guidelines and will not share PoC details here. I simply request acknowledgment and clarity on the status.

1 Like

Sure, here are the details of my submission so it can be identified:

Title: “EOA fallbackHandler PoC”

Submitted via: app.hats.finance (Safe bounty program)

Submission date: around 2025-09-15/16 (sent via MetaMask, with ~0.28–0.30 USD gas fee on Ethereum Mainnet)

Attached file: safe-poc-file-250914124452.zip

SHA256: mu5e8fceef49f8c77bdda9082989ba14e86596c96bc3dfda19d1180a174df5748b

Screenshot: 6185aac7ecb00276.jpeg - dump.li

ZIP archive: https://anonymfile.com/LN7ly/safe-poc-file-250914124452.zip

Inline log excerpt (for quick reference):

PoC: fallbackHandler EOA acceptance check
Zero fallback handler code: 0x
EOA address: 0x7099…79C8 code: 0x acceptedBySetup: true
:check_mark: shows whether EOA fallbackHandler is accepted and shows its code (2129ms)

And having received no response, I also sent this report to security@hats.finance

Hey @An.X.

First, I would like to clarify that the submission was responded to on the 17th of September, at 3:56 PM CET (just checked the sent email timestamp). I am also confident that you received the response (as you replied to it on the same day twice at 5:19 PM CET and 5:34 PM CET).

You did request we reconsider our evaluation, and I apologize that we were not able to re-evaluate right away (unfortunately, the people that handle the submissions, including myself, were on leave). I will continue our discussion in the email thread we already have.

To be precise, on my side I only received one initial message with the text:

“Thank you for taking the time to participate in our bug bounty program.
Allowing an EOA fallback handler is not a security issue. In fact, it presents similar behaviour to the caller (with the exception of gas usage) as if address(0) – the default – were set.”

After that, I replied twice with explanations and objections regarding why this should be considered a security-relevant finding. Those were my responses to that single message.