Bug bounty platform HackerOne severed ties with Medici Ventures-backed Voatz, the blockchain-based mobile voting app, for breach of partnership standards.Â
The removal cuts off Voatzâ access to HackerOneâs network of âethical hackersâ who trade their expertise in finding code faults for cash. HackerOne partners with corporations interested in shoring up potential security vulnerabilities. Across 1,800 total relationships and eight years, though, itâs never before kicked a partner out, said representative Samantha Spielman.
The news was first reported Monday by CyberScoop.
Spielman said Voatzâ breach of âpartnership standardsâ made the relationship unviable, despite the programâs past bug-hunting successes.Â
âAs a platform, we work tirelessly to foster that mutually beneficial relationship between security teams and the researcher community,â she said. Spielman declined to elaborate on Voatzâ standards breach.
Voatz told CoinDesk in a statement it regrets the relationshipâs âtemporary pause.â It said that HackerOne had caved to a âsmall group of researchers who, along with a few other members of the community, believe Voatz reported a researcher to the FBI.â
âThis falsehood and misinformation has been a source of animosity toward Voatz and our partners, who face consistent attacks from these researchers,â the statement said.
West Virginia Secretary of State Mac Warner said in October 2019 the Federal Bureau of Investigation was investigating an attempted breach of the app during a pilot program in 2018. West Virginia has used the app in multiple pilots, and Warner maintains that no votes have been altered to date.Â
Voatz came under the spotlight in mid-February when a group of MIT researchers released a scathing write-up highlighting myriad apparent security flaws in the app. They alleged Voatz was essentially bunk, criticized its transparency and called up election officials considering the app to maybe think twice.Â
Voatz responded with its own criticism. In a sarcasm-laced Feb. 13 press release, it called the researchersâ report unfair and their âbad faith recommendationsâ irreparably flawed.
However, earlier this month Trail of Bits published a report supporting the MIT researchersâ claims. Voatz had commissioned Trail of Bits to analyze its platform.
Voatz began working with HackerOne in August 2018 and has paid out over $6,000 to researchers through âHackerOne and other avenuesâ since. It plans to announce its own bounty program âin the coming days.â
West Virginia has dropped its partnership with the company.