Anything on ysws.hackclub.com is covered, along with any miscellaneous Hack Club HQ program. HCB run their own security program and you can find their policy here.
Payouts
Note: These amounts are approximations and final bounty amounts are subject to our discretion. This list is subject to change.
$150Medium severitystarting at $50; private (not Slack/HCA) emails on Hack Club platforms, names (except display names), exact birthdate
$20Low severity10+ people; IP addresses, non-public information
Remote code execution
$500Root or adminroot on *.selfhosted.hackclub.com or hcb.hackclub.com, or admin on the vercel.com/@hackclub GitHub, outside Docker
$250+Non-rootaccess to any of the above, or RCE in a sensitive Docker container on our infrastructure. payout can go up depending on PII impact!
Other
$50Information disclosure or integrity violationsexposed admin panels, configuration issues, irrecoverably high impact destructive actions
PIIXSS, CSRF, Open Proxy/Redirectpaid according to interaction level & PII impact. HCA/Hackatime OAuth2 application secrets will be paid based on PII and access level.
Payment methods
ACHUS bank transfer
Mailed checkUS only, by post
WISEInternational except for India, Iceland and Uganda
Wire transferInternational; $25 fee applied under $500
Whichever program the bug is found in covers the payout.
AI reports
Using AI to improve your report is fine, but submissions that are entirely AI-generated with no original input will not be accepted. We want original research with real-world impact. In some cases, a 0.5x or worse multiplier will be levied on valid reports that are hard to process! You may also be banned from participating in the program.
Out of scope
Any program not participating is out of scope. Generally also out of scope, not exhaustive:
pure brute force attacks
social engineering or phishing
clickjacking without significant impact
self-exploitation requiring user interaction
denial of service through resource exhaustion
platform issues on Slack that are outside our control
automated scanner output without real-world impact
scraping public Slack information or account enumeration
server side request forgery without proven meaningful impact
Safe harbor
We support good-faith security research: accessing a system only to find, investigate, or fix a security flaw, in a way that avoids harm to people or the public, and using what you learn to improve security.
For good-faith research conducted while this program is active, we will not bring or support legal action against you, including for bypassing measures that protect in-scope applications. If someone else brings legal action against you for that research, we will take steps to make known that you acted in good faith.
We ask the same care in return: respect privacy and make a good-faith effort not to access or destroy other people's data, report what you find promptly, and never exploit a vulnerability beyond what is needed to demonstrate it.