Hack Club Security
Bounty Program

Find security vulnerabilities & get cold, hard cash!

Submit a report

Programs

Anything on ysws.hackclub.com is covered, along with any miscellaneous Hack Club HQ program. HCB run their own security program and you can find their policy here.

Payouts

Note: These amounts are approximations and final bounty amounts are subject to our discretion. This list is subject to change.

PII leaks (main criteria)

  • $750+Critical severitygovernment-issued ID, identity verification documents
  • $300High severityphysical address, phone numbers
  • $150Medium severitystarting at $50; private (not Slack/HCA) emails on Hack Club platforms, names (except display names), exact birthdate
  • $20Low severity10+ people; IP addresses, non-public information

Remote code execution

  • $500Root or adminroot on *.selfhosted.hackclub.com or hcb.hackclub.com, or admin on the vercel.com/@hackclub GitHub, outside Docker
  • $250+Non-rootaccess to any of the above, or RCE in a sensitive Docker container on our infrastructure. payout can go up depending on PII impact!

Other

  • $50Information disclosure or integrity violationsexposed admin panels, configuration issues, irrecoverably high impact destructive actions
  • PIIXSS, CSRF, Open Proxy/Redirectpaid according to interaction level & PII impact. HCA/Hackatime OAuth2 application secrets will be paid based on PII and access level.

Payment methods

Whichever program the bug is found in covers the payout.

AI reports

Using AI to improve your report is fine, but submissions that are entirely AI-generated with no original input will not be accepted. We want original research with real-world impact. In some cases, a 0.5x or worse multiplier will be levied on valid reports that are hard to process! You may also be banned from participating in the program.

Out of scope

Any program not participating is out of scope. Generally also out of scope, not exhaustive:

Safe harbor

We support good-faith security research: accessing a system only to find, investigate, or fix a security flaw, in a way that avoids harm to people or the public, and using what you learn to improve security.

For good-faith research conducted while this program is active, we will not bring or support legal action against you, including for bypassing measures that protect in-scope applications. If someone else brings legal action against you for that research, we will take steps to make known that you acted in good faith.

We ask the same care in return: respect privacy and make a good-faith effort not to access or destroy other people's data, report what you find promptly, and never exploit a vulnerability beyond what is needed to demonstrate it.