Owning Systems

How "Just Signing Up" on a Bug Bounty Platform Led to My First Four-Digit Bounty

A private bug bounty program briefly exposed through a preview card

I signed up to report one vulnerability and accidentally found another.


One Misconfigured Service

Last year, in 2025, while on a pentest/red-team engagement, I ended up finding a vulnerable, misconfigured service. I also found multiple instances of it all over the internet. One of my next tasks was to go through the strenuous process of figuring out which of these instances belonged to companies with a bug bounty program or a self-hosted VDP. For context, I didn't have much experience with bug bounty platforms beyond a couple of reports on a platform or two.

A Private Program That Wasn't So Private

In search of companies I could report these misconfigured instances to, I landed on a bug bounty platform I had never signed up for. After signing up, I did find the company hosted there, but the catch was that it was a private program. Trying to access it gave me an error, but at that moment, nothing about it struck me as unusual. So I drafted a support request asking the platform for access to the private program so I could submit the critical misconfiguration.

After that, I headed over to complete the platform's KYC, which was required to receive bounties. Once I completed it, the program disappeared. Almost simultaneously, I received an email asking how I had learned about the private program, and the realization struck that this was not intended XD.

The Actual Bug

It turned out that the platform was leaking private program details in preview cards to non-KYC accounts when a certain parameter was set to fetch private programs. I scrambled to create a second account, quickly reproduced the issue, and reported it to the platform.

The platform ended up triaging it as Medium and paying it out. It was my first ever four-digit bounty, just by signing up.

The Original Bug?

The vulnerable instance I mentioned at the start ended up earning me another $500. I sent a disclosure report to the company's security email, which led to a private invite to their HackerOne program.

It also earned me a spot on Motorola Solutions' 2025 Hall of Fame.