Bug Bounty Radar

These programs are curated for ethical hackers who thrive on high-signal findings. Review the scope, align with your lab discoveries, and always follow each platform's disclosure policy.

FastAPI Cloud

HackerOne • Updated 2024-05-18

Top reward $20K

Prototype pollution in async workers and GraphQL stitching flaws.

Scope: api.fastapicloud.com, *.fastapicloud.com

Read full brief →

Supply Chain Monitor

Bugcrowd • Updated 2024-05-22

Top reward $12K

Dependency confusion, pipeline breakout, and artifact poisoning.

Scope: *.scm.dev, api.scm.dev

Read full brief →

Secure Notes

Intigriti • Updated 2024-05-17

Top reward €8K

OAuth misconfigurations, storage isolation, and advanced XSS chains.

Scope: app.securenotes.io, api.securenotes.io

Read full brief →

OpenTelemetry Hub

YesWeHack • Updated 2024-05-20

Top reward €10K

Collector escapes, tenant isolation bugs, and SSRF via exporters.

Scope: *.otelhub.dev

Read full brief →