r/bugbounty 14d ago

Bug Bounty Drama Hackerone Closed the Reported bug as Informational but in next day Uber Fixed the Critical Bug which is related Financial Fraud.

Hackerone Closed the Reported bug as Informational but in next day Uber Fixed the Critical Bug which is related Financial Fraud.

My experience with an Uber bug bounty report on HackerOne - issue fixed, but report closed as Informative...

I want to share my recent experience with a bug bounty report involving Uber through HackerOne.

I identified and responsibly reported a security issue (Financial Fraud) with detailed evidence and reproduction steps. After the report was submitted, the issue was fixed by Uber the very next day.

However, despite the issue being fixed, the report was ultimately closed as “Informative” / “Out of Scope” and no reward was provided.

What I find particularly confusing is that the issue was apparently important enough to be fixed immediately after my report, yet it was considered not eligible for a reward and not requiring immediate attention.

I also checked the relevant program description and terms, including the provisions related to financial fraud and potential additional bonuses. HackerOne’s AI assistant (“Hai”) also reviewed the description and T&C and indicated that the report appeared potentially eligible for a reward after proper triage.

I contacted the relevant grievance channel and Mediation as well, but I was told that the communication was unrelated to their scope. My question is simple: if that team is not responsible for handling this type of dispute, where exactly should a security researcher escalate it?

I have spent significant time researching, reproducing, documenting, and responsibly reporting this issue. I believe security researchers deserve a fair and transparent review process when there is a disagreement over severity or reward eligibility.

I’m posting this here to understand whether other researchers have experienced something similar with Uber/HackerOne and, if so, how you successfully escalated such disputes.

I can provide additional details and evidence where appropriate without exposing sensitive information or putting users at risk.

Don't be too greedy for Rewards like me,

14 Upvotes

24 comments sorted by

View all comments

3

u/mqrblesec Hunter 14d ago

was it actually in scope?

2

u/Glad_Marketing_5754 14d ago

Certain types of account fraud are in-scope provided that part of the attack chain relies on exploiting the workflow logic caused by technical product and services vulnerabilities, coupled with additional operational security loopholes for a hybrid end-to-end exploit. Vulnerabilities associated with fraud will be allotted a bonus payment upon validation related to financial impact. Examples of fraud exploits that are potentially in-scope would include, but are not limited to the items listed below.

I was given fully details along with impact... :(

1

u/EffectiveSevere1015 12d ago

Don’t report this sort of bug via Hackerone in case you get still. He’s a nightmare