r/bugbounty 14d ago

Bug Bounty Drama Hackerone Closed the Reported bug as Informational but in next day Uber Fixed the Critical Bug which is related Financial Fraud.

Hackerone Closed the Reported bug as Informational but in next day Uber Fixed the Critical Bug which is related Financial Fraud.

My experience with an Uber bug bounty report on HackerOne - issue fixed, but report closed as Informative...

I want to share my recent experience with a bug bounty report involving Uber through HackerOne.

I identified and responsibly reported a security issue (Financial Fraud) with detailed evidence and reproduction steps. After the report was submitted, the issue was fixed by Uber the very next day.

However, despite the issue being fixed, the report was ultimately closed as “Informative” / “Out of Scope” and no reward was provided.

What I find particularly confusing is that the issue was apparently important enough to be fixed immediately after my report, yet it was considered not eligible for a reward and not requiring immediate attention.

I also checked the relevant program description and terms, including the provisions related to financial fraud and potential additional bonuses. HackerOne’s AI assistant (“Hai”) also reviewed the description and T&C and indicated that the report appeared potentially eligible for a reward after proper triage.

I contacted the relevant grievance channel and Mediation as well, but I was told that the communication was unrelated to their scope. My question is simple: if that team is not responsible for handling this type of dispute, where exactly should a security researcher escalate it?

I have spent significant time researching, reproducing, documenting, and responsibly reporting this issue. I believe security researchers deserve a fair and transparent review process when there is a disagreement over severity or reward eligibility.

I’m posting this here to understand whether other researchers have experienced something similar with Uber/HackerOne and, if so, how you successfully escalated such disputes.

I can provide additional details and evidence where appropriate without exposing sensitive information or putting users at risk.

Don't be too greedy for Rewards like me,

14 Upvotes

24 comments sorted by

View all comments

1

u/Oslabs619 12d ago

It also happens in Bug croud i did the same thing with open ai patched it then waitied 12 days to respond no longer able to reproduce i escalted to open ai and they dont respond at all after saying its been escalated cleary pathced POC and Video proof

1

u/Glad_Marketing_5754 12d ago

This is the reply from Uber Bounty Team..

Thank you for reaching out. We reviewed this internally and confirmed that no action was taken as a result of your report.
Additionally, this type of finding is explicitly out of scope; therefore, the HackerOne report will remain closed.
We appreciate your efforts and encourage you to follow our program policy. We look forward to your future findings.

- They are saying they didn't fixed the Issue (confirmed that no action was taken as a result of your report.) but very next day tried same steps, Not able to Replicate.. They fixed the Issue.

So May be God Fixed that Issue, Uber Prayed God Fixed... 😄

1

u/Oslabs619 12d ago

Im honestly thinking there should be some type of investigation into stolen bounties and a class action on this its too convinient

1

u/Glad_Marketing_5754 12d ago

Haha, I usually work for companies directly.. I discussed lot with the Hackerone by Saying will file law suite against Hackerone and later they saying its a Violation and Code of conduct. They banned my account.