I reported 10 valid bugs including SQL Injection and account takeover to a company running a public bug bounty program. Initially, they acknowledged the reports and later fixed all the issues. But instead of rewarding or crediting me, they gave excuses and rejected them. Shortly after, they shut down their bug bounty program entirely.
There’s no official body to protect bug hunters in such cases.
If there is someone who can help me with this situation, please reply.
Hi @userx - just checking in. Did you find any resolution? We have resources on handling these situations at https://disclose.io/resources. Happy to connect you with community members who have navigated similar issues.
Sorry about that broken link, @userx — we’ve updated our site and that page no longer exists. Here are some things that might help with your situation:
If the company’s bug bounty was hosted on a platform (HackerOne, Bugcrowd, etc.), you can raise a mediation request through that platform directly
Document everything — screenshots of the program scope, your submissions, and their acknowledgments are valuable if you ever need to escalate