Scams
Unpaid
Programs
opengrants.io
Self-Hosted
redacted | opengrants.io
Fixed 2 Critical Bugs, No Bounty
achievable.me
Self-Hosted
Unauthenticated Account Takeover via accountSetup Mutation (ATO) | achievable.me
Unauthenticated Full Account Takeover via accountSetup GraphQL Mutation
payop.com
Self-Hosted
SQL Injection and 5 others including high and medium | payop.com
SQL Injection and 5 others including high and medium
hivelocity.net
Self-Hosted
SSRF | hivelocity.net
Hivelocity Bug Bounty Unauthenticated SSRF (core.hivelocity.net) (CVSS 9.1) Denied After 2 months, Vendor Acknowledged Vulnerability Exists
glia.com
Self-Hosted
DOM-Based Open Redirect and Reverse Tabnabbing via Insecure Cross-Origin postMessage | glia.com
Scammer Bug bounty program
acceptmission.com
Self-Hosted
3x htmli | stored xss | race condition | acceptmission.com
8 Months of Complete Silence After Multiple Valid Security Reports
babyone.de
Other
RXSS | babyone.de
Reflected Cross-Site Scripting (XSS) Disclosure Followed by Unilateral Account Restriction on babyone.de
huntr.com
Other
RCE,DoS,SSRF | huntr.com
huntr validated bounties retroactively reduced, then withheld after account ban
auvp.com.br
Self-Hosted
Leak of PII | auvp.com.br
Owner tweeted about paying for criticals + swags, scam exitted without payouts
huntr.com
Other
SSRF, RCE, PE, IDOR ... | huntr.com
Huntr scoped the Kubeflow engagement to a repo with no code, closed 14 critical/high reports as NA, then banned the account
scribblemaps.com
Self-Hosted
Internal Information Disclosure | scribblemaps.com
Reports of internal sensitive information disclosure were left unanswered
t402.io
Self-Hosted
Authorization Bypass / Signature Verification | t402.io
Vendor confirmed my security report, fixed the vulnerability, requested payment details, then stopped responding
notte.cc
Self-Hosted
Remote Code Execution | notte.cc
Notte.cc Scammed on RCE Finding
Civo.com
Self-Hosted
ATO using Email Forget | Civo.com
Not Replying after Fixing Bugs
followup.cc
Self-Hosted
Captcha Bypass | followup.cc
Reported a Captcha Bypass bug, but got no response in return
substack.com
Self-Hosted
race condition | substack.com
I reported bug to substack.com they replied also but never added my name to HOF
emerson.com
Self-Hosted
IDOR | emerson.com
Emerson.com Fixed My Vulnerability Report in 24 Hours — But the Reward Never Arrived
tasksmind.com
Self-Hosted
Subscription Bypass | tasksmind.com
SUBSCRIPTION BYPASS
companyinfo.nl,fdmediagroep.nl,fdmg.nl
Self-Hosted
otp bypass | companyinfo.nl,fdmediagroep.nl,fdmg.nl
i reported otp bypass on fdmediagroep.nl and not a single reply from company {auotmated}
boldcommerce.com
Self-Hosted
BAC | boldcommerce.com
Approved Security Bounty Still Unpaid Months After Validation
projectbios.com
Self-Hosted
critical vulns | projectbios.com
i reported multiple bugs on projectbios now it dosnt exist haha
bevolkingsonderzoeknederland.nl
Self-Hosted
(NOT_Scam) text injection | bevolkingsonderzoeknederland.nl
i reported a text injection but email dosnt exist
westermo.com
Self-Hosted
reflected xss | westermo.com
reflected xss report ignored
alphanodus.com
Self-Hosted
html injection | alphanodus.com
html injection on signup page
wazoku.com
Self-Hosted
Sensitive Data Exposure | wazoku.com
Cancelled the decided reward amount after asked updates for proceed payment
gifty.nl
Self-Hosted
RCE | gifty.nl
Dependency Confusion Vulnerability
scantrust.com
Self-Hosted
Stored XSS | scantrust.com
Silent Fix,No Response
boat-lifestyle.com
Self-Hosted
Reflected XSS | boat-lifestyle.com
Responsible Disclosure – Reflected XSS Vulnerability in Search Input on boat-lifestyle.com
rfgstudios.com
Self-Hosted
IDOR | rfgstudios.com
Silent Fix | Bounty Denied
zoviz.com
Self-Hosted
Improper Access Control | zoviz.com
Premium Feature Bypass
www.proxsys.nl
Self-Hosted
Open Redirect | www.proxsys.nl
floatbot.ai
Self-Hosted
RCE | floatbot.ai
Reported a Remote code execution
signageos.io
Self-Hosted
logical bugs | signageos.io
no payout and this program reported by sevral researcher marked as scam
plumsail.com
Self-Hosted
logical bug | plumsail.com
Unauthenticated Webhook Subscription Deletion — Missing Authentication + Confirmed Data Destruction
zetrix.com
Self-Hosted
multiple bugs | zetrix.com
Reports Rejected, No Response
Yatra.com
Self-Hosted
multiple bugs | Yatra.com
Yatra Bug Ignored
conductor.com
Self-Hosted
BAC | conductor.com
no Response
punchzee.com
Self-Hosted
Logic | punchzee.com
no Response
float.com
Self-Hosted
Org Takover | float.com
no Response
increase.com
Self-Hosted
BAC | increase.com
Reject valid vulnerability
klikkit.no
Self-Hosted
idor|htmli|cors | klikkit.no
IDORs CORS Misconfiguration, HTML Injection, and 1 Year of Silence
wayfair.com
HackerOne
CSRF | wayfair.com
The program don’t accept any kind of csrf vulnerability and Their response time is very very bad.
cutshort.io
Self-Hosted
subdomain takeover | cutshort.io
subdomain takeover report ignored by company

REPORT A SCAM

All submissions reviewed before publishing.

Program

📸
Click or drag
Max 5MB

Incident

Evidence is required. Include report IDs, screenshots, dates, or any proof.
🖼
Multiple photos
Up to 10, 5MB each

Your Info

Never published. Used for confirmation and follow-up only.
Submitted! Will appear after review.

Get in Touch

Have a question, tip, or partnership inquiry? Reach out to us directly.

🐛
Report a Scam
Use the Submit tab to file a detailed report with evidence.
🛡
Security Issues
Found a vulnerability on our site? Email us directly.
🤝
Partnerships
Interested in collaborating? We'd love to hear from you.

Get Notified of New Scam Reports

Subscribe to get an email the moment a new scam report or blog post goes live on BugBountyScam. Double opt-in, no spam, unsubscribe anytime.

New Scam Reports
Instant alert when a bug bounty program gets reported.
Blog Posts
Get notified when we publish new investigations.
🔒
Privacy First
We never share your email. One-click unsubscribe in every message.

⌕ Program Lookup

Check if a bug bounty program has scam reports

☠ Wall of Shame

Programs with the most scam reports from the community

◈ Scam Analytics

⧖ Track Report

Enter your tracking ID to check submission status

Blog

☆ Weekly Digest

✅ Valid Programs

Bug bounty programs discovered through researcher experiences
⚠ Programs here are user-submitted. Experiences are personal researcher accounts. Bounty ranges and response times are claimed by submitters and are not independently verified by BugBountyScam. Verify important details yourself before relying on them.
Stay Updated
Get notified when new valid programs are approved.