Scam Alert: boldcommerce.com — Approved Security Bounty Still Unpaid Months After Validation
Company / Program: boldcommerce.com
Platform: Self-Hosted · Severity: low · Scam type: no-payout
Published:
Reported by: serioton
I submitted a security vulnerability report (Reference: BSECB-425) on December 31, 2025.
The vulnerability was reviewed and officially validated by the security team on March 24, 2026. The team classified the issue as Low severity and approved a bounty payment of $150 CAD. I provided the requested payment details immediately after validation.
On April 2, 2026, a program representative informed me that payment was delayed but should be received within the next two weeks.
However, despite waiting beyond the stated timeline and sending multiple follow-up messages on:
April 18, 2026
April 25, 2026
April 27, 2026
May 4, 2026
May 18, 2026
June 17, 2026
I have not received the approved reward, nor have I received any meaningful update regarding payment status.
The report was validated, the reward amount was confirmed, and the case was marked as resolved, yet the payment remains outstanding.