From 28 Sep to 27 Nov, every High, Critical and Exceptional report on Tier 1 and Tier 2 targets pays +50%.
This window rewards one thing: severity where it matters. Below is how we suggest you get there, and how your feedback will shape what comes next.
How we suggest you hunt
- Start with the documentation. Most duplicates and out of scope reports come from skipping it, and ten minutes of reading saves everyone days.
- From there, make sure the scope is clear. The path to logic bugs starts with knowing what is in scope and how each target is supposed to behave. If anything is unclear, ask before you hunt.
- With the scope clear, build the picture before you test. Map the attack surface. Know what each product is, and where the line runs between B2C and B2B. Bugs hide in business logic, and business logic only makes sense once you know what each product does and how the flows connect.
- Two accelerators on the way. Our documentation works well as context for AI agents: it is the fastest route to productive testing and to resuming where you left off. And credentials are not a limitation: request multiple accounts, because cross account scenarios are where our real bugs live, from IDOR to authorization between roles. One profile sees nothing. Three do.
- A note on expectations: you do not need web3 expertise for this program. Most of our surface is standard web2: APIs, dashboards, session handling, access control. Researchers who test banks can test us.
- One boundary. Use AI to build context and understand the app, and use the program with judgement. Do not spam reports hoping something sticks: the platform limits how many reports you can have open, so spend them on findings you believe in. Automated, copy pasted submissions are classified as spam.
Two constraints we can manage for you
- Country limitations are real, by design, and worth testing: registration and some features are restricted by regulation. If a limitation blocked you during testing, tell us in the form. If a wall did not hold, we want to hear about it.
- If you are stuck at IDV: once you have completed identity verification, reach out and we will skip the step on your account, so you move faster through the remaining flows.
What is coming, and how your answers steer it
Over the next two months we are publishing updates on a regular cadence: fresh hints per product, boosted bonuses on High, Critical and Exceptional, and digested information built from your answers to the form (Uphold - Bug Bounty Program Feedback).
The loop is direct. Your answers guide what we prioritize next: which blockers to attack, which context to build, which products deserve a closer look. Nothing is read and archived.
So tell us where you got stuck, where you gave up and what we should fix. Two minutes of your time.
Uphold Security Team
Hello Researchers,
We appreciate the high level of engagement with the Topper component. However, we have observed a significant volume of automated traffic and high-frequency scanning hitting Topper in our production environment.
If you are currently running automation against Topper in Production, please stop immediately. We provide a dedicated sandbox environment precisely for this type of research. It allows you to test Topper’s limits and run automated scripts without impacting live services or real users. Moving forward, reports resulting from production automation may be marked as Out of Scope.
Please direct all automated testing to our sandbox:
Thank you for your cooperation in keeping our production environment stable.
Regards,
Uphold Security Team
Hunters!
We are providing this update to clarify the current process for accessing our sandbox environments to ensure you can get started with your testing as quickly as possible.
Enterprise Portal (Self-Signup)
Self-registration is now fully a*vailable for all researchers. You can instantly create sandbox environments to explore and test Enterprise APIs, no manual invite or sales contact required.
Instant Access: Register directly at portal.enterprise.uphold.com.
Sandbox Wallet Access Flow
For testing on the wallet environment, please follow this specific flow to prepare your accounts for authorization testing:
- Registration: Create your accounts on the sandbox environment using your Intigriti alias email (e.g., username+user1@intigriti.me) and dummy data. You can create as many accounts as required for your scenarios.
- MFA Bypass: During the initial setup, use the code 000000 as an MFA bypass.
- KYC Stage: Complete the registration process until you reach the ID verification (KYC) stage.
Crucial Step: Once you have registered your accounts, please answer us back via email or your report with the specific Intigriti alias emails used. Our team will then manually perform a KYC bypass to grant you access.
Happy hacking, and thank you for helping us secure Uphold!
Uphold Security Team
We’ve launched Corporate Self-Signup, allowing researchers to instantly create sandbox environments to explore and test Uphold’s Enterprise APIs, no sales contact or invite required.
Key Details
- Instant Sandbox Access: Create an account and start testing right away.
- Simple 3-Step Flow:
- Fill out a short form
- Confirm your email
- Set up 2FA and begin testing
Important : Please conduct all testing exclusively in sandbox environments created through the self-signup process. Testing in production will affect the analysis and validity of reports, and may lead to disqualification.
You can access the new signup flow and start testing here: Signup
Hey there, fellow hackers!
We’ve made several updates to the program scope, rules, and details to make it easier for you to navigate, understand, and contribute to our bug bounty program. These improvements include:
✅ Clearer Scope & Testing Guidelines – Helping you focus on what matters most and have proper context about each application's capabilities.
✅ Refined Rules of Engagement – Ensuring transparency in how we operate.
✅ Improved Severity Assessment & Rewards – Better alignment with impact.
✅ Expanded FAQ – Answering common questions to save you time.
✅ New Known Issues Section – Avoid submitting duplicates by checking reported issues first.
🚀 Check out the updated program details here: Uphold BB Program
🔑 Need Credentials for Sandbox Testing?
We provide limited sets of sandbox credentials to help researchers expand their testing surface. Access will be granted on a rotating basis and prioritized based on ongoing research needs. If you require credentials, please contact us, and we will do our best to accommodate your request while ensuring fair access to all researchers.
💡 Your feedback matters! If you have suggestions or thoughts on these changes, feel free to share them.
Happy hacking, and thank you for helping us secure Uphold!
Uphold Security Team
Hey there, fellow hackers!
October is Cyber Security Month, and we want to celebrate with you. From October 21st 2024 to October 31st 2024, we're spicing up our bug bounty program with some awesome perks. It's our way of saying thanks for helping us keep things secure.
What's Up for Grabs?
- €1,000 Extra Cash: Found a valid bug that's medium severity or higher? Boom - there's an extra €1000 in it for you, on top of our regular bounty.
- Sweet Swag: Who doesn't love free gear? Score some exclusive Uphold merchandise to show off your elite hacker status.
Why You Should Jump In
We know you're all about making the digital world safer, and so are we. This is your chance to showcase your skills, earn some cash, and grab some cool stuff along the way.
How to Get Started
- Hunt for Bugs: Dive into our platform and see what you can uncover.
- Report It: Found something? Let us know through Intigrit's official bug bounty submission process.
- Claim Your Rewards: If it's a valid medium (or higher) severity bug, the bonus and swag are all yours!
Need-to-Know Details
- The promotion runs from October 21st 2024 to October 31st 2024.
- Only findings classified as medium severity or above qualify for the bonus and goodies.
- All findings must follow our bug bounty program policies.
So, are you ready to join the hunt and make a difference? Let's team up to make Uphold safer for everyone.
Got questions or just want to chat? Hit us up at security@uphold.com. We're all ears!
Happy hacking, and good luck!
Hunters!
It’s been a while, and we’ve been hard at work building more things for you to break. We’ve recently released Uphold Vault (part of the Uphold Wallet application) and UpHODL, two flagship products that we’re very proud of.
We would love to see all of the improvements that we can make to these products, so for every vulnerability found (and validated by both the Intigriti team and by us) for these two products before 31/06/2024, we’ll give you a 30% bonus!
In this update we’ve also expanded our scope to include new applications (including Topper), added a bonus scheme for exceptional vulnerabilities that would have a significant business impact, and upped our bounties. Please check it all out and see what you can find.
As always, happy hunting!
The Uphold Team
Dear Intigriti Hunters,
We've made massive changes to our program, with a re-focus on bugbounty for 2022.
We'd love you to take a new look at the scope, as we've introduced new tier levels and new scopes.
And bigger bounties
We look forward to seeing you, happy hunting!
The Uphold Team
Hello Intigriti Researchers.
Can you help us make our program awesome? Please answer these short questions on bounties and scope so we can make the changes you want!
Survey Link
Thank you for your help, we will review your responses and take action shortly. Watch this space :)
Hello Security Researchers,
For every High, Critical or Exceptional vulnerability found (and validated by the Intigriti team) in August, you will get an extra €500.
Please take a look at our platform and dig away, looking for vulnerabilities.
Happy Hunting!
Uphold Security Team






























