Work at Paystack Vulnerability Disclosure? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 3 Oct 2026.
What it pays, by severity
Intake & responsiveness · last 90 days
Response targets it sets itself
A target the program declared, not a measurement of it being met.
Getting in the door
Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.
Over 43 days (89 snapshots): intake up 12 reports; response efficiency down 1 points.
See how this programme’s report load compares to others →
Reviews
0 publishedNo reviews yet.
Who this program credits
53 creditedResearchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.
| # | Researcher | Reputation | Recognised / submitted |
|---|---|---|---|
| 1 | harrymg | 35 | 5 / 7 71% |
| 1 | susant000 | 12 | 0 / 0 |
| 1 | bastianwelfrid | 9 | 0 / 0 |
| 1 | fisjkars | 9 | 0 / 0 |
| 1 | 0xneutrall | 7 | 0 / 2 0% |
| 1 | afewgoats | 7 | 0 / 0 |
| 1 | anirudh533 | 7 | 0 / 0 |
| 1 | d0xing | 7 | 0 / 0 |
| 1 | ddworken | 7 | 0 / 0 |
| 1 | dmxjon | 7 | 0 / 0 |
| 1 | timyun | 7 | 1 / 2 50% |
| 2 | abdellah29 | 30 | 5 / 5 100% |
| 2 | d4rkrai | 0 | 0 / 1 0% |
| 2 | rollax | 0 | 0 / 1 0% |
| 3 | caesar302 | 14 | 3 / 3 100% |
| 4 | mohab4173 | 9 | 1 / 1 100% |
| 4 | github-bot | 7 | 2 / 4 50% |
| 5 | 0x207 | 7 | 1 / 2 50% |
| 5 | 1sequalt0 | 7 | 1 / 1 100% |
| 5 | amirf00 | 7 | 0 / 0 |
| 5 | anhchangmutrang | 7 | 1 / 1 100% |
| 5 | chrisnwobi99 | 7 | 0 / 0 |
| 5 | cucumbersalad | 7 | 0 / 0 |
| 5 | dace0x | 7 | 1 / 4 25% |
| 5 | hellouser23 | 7 | 0 / 1 0% |
Showing the top 25 of 53 credited on HackerOne.
Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 1 Oct 2026.
Scope
45 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.helmservices.com | OTHER | out | None |
| *.index.com | OTHER | out | None |
| *.indiehackers.com | OTHER | submit only | Critical |
| *.payable.com | OTHER | submit only | Critical |
| *.paystack.com | OTHER | out | None |
Show all 45 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.paystackintegrations.com | URL | submit only | Critical |
| *.runkit.com | OTHER | out | None |
| *.stripe.com | OTHER | submit only | Critical |
| *.teapot.co | OTHER | out | None |
| *.totems.co | OTHER | out | None |
| *.touchtechpayments.com | OTHER | submit only | Critical |
| 978516833 | APPLE STORE APP ID | submit only | Critical |
| api.paystack.co | URL | submit only | Critical |
| api.stripe.com | URL | submit only | Critical |
| api.taxjar.com | URL | submit only | Critical |
| app.taxjar.com | URL | submit only | Critical |
| Assets which are owned by Paystack are in scope for this Vulnerability Disclosure Program | OTHER | submit only | Critical |
| checkout.paystack.com | URL | submit only | Critical |
| com.paystack.zap | GOOGLE PLAY APP ID | submit only | Critical |
| com.stripe.android.dashboard | OTHER APK | submit only | Critical |
| connect.stripe.com | URL | submit only | Critical |
| dashboard.paystack.com | URL | submit only | Critical |
| dashboard.stripe.com | URL | submit only | Critical |
| decodefintech.com | URL | submit only | Critical |
| js.stripe.com | URL | submit only | Critical |
| legacy.paystack.co | URL | submit only | Critical |
| nigerialogos.com | URL | submit only | Critical |
| paystack.shop | URL | submit only | Critical |
| paystackintegrations.com | URL | submit only | Critical |
| paystackmfb.com | URL | submit only | Critical |
| standard.paystack.co | URL | submit only | Critical |
| Stripe Atlas | OTHER | submit only | Critical |
| Stripe Billing | OTHER | submit only | Critical |
| Stripe Checkout | OTHER | submit only | Critical |
| Stripe Connect | OTHER | submit only | Critical |
| Stripe Dashboard | OTHER | submit only | Critical |
| Stripe Elements | OTHER | submit only | Critical |
| Stripe Issuing | OTHER | submit only | Critical |
| Stripe Open Source | OTHER | submit only | Critical |
| Stripe Payments | OTHER | submit only | Critical |
| Stripe Radar | OTHER | submit only | Critical |
| Stripe SDKs | OTHER | submit only | Critical |
| Stripe Sigma | OTHER | submit only | Critical |
| Stripe Terminal | OTHER | submit only | Critical |
| zap.money | URL | submit only | Critical |
HackerOne lists 47 scope entries; its public listing groups many assets under one label, so identical entries are shown once.