Work at Bolt Technology OÜ? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
At Bolt, we're building a future where people don’t need to own personal cars to move around safely and conveniently. A future where people have the freedom to use transport on demand, choosing whatever vehicle's best for each occasion — be it a car, scooter, or e-bike. No technology is perfect and Bolt believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our web and mobile applications. Good luck, and happy hunting! How does the program work? Security researchers and Bolt customers are encouraged to submit reports regarding the security measures used to protect Bolt products and services. Members of Bolt’s team may contact you to confirm that we have received your submission, ask questions about your findings, and discuss how to reproduce them. Bolt may direct you to stop your activities in the event that your research impacts Bolt-owned assets, Bolt vendors, or other customers. If directed to stop, you must immediately comply with the request. Timeline Note: Timeline as shown below is based on a submission which includes a fully detailed vulnerability with all of the required reproduction steps We aim to respond to submissions as fast as possible, according to the severity of the report. Bounty Payout: 5 business days from Bolt's validation (after Bugcrowd triage is completed) Response to Researcher Questions: 2 business days from blocker created for Bolt Please make sure your report includes a detailed description of the issue and the steps you believe may be required to reproduce what you have observed. A detailed description of the vulnerability and reproduction steps are required for each report. If you do not provide this information within 7 business days from the submission of the report, we will close the report as Not Applicable. Ratings/Rewards For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
Scope
12 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.bolt.eu | website | ✓ bounty | not set |
| *.boltable.eu | website | ✓ bounty | not set |
| *.taxify.eu | website | ✓ bounty | not set |
| Bolt Food (Android) | android | ✓ bounty | not set |
| Bolt Food (iOS) | ios | ✓ bounty | not set |
Show all 12 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| Bolt Rider (Android) | android | ✓ bounty | not set |
| Bolt Rider (iOS) | ios | ✓ bounty | not set |
| *.test.bolt.eu | website | out | not set |
| *.test.taxify.eu | website | out | not set |
| Bolt Driver (Android) | android | out | not set |
| Bolt Driver (iOS) | ios | out | not set |
| business-old.bolt.eu | website | out | not set |