Work at d-you App & German EUDI Wallet Ecosystem? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 23 Sep 2026.
What it pays, by severity
Intake & responsiveness · last 90 days
Response targets it sets itself
A target the program declared, not a measurement of it being met.
Getting in the door
Over 7 days (164 snapshots): no change on the figures worth watching.
See how this programme’s report load compares to others →
Reviews
0 publishedNo reviews yet.
Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 16 Sep 2026.
Scope
13 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| d-you Android test | GOOGLE PLAY APP ID | ✓ bounty | Critical |
| d-you iOS test | TESTFLIGHT | ✓ bounty | Critical |
| d-you Wallet Android Test | GOOGLE PLAY APP ID | ✓ bounty | Critical |
| d-you Wallet iOS Test | TESTFLIGHT | ✓ bounty | Critical |
| https://github.com/german-national-wallet/de-eudi-wallet-backend | SOURCE CODE | ✓ bounty | Critical |
Show all 13 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| https://groups.google.com/g/de-eudi-bug-bounty/ | GOOGLE PLAY APP ID | ✓ bounty | Critical |
| https://test.api.example.com | API | ✓ bounty | Critical |
| https://testflight.apple.com/join/a2Qxrr2C | APPLE STORE APP ID | ✓ bounty | Critical |
| https://wallet-backend-sandbox.apps.sandbox.nwb.youniqx.com/v1/mdvm | API | ✓ bounty | Critical |
| https://wallet-backend-sandbox.apps.sandbox.nwb.youniqx.com/v1/pns | API | ✓ bounty | High |
| https://wallet-backend-sandbox.apps.sandbox.nwb.youniqx.com/v1/rwsca | API | ✓ bounty | Critical |
| https://wallet-backend-sandbox.apps.sandbox.nwb.youniqx.com/v1/status-lists | API | ✓ bounty | Critical |
| https://wallet-backend-sandbox.apps.sandbox.nwb.youniqx.com/v1/wpb | API | ✓ bounty | Critical |
HackerOne lists 14 scope entries; its public listing groups many assets under one label, so identical entries are shown once.