Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Privy (Bounty)
Privy (Bounty) HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Privy (Bounty)? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 24 Sep 2026.

What it pays, by severity

Critical no reports on record
High no reports on record
Medium no reports on record
Low no reports on record

$80,000 paid to researchers in total, $20,000 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
360
in 90 days
Resolved
not published
all time, last one 9 days ago
Participants
70
hunters engaged
Response efficiency
94%
meeting its targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 15 days 344–360
27 Aug 360 reports 24 Sep

Response targets it sets itself

First response
1 day
Triage
10 days
Bounty
15 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

bounty amounts hidden

Over 33 days (18 snapshots): intake up 3 reports; response efficiency down 2 points; 90-day payout up $5,000.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

68 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 theycallme_mufasa 191 9 / 29 31%
2 yipman 127 3 / 7 43%
3 bs0xx 113 4 / 14 29%
4 notmore 103 5 / 20 25%
5 kymu_ 66 3 / 9 33%
6 ymelnyk 56 3 / 4 75%
6 jomolopo 54 0 / 1 0%
7 crisi_hacker 44 2 / 5 40%
7 harshitarora1210 44 2 / 2 100%
7 kassem_s94 44 2 / 3 67%
10 th0h0 41 1 / 4 25%
11 hx01 39 1 / 2 50%
11 khartmanpt12 39 2 / 4 50%
13 4w3 37 1 / 5 20%
13 samspl 37 1 / 5 20%
15 0l0v3r1 34 1 / 1 100%
15 cardador 34 1 / 6 17%
17 4ldairx 32 1 / 7 14%
17 borg_security 32 1 / 1 100%
17 deadzord 32 2 / 4 50%
17 elfayad 32 1 / 3 33%
21 w2w 27 1 / 1 100%
22 athanws 24 2 / 4 50%
22 dragon744 24 2 / 4 50%
22 idynavu 24 2 / 3 67%

Showing the top 25 of 68 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 23 Sep 2026.

Privy is a library that allows developers to onboard all users to their web3 product, helping them with authentication and key management.

Responsiveness
94% HackerOne’s figure
Swag
Offered
Currency
USD
Submissions
Open
Launched
Jan 2025
Scope entries
17 HackerOne’s count

Scope

17 assets
AssetTypeEligibilityMax severity
@privy-io controlled namespace dependencies OTHER ✓ bounty Critical
api.privy.io URL ✓ bounty Critical
auth.privy.io URL ✓ bounty Critical
console.privy.io URL ✓ bounty Critical
dashboard.privy.io URL ✓ bounty Critical
Show all 17 assets
AssetTypeEligibilityMax severity
home.privy.io URL ✓ bounty Critical
https://www.npmjs.com/package/@privy-io/cross-app-connect OTHER ✓ bounty Critical
https://www.npmjs.com/package/@privy-io/cross-app-provider OTHER ✓ bounty Critical
https://www.npmjs.com/package/@privy-io/expo OTHER ✓ bounty Critical
https://www.npmjs.com/package/@privy-io/js-sdk-core OTHER ✓ bounty Critical
https://www.npmjs.com/package/@privy-io/react-auth SOURCE CODE ✓ bounty Critical
https://www.npmjs.com/package/@privy-io/wagmi OTHER ✓ bounty Critical
recovery.privy.io URL ✓ bounty Critical
blog.privy.io URL out None
demo.privy.io URL out None
docs.privy.io URL out None
privy.io URL out None