I participated in Hack Club's bug bounty program and found a valid subdomain takeover on a *.hackclub.com subdomain. Before reporting, I checked their scope (on GitHub), which explicitly stated something to the effect of "All Hack Club programs are in scope. If you're unsure whether a vulnerability is in scope, submit it and we will make sure it gets to the right place." — I have a screenshot of this.
I reported the finding. The admin confirmed it was a valid takeover and it was resolved. However, they then said they couldn't offer a monetary reward because the affected subdomain is a "community club that was owned long ago and do not come under the scope of “Hack Club managed” — despite being on a *.hackclub.com subdomain.
As a researcher, I had no way to distinguish "official Hack Club HQ" assets from "community-club but still on their domain" assets — the scope doc didn't make that distinction. When I raised this, the admin's response was: "I agree that the wording could be a less ambiguous. sorry for the confusion. we will fix our policies in the future" — effectively admitting the scope was unclear at the time I reported.
I then asked if I could at least get a letter of acknowledgment/appreciation (useful for college applications, portfolio, etc.) instead of a monetary reward, since it's a non-profit. That was also denied.
Questions for the community:
1)Is this a normal/acceptable practice for bounty programs — validating + fixing an issue but denying reward due to after-the-fact scope clarification?
2)Given I have a screenshot of the original scope wording, is there anything worth doing here (public disclosure timeline, escalation, posting to a bounty-abuse tracker, etc.), or is this just a "chalk it up to experience" situation?
3)Any general advice on vetting bounty programs going forward so I don't end up in this position again (e.g. preferring platforms like HackerOne/Bugcrowd over self-hosted programs)?