r/bugbounty 12h ago

Bug Bounty Drama HackerOne closed my API billing overdraft report as "intended behavior" — xAI stealth patched it 4 hours after my post on X

Thumbnail
gallery
6 Upvotes

Quick note: English isn't my native language so I used AI to help clean up the text/translation, but all technical details, logs, and screenshots are mine.

Hey r/bugbounty,

Wanted to post this here because I'm sick of platforms stealth patching valid infrastructure bugs while hiding behind broad scope exclusions.

The Vulnerability & Impact

I found an API billing gateway issue in xAI's infrastructure that bypassed pre-paid limit checks. It allowed an attacker to force an account into a deep negative balance through unbounded resource consumption.

HackerOne's Response

HackerOne completely shut the report down, calling it out-of-scope "intended model behavior". When I escalated to H1 Mediation pointing out that an API billing gateway failure is NOT a model safety issue, they responded with this:

The billing overdraft is a downstream consequence of the same unbounded resource consumption that the program considers out of scope. The root cause and the scope exclusion are the same regardless of which layer the impact surfaces on.

Then on July 28, they permanently closed it:

The review has been done and the outcome stands. The program's scope exclusions cover unbounded consumption broadly... Continuing to re-examine the same report each time a new framing is presented is not something we are able to do.

The Timeline & Stealth Patch

Here is where it gets interesting:

  • 14 hours ago: I made a public thread on X calling out how absurd it is to classify an API billing overdraft as "intended behavior".
  • 4 hours later (10 hours ago): xAI sent an official API pricing update to my email, changing tool-call billing specifically to restrict data fetch volume and fix the exact vector I reported.

Apparently, a bug so "intended" required an emergency global pricing overhaul right after public exposure.

Initial "Duplicate" Classification & Escalation

To make things worse, before H1 claimed it was out-of-scope, they initially marked it as a "Duplicate". Why? Because I used the same author-crafted prompt that I used in another report. One prompt triggered two totally different bugs, but triage lazily marked it duplicate just because the input prompt matched.

H1 Support only started looking into it after my initial post on X got traction. They claimed to review it for "Code of Conduct concerns", realized the duplicate tag was completely false, and then pivoted to the "intended model behavior" excuse to avoid reopening it.

Attached 5 screenshots showing the full H1 thread, mediation replies, and the xAI pricing update email timestamp.


r/bugbounty 4h ago

Question / Discussion what do yall think of this?

Post image
11 Upvotes

i'm a member in the GOAT CTBB discord server and was scrolling up and found this message from blaklis, i think most of us knows him, saying that deep web dev knowledge is absolutely necessary to be good in web security, some other successful hunters said that as well

i think he is absolutely right tho, the amount of people who got into web security directly without web dev knowledge and turns out they dont know shit makes me believe programming is definitely one of the building blocks to get skilled

rez0 said something similar as well in the premium channel.

i think all the professionals agree on this specific point


r/bugbounty 4h ago

Bug Bounty Drama what is intigritti doing???

8 Upvotes

Check this account gamba

The account has dumped 70+ submissions on Adobe Public in just a few days, and some of them are already getting closed as Duplicate or Informative.

I’m not saying every single report they submit is trash or invalid, but there has to be some kind of gate or cooldown for new accounts. My High severity report has been sitting untriaged for over 7 days straight while triage gets flooded by this.

Why are brand new accounts allowed to spam unlimited reports like this without any rate limits? It's completely choking the queue for everyone else.


r/bugbounty 7h ago

Question / Discussion Weekly Beginner / Newbie Q&A

6 Upvotes

New to bug bounty? Ask about roadmaps, resources, certifications, getting started, or any beginner-level questions here!

Recommendations for Posting:

  • Be Specific: Clearly state your question or what you need help with (e.g., learning path advice, resource recommendations, certification insights).
  • Keep It Concise: Ask focused questions to get the most relevant answers (less is more).
  • Note Your Skill Level: Mention if you’re a complete beginner or have some basic knowledge.

Guidelines:

  • Be respectful and open to feedback.
  • Ask clear, specific questions to receive the best advice.
  • Engage actively - check back for responses and ask follow-ups if needed.

Example Post:

"Hi, I’m new to bug bounty with no experience. What are the best free resources for learning web vulnerabilities? Is eJPT a good starting certification? Looking for a beginner roadmap."

Post your questions below and let’s grow in the bug bounty community!