monobank summarized the results of the first Bug Bounty for UAH 1 million — “white” hackers found a number of P2-P4 vulnerabilities and earned $6,800

monobank passed the first external pentest – according to the results of the first Bug Bounty, which took place on December 1, accredited “white” (ethical) hackers found several “holes” in the security of the IT systems of the popular neobank. Maksym Pugach, Chief Information Officer of the Fintech Band, told Forbes about the results of the hackathon.

This is the first time in 6 years that monobank organized a program for finding vulnerabilities and allocated a fairly solid budget of UAH 1 million for it. — we told all the key details of the news on November 17, when registration started.

As the chief IT member of the monobank development team told, almost 1,000 white hats applied to participate in the vulnerability search program at monobank, but in the end only 275 specialists were selected who signed the NDA through the “Action” application – this, among other things, helped the management of the mono-Russian … Agency .

23 hackers who submitted 46 reports took an active part in the competition – the participants did not find any vulnerability of critical level (P1). Meanwhile, two high-level P2 vulnerabilities, one P3, and six lowest-level P4 bugs are reported. The maximum award amount under the program was $750 for a level 2 vulnerability found. Researchers will receive $500 for level three (P3) vulnerabilities, and $250 for P4 vulnerabilities. Interestingly, these amounts are slightly different from those listed in the original award table, but there may be nuances to the assessment of significance. At the same time, all participants paid an additional $100 each, and the total payouts under the program amounted to $6,800.

Monobank plans the next competition in a year or two, and their frequency will depend on the volume of new functions. One can only hope that such contests will make the monobank secure and resistant to possible hacker attacks in the future, such as the recent massive DDoS attack on December 12. Maybe Kyivstar should also consider restarting its own BugBounty program, given the bitter experience and mistakes of the past.

  • In 2020, the Ministry of Digitization held a similar Bug Bounty marathon with a prize fund of UAH 1 million to test the Diya application – then the department stated that the state service was impenetrable to hackers and no one managed to hack Diya. However, questions arose regarding the organization of the contest due to limited access to participation.
  • monobank is a card product of Fintech Band and Universal Bank. The first was founded in January 2017 by former PrivatBank top managers Oleg Horokhovskyi, Dmytro Dubilet and Mykhailo Rogalskyi. The project uses the banking license of Universal Bank, which is part of the TAS group and belongs to Ukrainian businessman Serhiy Tihipko.

Related Posts

UK to regulate cryptocurrency memes: illegal advertising

Britain’s financial services regulator has issued guidance to financial services companies and social media influencers who create memes about cryptocurrencies and other investments to regulate them amid…

unofficial renders of the Google Pixel 9 and information about the Pixel 9 Pro XL

The whistleblower @OnLeaks and the site 91mobiles presented the renders of the Google Pixel 9 phone. Four images and a 360° video show a black smartphone with…

Embracer to sell Gearbox (Borderlands) to Take-Two (Rockstar and 2K) for $460 million

Embracer continues to sell off assets – the Swedish gaming holding has just confirmed the sale of The Gearbox Entertainment studio to Take-Two Interactive. The sum is…

photo of the new Xbox X console

The eXputer site managed to get a photo of a new modification of the Microsoft Xbox game console. The source reports that it is a white Xbox…

Israel Deploys Massive Facial Recognition Program in Gaza, – The New York Times

The Technology section is powered by Favbet Tech The images are matched against a database of Palestinians with ties to Hamas. According to The New York Times,…

Twitch has banned chest and buttock broadcasts of gameplay

Twitch has updated its community rules and banned the focus of streams on breasts and buttocks. According to the update, starting March 29, “content that focuses on…

Leave a Reply

Your email address will not be published. Required fields are marked *