HackerOne · Bug Bounty

PayPal Bug Bounty Program

Complete guide to PayPal's bug bounty program on HackerOne. View in-scope assets, reward amounts, response times, and tips for finding vulnerabilities.

Program Overview

PayPal runs a bug bounty program on HackerOne. The program has 41 in-scope assets and is managed by HackerOne's triage team.

41
In-Scope Assets
9h
Avg Response
95%
Efficiency
33d
Avg Bounty Time
136d
Avg Resolve

In-Scope Assets

AssetTypeMax SeverityEligible
*.braintree-api.comURLCriticalBounty
*.braintree.toolsURLCriticalBounty
*.braintreegateway.comURLCriticalBounty
*.braintreepayments.comURLCriticalBounty
*.hyperwallet.comURLCriticalBounty
*.paydiant.comURLCriticalBounty
*.paylution.comURLCriticalBounty
*.paypal.comURLCriticalBounty
*.paypalcorp.comURLCriticalBounty
*.venmo.comURLCriticalBounty
*.xoom.comURLCriticalBounty
351727428APPLE_STORE_APP_IDCriticalBounty
Braintree SDKOTHERCriticalBounty
PayPal SDKOTHERCriticalBounty
api.loanbuilder.comURLLowBounty
api.swiftfinancial.comURLLowBounty
com.paypal.android.p2pmobileGOOGLE_PLAY_APP_IDCriticalBounty
com.paypal.merchantAPPLE_STORE_APP_IDCriticalBounty
com.paypal.merchant.clientGOOGLE_PLAY_APP_IDCriticalBounty
com.venmoGOOGLE_PLAY_APP_IDCriticalBounty
com.xoom.android.appGOOGLE_PLAY_APP_IDCriticalBounty
com.xoom.appAPPLE_STORE_APP_IDCriticalBounty
com.yourcompany.PPClientAPPLE_STORE_APP_IDCriticalNo Bounty
decision.swiftfinancial.comURLLowBounty
loanbuilder.comURLLowBounty
my.loanbuilder.comURLLowBounty
my.swiftfinancial.comURLLowBounty
partner.swiftfinancial.comURLLowBounty
paypal.meURLCriticalBounty
paypalobjects.comURLMediumBounty
pigeon.swiftfinancial.comURLLowBounty
prequal.swiftfinancial.comURLLowBounty
py.plURLCriticalBounty
sandbox.braintreegateway.comURLMediumBounty
scrutiny.swiftfinancial.comURLLowBounty
swiftcapital.comURLLowBounty
swiftfinancial.comURLLowBounty
www.loanbuilder.comURLLowBounty
www.paypal-*.comURLLowBounty
www.swiftcapital.comURLLowBounty
www.swiftfinancial.comURLLowBounty

Out-of-Scope Assets

  • *.atlassian.net
  • *.paypal.cn
  • braintree.com
  • com.paypal.here
  • com.paypal.here
  • com.paypal.herehd
  • www.gopay.com

Tips for Hacking PayPal

  1. Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
  2. Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
  3. Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
  4. Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
  5. Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.

Frequently Asked Questions

How do I start hacking PayPal?

Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.

Does PayPal pay bounties?

Yes, PayPal offers monetary rewards for valid security vulnerabilities.

What types of vulnerabilities does PayPal accept?

PayPal accepts reports for vulnerabilities found in their 41 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.