HackerOne · Bug Bounty

Ripio Bug Bounty Program

Complete guide to Ripio's bug bounty program on HackerOne. View in-scope assets, reward amounts, response times, and tips for finding vulnerabilities.

Program Overview

Ripio runs a bug bounty program on HackerOne. The program has 24 in-scope assets.

24
In-Scope Assets
2d
Avg Response
99%
Efficiency
3d
Avg Bounty Time
11d
Avg Resolve

In-Scope Assets

AssetTypeMax SeverityEligible
*ripio.comWILDCARDNoneNo Bounty
*ripiotrade.coWILDCARDCriticalBounty
Web3 - Smart Contracts ScopeOTHERCriticalBounty
com.ripio.androidGOOGLE_PLAY_APP_IDCriticalBounty
com.ripio.iosAPPLE_STORE_APP_IDCriticalBounty
defi.ripio.comURLCriticalBounty
http://auth.ripio.comURLCriticalBounty
https://app.ripio.comURLCriticalBounty
https://basescan.org/address/0xf469eC9dEBf7F0adEBA4d1Db2FF5c70707bEeB30SMART_CONTRACTCriticalBounty
https://bridge.ripio.com/URLCriticalBounty
https://etherscan.io/address/0x0DC4F92879B7670e5f4e4e6e3c801D229129D90DSMART_CONTRACTCriticalBounty
https://etherscan.io/address/0x337E7456B420bD3481e7FA61fA9850343d610d34SMART_CONTRACTCriticalBounty
https://etherscan.io/address/0x46167cB034feC6ceC46CaeD4f61281f5Aa0Eb0e6SMART_CONTRACTCriticalBounty
https://etherscan.io/address/0x465e642387d3d73a57CDc1368fFA53A800bA5D47SMART_CONTRACTCriticalBounty
https://etherscan.io/address/0x4F34c8b3b5FB6D98Da888F0feA543d4d9C9F2eBESMART_CONTRACTCriticalBounty
https://etherscan.io/address/0x61D450a098b6a7f69fC4b98CE68198fe59768651SMART_CONTRACTCriticalBounty
https://etherscan.io/address/0x8a1D45e102e886510e891d2Ec656a708991e2D76SMART_CONTRACTCriticalBounty
https://etherscan.io/address/0xD168CFbBE260D48cd119497a9a2eE8482080C5E7SMART_CONTRACTCriticalBounty
https://etherscan.io/address/0xD76f5Faf6888e24D9F04Bf92a0c8B921FE4390e0SMART_CONTRACTCriticalBounty
https://etherscan.io/address/0xdcC340132740AD57E9Fc90C9BD08B00dBbc87986SMART_CONTRACTCriticalBounty
https://kyc.ripio.com/URLCriticalBounty
https://worldscan.org/address/0xDe7Ec97CFDeE9F20f9d256F4a0A0d694479fa2E0SMART_CONTRACTCriticalBounty
sandbox-b2b.ripio.comURLCriticalBounty
trade.ripio.comURLCriticalBounty

Tips for Hacking Ripio

  1. Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
  2. Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
  3. Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
  4. Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
  5. Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.

Frequently Asked Questions

How do I start hacking Ripio?

Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.

Does Ripio pay bounties?

Yes, Ripio offers monetary rewards for valid security vulnerabilities.

What types of vulnerabilities does Ripio accept?

Ripio accepts reports for vulnerabilities found in their 24 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.