{"id":"73ca7ddf-de6c-437a-8e3f-43a77efa9e3a","engagementId":"c6d34348-fa87-46e3-a2d8-277899262021","data":{"brief":{"id":"363e1493-bcf0-45d6-9225-c8d40f87a64e","name":"Cash App","tagline":"Help Secure Cash App","description":"\u003ch2\u003eBlock, Inc.\u003c/h2\u003e\n\n\u003cp\u003eThis program is part of Block, Inc. You can participate in our other bug bounty programs below:\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://bugcrowd.com/square?preview=3b034fbb39b8f94910e4ae07720b1d7f\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSquare\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://bugcrowd.com/tidal-bugbounty?preview=f39b37c04ea03ee111302f7ae385f67c\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eTidal\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://bugcrowd.com/afterpay\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAfterpay\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://bugcrowd.com/engagements/blockopensource\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBlock Open Source\u003c/a\u003e\u003c/p\u003e\n\n\u003ch2\u003eSerious about security\u003c/h2\u003e\n\n\u003cp\u003eOur approach to security is designed to protect the CashApp ecosystem. We monitor every transaction, continuously innovate in fraud prevention, and we protect our customers’ data like our business depends on it - because it does. We adhere to industry-leading standards to manage our network, secure our web and client applications, and set policies across our organization.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eA Note on Similar Submissions:\u003c/strong\u003e\u003cbr\u003e\nWe ask that researchers who are able to identify the same or similar types of issues in multiple locations across one of our applications combine those findings into a single submission that includes a description as well as the various locations where vulnerabilities have been identified. This greatly assists us in our triage process and allows us to process your submissions faster. The combined submissions will be evaluated holistically and will receive rewards corresponding to the collective findings. For example, if an application is discovered to have broken access control on a number of API endpoints, please submit a single submission that includes a list of those API endpoints. If separate submissions are made, they may be inadvertently closed as duplicates.\u003c/p\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eCredentials are not provided for this engagement but feel free to self register using your \u003ccode\u003e@bugcrowdninja.com\u003c/code\u003e email address.\u003c/li\u003e\n\u003cli\u003eAccess to *.cashstaging.app is not provided, however, if you are able to hit the site and find vulnerabilities you are welcome to submit them here. \u003c/li\u003e\n\u003cli\u003eThe flags are long enough that brute force won't work. You'll have to be more creative!\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules of Engagement\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf you are able to access or modify personal data of Cash App customers or other sensitive data, immediately contact Block - do not attempt to conduct post-exploitation work.\u003c/li\u003e\n\u003cli\u003eDo not use, share, publish, or disclose information obtained in the course of identifying issues. After submitting you must delete, purge, and/or destroy all copies of information or digital samples.\u003c/li\u003e\n\u003cli\u003eDo not attempt a denial-of-service attack.\u003c/li\u003e\n\u003cli\u003eDo not use ChatGPT, DeepSeek, Google Gemini or any AI tools during your research. You may not disclose any information within these platforms.\u003c/li\u003e\n\u003cli\u003ePlease contact support@bugcrowd.com for any escalations. Do not contact Cash App, Block, or Block aliases to follow up on submissions. Doing so can result in point reduction or program expulsion.\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eCash App for iOS\u003c/strong\u003e: \u003ca href=\"https://itunes.apple.com/us/app/cash-app/id711923939?mt=8\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://itunes.apple.com/us/app/cash-app/id711923939?mt=8\u003c/a\u003e\u003cbr\u003e\n\u003cstrong\u003eCash App for Android\u003c/strong\u003e: \u003ca href=\"https://play.google.com/store/apps/details?id=com.squareup.cash\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://play.google.com/store/apps/details?id=com.squareup.cash\u003c/a\u003e\u003cbr\u003e\n\u003cstrong\u003eCash App for Web\u003c/strong\u003e: \u003ca href=\"https://cash.app\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://cash.app\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eAny finding or (sub)domain that is not listed in scope but is confirmed owned by Cash/Block may be accepted upon review. Rewards for these findings may differ and fall under the Subdomain Takeover rubric shown below.\u003c/p\u003e\n\n\u003ch3\u003eFocus Area: Authentication Flows\u003c/h3\u003e\n\n\u003cp\u003eIn our commitment to maintaining the highest level of security and trust in Cash App, we are particularly interested in identifying and mitigating vulnerabilities that may affect the integrity of our authentication systems. We urge security researchers to concentrate their efforts on exploring and testing the robustness of our authentication flows, including but not limited to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eLogin Flows: Please focus on the mechanisms that enable users to gain access to their accounts, including multi-factor authentication, and any other methods supported by our platform. We are looking for vulnerabilities that could potentially allow unauthorized access or account takeover.\u003c/li\u003e\n\u003cli\u003eAccount Recovery Flows: Special attention should be paid to the processes that allow users to recover or reset their account access. This includes account recovery questions and factors, and the use of email, phone number or $CashTag for account identification. We aim to uncover any weaknesses that could be exploited to bypass these recovery procedures or to gain unauthorized access to user accounts.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eWe encourage researchers to approach these areas with a creative and critical mindset, exploring potential vulnerabilities that could be exploited through various attack vectors. Our goal is to ensure that our authentication flows are not just compliant with industry standards, but are also as resilient as possible against emerging threats and sophisticated attack methodologies.\u003c/p\u003e\n\n\u003ch2\u003eSubdomain Takeovers\u003c/h2\u003e\n\n\u003cp\u003ePayouts for Subdomain Takeover findings differ from the rewards listed above. Please review the severity and descriptions below before submitting a report.\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eImpact\u003c/th\u003e\n\u003cth\u003eSeverity\u003c/th\u003e\n\u003cth\u003eReward\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eHigh Impact Subdomain Takeover\u003c/td\u003e\n\u003ctd\u003eP2\u003c/td\u003e\n\u003ctd\u003e$2,500\u003c/td\u003e\n\u003ctd\u003eAwarded for domains and subdomains with reputational or technical risk. Also for subdomains under a parent domain with reputational or technical risk, and access to sensitive data on that parent domain.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eBasic Subdomain Takeover\u003c/td\u003e\n\u003ctd\u003eP3\u003c/td\u003e\n\u003ctd\u003e$250 - $500\u003c/td\u003e\n\u003ctd\u003eAwarded for domains and subdomains under a parent domain with reputational or technical risk, but without access to sensitive data on that parent domain.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eConcession award\u003c/td\u003e\n\u003ctd\u003eP4\u003c/td\u003e\n\u003ctd\u003e$100\u003c/td\u003e\n\u003ctd\u003eAwarded for domains and subdomains that are owned by Block and have no risks except publicity risk (which is inherent in ownership).\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003ch2\u003eInfo Stealer Logs\u003c/h2\u003e\n\n\u003cp\u003eBlock is aware of credentials obtained from stealer log malware. While we encourage researchers to submit findings that impact Block or Block customers, we reserve the right to treat each submission and reward on a case by case basis. Payout may not align with our standard payout scheme.\u003c/p\u003e\n\n\u003ch2\u003eProgram Exclusions\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny target that is covered under another Block bug bounty program (e.g. Square, Block Open Source, Tidal, Afterpay)\u003c/li\u003e\n\u003cli\u003eSquare.online, square.links, square.site, and Weebly assets are considered out of scope for this program\u003c/li\u003e\n\u003cli\u003eAny vulnerabilities found in Third-party software \u003c/li\u003e\n\u003cli\u003eAny physical attempts against Square property or data centers\u003c/li\u003e\n\u003cli\u003eLogout CSRF\u003c/li\u003e\n\u003cli\u003ePresence of autocomplete attribute on web forms\u003c/li\u003e\n\u003cli\u003eMissing cookie flags on non-sensitive cookies\u003c/li\u003e\n\u003cli\u003eNo maximum password length\u003c/li\u003e\n\u003cli\u003eAn oracle that discloses whether a given username, email address, or phone number is associated with an actual account. (However, please do submit anything that allows you to recover usernames en masse.) Enumeration of users is only considered valid for Square sites. \u003c/li\u003e\n\u003cli\u003eUsing spoofed emails for phishing\u003c/li\u003e\n\u003cli\u003eReports of the 2-factor token not expiring. We use TOTP codes for two factor.\u003c/li\u003e\n\u003cli\u003eDo not attempt a denial-of-service (DoS) attack\u003c/li\u003e\n\u003cli\u003eCache poisoning resulting in DoS\u003c/li\u003e\n\u003cli\u003ePublic information that is Square customers but not specifically regarding Cash App \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eDisclosure Procedures\u003c/h2\u003e\n\n\u003cp\u003eBlock recognizes the important contributions the security research community can make. We do not publicly disclose vulnerabilities by default. We take the security of our services very seriously and monitor their use for indications of a malicious attack. In order to distinguish legitimate security research from malicious attacks against our services, we promise not to bring legal action against researchers who:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eShare with us the full details of any problem found\u003c/li\u003e\n\u003cli\u003eDo not disclose the issue to others until we’ve had a reasonable time to address it and disclosure has been approved by us\u003c/li\u003e\n\u003cli\u003eDo not intentionally harm the experience or usefulness of the service to others\u003c/li\u003e\n\u003cli\u003eNever attempt to view, modify, access, disclose, exfiltrate, use or damage data belonging to Block, its customers, or others\u003c/li\u003e\n\u003cli\u003eDo not perform any research or testing in violation of the law\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSubmission Quality\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eDetailed steps for reproducing the bug. If valuable, please include any screenshots, links you clicked on, pages visited, etc. We prefer detailed repro steps or video demos.\u003c/li\u003e\n\u003cli\u003eAlways include the linked account name, email address or SMS.\u003c/li\u003e\n\u003cli\u003eDescribe the versions of all relevant components of the attack (eg browser, OS, mobile app version).\u003c/li\u003e\n\u003cli\u003eDescribe a concrete attack scenario. How will the problem impact Cash or Cash customers? Put the problem into context and demonstrate with clear evidence.\u003c/li\u003e\n\u003cli\u003ePlease group related issues into the same report rather than submitting nearly-identical reports. For example, an authorization bypass might affect a handful of endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRegarding Cryptocurrency\u003c/h2\u003e\n\n\u003cp\u003ePlease submit any issues related to cryptocurrency to the Cash program immediately. Cash is eager to work with the community to make sure that every researcher finding related to cryptocurrency will be fairly rewarded given the vulnerability's impact on business and overall severity. This includes compensation that might be higher than what is advertised currently.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"f2f77420-e4fa-42d6-ad5b-08b0ad131492","name":"████████████████","targets":[{"id":"e1cf3828-a25d-4b45-9e81-a89aace8c67f","uri":null,"name":"███████████████████████████████████","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"82b7bad9-40cc-4c8b-b710-5b5b22290279","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"e1cf3828-a25d-4b45-9e81-a89aace8c67f"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"e1cf3828-a25d-4b45-9e81-a89aace8c67f"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"e1cf3828-a25d-4b45-9e81-a89aace8c67f"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"e1cf3828-a25d-4b45-9e81-a89aace8c67f"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"e1cf3828-a25d-4b45-9e81-a89aace8c67f"}],"recentChangeFlags":null},{"id":"177b1d6a-87b9-41d0-9646-b2e392e091e3","uri":null,"name":"███████████████████████████████████████","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7beaab6c-939e-4fdc-896a-c988fd4a736e","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"177b1d6a-87b9-41d0-9646-b2e392e091e3"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"177b1d6a-87b9-41d0-9646-b2e392e091e3"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"177b1d6a-87b9-41d0-9646-b2e392e091e3"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"177b1d6a-87b9-41d0-9646-b2e392e091e3"}],"recentChangeFlags":null},{"id":"198fe9a0-24fb-4f86-9c64-09be8fe253c7","uri":null,"name":"██████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a3e5bd26-ccce-42c6-9b24-c138b6cd57ef","sortOrder":0},"sortOrder":0,"tags":[{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"198fe9a0-24fb-4f86-9c64-09be8fe253c7"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"198fe9a0-24fb-4f86-9c64-09be8fe253c7"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"198fe9a0-24fb-4f86-9c64-09be8fe253c7"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"198fe9a0-24fb-4f86-9c64-09be8fe253c7"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"198fe9a0-24fb-4f86-9c64-09be8fe253c7"}],"recentChangeFlags":null},{"id":"96ec96c5-ef2a-4731-a406-ed6b688a8fe4","uri":null,"name":"█████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0f3d3e6f-b08d-4003-a7ea-0f47264a58d8","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"96ec96c5-ef2a-4731-a406-ed6b688a8fe4"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"267b2770-7863-4e0d-9e07-eb2607a479b6","p1MaxCents":1800000,"p1MinCents":500000,"p2MaxCents":500000,"p2MinCents":100000,"p3MaxCents":50000,"p3MinCents":25000,"p4MaxCents":20000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":5000,"max":18000},"2":{"min":1000,"max":5000},"3":{"min":250,"max":500},"4":{"min":100,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"c6d34348-fa87-46e3-a2d8-277899262021","code":"cashapp","state":"in_progress_paused","endsAt":null,"bountyId":"da25f60e-161b-4371-8b2a-37c3dac6eefe","startsAt":"2020-06-02T19:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/engagement_brief_logos/engagement_brief/logo/363e1493-bcf0-45d6-9225-c8d40f87a64e/d8fb183a-3627-4a21-92c6-c814d961f758.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"This engagment is paused until further notice and will not reopen.","lastTransitionAt":"2026-10-01T05:59:03.257Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/cashapp","changelogs":"/engagements/cashapp/changelog","submissions":null,"announcements":"/engagements/cashapp/announcements","hallOfFame":"/engagements/cashapp/hall_of_fames","crowdstream":null},"announcementsCount":5,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":"updated","userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=cashapp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/cashapp/engagement_subscribers","engagementChangelogsUrl":"/engagements/cashapp/changelog","publishedAt":"2026-10-01T05:59:03.290Z","engagementChangelogUrl":"/engagements/cashapp/changelog/73ca7ddf-de6c-437a-8e3f-43a77efa9e3a","createUserFeedbacksUrl":"/engagements/cashapp/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}