{"id":"2a22afbc-7959-4be1-ad47-054ecc6db7d6","engagementId":"fedac6ed-0e7b-45c3-87ae-0484e34c8b81","data":{"brief":{"id":"61c189c0-84cf-4c0e-857c-77a4f8741a68","name":"Chime Managed Bug Bounty Engagement","tagline":"We unite everyday people to unlock their financial progress!","description":"\u003ch2\u003eIntroduction\u003c/h2\u003e\n\n\u003cp\u003eWelcome to Chime’s Bug Bounty Program!\u003c/p\u003e\n\n\u003cp\u003eAs a fintech leader, security is at the heart of everything we do. We’re committed to providing our members with a safe, reliable banking experience, and your expertise as a security researcher plays a vital role in making that possible.\u003c/p\u003e\n\n\u003cp\u003eAt Chime, our mission is to bring financial peace of mind to everyone. We’ve helped millions of Americans by removing unnecessary fees, enabling automatic savings, and offering financial wellness features such as fee-free overdrafts, early paycheck access through MyPay, credit building tools, and Chime at Workplace. These benefits only matter if they’re secure, and that’s where you come in.\u003c/p\u003e\n\n\u003cp\u003eBy participating in our bug bounty program, you’re helping us stay ahead of emerging threats, protect our members, and uphold the trust they place in us.\u003c/p\u003e\n\n\u003cp\u003eThank you for collaborating with us to make Chime even more secure.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eHigh-Value Focus Areas\u003c/h1\u003e\n\n\u003cp\u003eWe strongly encourage researchers to direct testing toward high-impact business logic and mobile endpoints:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eGraphQL Implementations:\u003c/strong\u003e Query complexity abuses, broken object-level authorization (BOLA/IDOR), and field-level permission bypasses.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eMobile Applications (iOS \u0026amp; Android):\u003c/strong\u003e Security flaws in native endpoints, session storage, and IPC mechanisms on non-rooted/non-jailbroken devices.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eMoney Movement \u0026amp; Ledger Integrity:\u003c/strong\u003e Bypassing daily/monthly transfer limits, race conditions/retry logic leading to financial advantage (e.g., double spending), and UI vs. backend balance desynchronization.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eIdentity \u0026amp; Account Lifecycle:\u003c/strong\u003e Skipping KYC/activation steps to achieve a funded account state, referral/rew\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSeverity Determination\u003c/h2\u003e\n\n\u003cp\u003eWe use a combination of \u003cstrong\u003eImpact\u003c/strong\u003e and \u003cstrong\u003eExploitability\u003c/strong\u003e to determine final severity​:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf a vulnerability could directly affect finances or sensitive data for many users, it will likely be Critical.\u003c/li\u003e\n\u003cli\u003eIf it affects individual users or non-sensitive data, it may be High or Medium.\u003c/li\u003e\n\u003cli\u003eIf it requires unlikely user interaction or has mitigations in place (e.g., a theoretical bug that can't be exploited easily), it may be Low or even Informational. We will communicate our severity reasoning when triaging your report. If you believe we misclassified something, we are open to dialogue – our goal is to be fair and consistent.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eWhat's in Scope\u003c/h2\u003e\n\n\u003cp\u003eAll Chime-owned assets and services are in scope unless explicitly listed as Out of Scope. Testing is permitted across production and QA/development environments per the testing guidelines. If an unlisted asset demonstrably belongs to Chime, you may report it; however, it will be handled as vulnerability disclosure only and is ineligible for bounties or points.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eDisclosure Policy\u003c/h1\u003e\n\n\u003cp\u003e\u003cstrong\u003eRespect confidentiality:\u003c/strong\u003e Please \u003cstrong\u003edo not discuss or publicize\u003c/strong\u003e vulnerabilities found in this program. This includes both vulnerabilities that are still being triaged and those that have been resolved. If in doubt, ask our team for clarification before sharing any information.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eParticipation Criteria\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eBy participating, you represent that you (i) are at least 18 years old, (ii) are not located in, organized under the laws of, or ordinarily resident in a jurisdiction subject to comprehensive U.S. sanctions, (iii) are not identified on the U.S. Treasury Department’s Specially Designated Nationals and Blocked Persons List (“SDN List”) or any other U.S. restricted-party list, and (iv) are not, and are not owned or controlled (\u0026gt;50 %), by any person or entity designated on the U.S. Department of Commerce Entity List, Unverified List, or Military End-User List, or otherwise subject to U.S. export-control restrictions.\u003c/li\u003e\n\u003cli\u003eYou may not submit vulnerability reports while physically present in any jurisdiction subject to comprehensive U.S. sanctions.\u003c/li\u003e\n\u003cli\u003eYou must not be a current employee or immediate family member of Chime or any third party managing Chime’s digital assets or infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eGeneral Rules\u003c/strong\u003e\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003e\n\u003cstrong\u003eSubmit One Vulnerability Per Report:\u003c/strong\u003e If multiple bugs must be chained to show impact, explain the full chain clearly in a single submission.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eOne Fix = One Bounty\u003c/strong\u003e: Multiple endpoints or parameters sharing the exact same root cause will be awarded a single bounty as duplicates.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eReproducibility:\u003c/strong\u003e Reports must contain clear, step-by-step instructions or PoC code. Unreproducible reports will be marked ineligible.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccount Interaction:\u003c/strong\u003e Only interact with accounts you own or have explicit permission to test. Stop immediately and report if you encounter another member's sensitive PII.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNo Targeting:\u003c/strong\u003e Do not target Chime employees, contractors, or real members during testing.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch2\u003eExamples of Valid Vulnerabilities\u003c/h2\u003e\n\n\u003cp\u003eTo help you focus on impactful findings, here are examples of vulnerabilities in different severity categories. These examples illustrate the kinds of issues we consider critical, high, medium, or low severity. This is not an exhaustive list, but a guideline. We assess severity case-by-case based on impact and exploitability.\u003c/p\u003e\n\n\u003ch2\u003eSeverity Determination Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eCritical (P1): Direct compromise of sensitive data, funds, or infrastructure; multi-user/systemic impact (e.g., unauthorized fund transfers, double-spend race conditions, production RCE, SSN leaks, critical SQLi, AWS SSRF).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eHigh (P2): Single-user account takeover (ATO), non-production RCE, single-user PII exposure, access control flaws affecting an isolated user account.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMedium (P3): Limited non-sensitive information exposure (e.g., email address enumeration, viewing limited non-financial account details).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eLow (P4): Low-impact issues with minimal exploitability (e.g., non-critical subdomain takeovers without escalation paths).\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eProgram Exclusions\u003c/h2\u003e\n\n\u003cp\u003eWhen reporting vulnerabilities, please consider (1) the attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOut-of-Scope Vulnerabilities \u0026amp; Assets\u003c/li\u003e\n\u003cli\u003eOut-of-Scope Vulnerabilities\u003c/li\u003e\n\u003cli\u003eDebug information disclosures without sensitive data, stack traces, or software version/banner disclosure.\u003c/li\u003e\n\u003cli\u003eMissing security best practices without direct exploitability (e.g., SSL/TLS configurations, missing CSP headers, missing HttpOnly/Secure flags on non-sensitive cookies).\u003c/li\u003e\n\u003cli\u003eMissing email authentication records (SPF, DKIM, DMARC) or basic user enumeration with insignificant data exposure.\u003c/li\u003e\n\u003cli\u003eClickjacking on unauthenticated pages or forms lacking sensitive state-changing actions.\u003c/li\u003e\n\u003cli\u003eUnauthenticated CSRF on login/logout forms or non-sensitive actions.\u003c/li\u003e\n\u003cli\u003eOpen redirects without a secondary chained exploit path.\u003c/li\u003e\n\u003cli\u003eDenial of Service (DoS/DDoS) attacks, rate-limiting on non-auth endpoints, or load testing.\u003c/li\u003e\n\u003cli\u003eAttacks requiring physical access to a victim device, MITM positioning, or unlikely user interactions.\u003c/li\u003e\n\u003cli\u003eSocial engineering (phishing, vishing, smishing) against employees or members.\u003c/li\u003e\n\u003cli\u003eMobile app lack of obfuscation, missing root/jailbreak detection, or missing cert pinning (Certificate Transparency is used).\u003c/li\u003e\n\u003cli\u003ePublicly exposed API keys meant for public use (e.g., DataDog client tokens, Google Maps keys).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eOut-of-scope vulnerability reports that pose a valid security impact may be addressed as a form of vulnerability disclosure but will generally not be considered eligible for a bounty. If you aren't sure whether something is in scope, you can ask us by submitting a question via Bugcrowd or contacting us directly.\u003c/p\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, and NOT otherwise, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws. Researchers remain responsible for compliance with laws of the jurisdiction where the testing occurs.\u003c/li\u003e\n\u003cli\u003eChime will not pursue civil or criminal action against researchers for good-faith activities that comply with these rules, including accidental limited data access, provided the data is promptly reported and not retained.\u003c/li\u003e\n\u003cli\u003eNothing in this program waives remedies for willful misconduct or breaches of confidentiality obligations.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e  or contact \u003ccode\u003ebugbounty[AT]chime[DOT]com\u003c/code\u003e for clarification before proceeding.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"8ccd0b52-e3a0-4df9-825f-ca9dc653eb1d","name":"Primary Targets","targets":[{"id":"6cfa0690-7ae9-421b-a7ad-17b642c8c58a","uri":"","name":"All Chime Assets","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c5b9c434-9df4-4338-add5-44ec6bc2283f","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"6094fa1f-6384-4ce8-8445-21a8b09ad34b","uri":"","name":"*.chimepayments.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f238edd0-f51d-4863-9435-bf26d5683663","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"2d8a8441-9ef7-424b-8319-8c98939818f3","uri":"https://*.chime.com","name":"*.chime.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"11181245-90ef-4d22-916c-8efdd5815f3b","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"718aa085-ba7a-4c02-b74b-739098e36b8c","uri":"","name":"*.1debit.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4dcb155d-24cd-40bd-bbf3-da8dfd574db8","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"66e8cc93-d64d-408f-afae-56effb7a990c","uri":"","name":"*.chimecard.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5df2b110-4ad9-4039-9db3-6df626b57bcd","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"f636b393-f44e-4cd9-ae47-321c44e3cf97","uri":"","name":"*.chmfin.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"611a585f-2541-4e22-8f32-f529a9b9e5b2","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null},{"id":"92c55833-d9c4-46e7-b07c-b71dfb353843","uri":"","name":"*.chimebank.com\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3ec7448a-4b21-44d7-9034-76a180e3f12e","sortOrder":6},"sortOrder":6,"tags":null,"recentChangeFlags":null},{"id":"5a008636-ce1e-4046-b6ec-fcfb9acef4a3","uri":"https://www.chime.com","name":"www.chime.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a6da812d-8648-4c75-a5d4-cdb82f2bc84b","sortOrder":7},"sortOrder":7,"tags":null,"recentChangeFlags":null},{"id":"7b7c3075-c22a-4fb3-8281-89fbde3332d3","uri":"https://app.chime.com","name":"app.chime.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5c2a75df-efcc-439c-b53d-bb816e3da804","sortOrder":8},"sortOrder":8,"tags":null,"recentChangeFlags":null},{"id":"fff4da93-d883-4646-8212-aeda2b22bd68","uri":"https://play.google.com/store/apps/details?id=com.onedebit.chime","name":"Chime - Android App (Prod)","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"97adcaa4-e235-4605-8bc2-ade1dd03cc05","sortOrder":9},"sortOrder":9,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"fff4da93-d883-4646-8212-aeda2b22bd68"}],"recentChangeFlags":null},{"id":"6ec0581a-610e-4bac-babe-3d347e8f5c27","uri":"https://apps.apple.com/us/app/chime-mobile-banking/id836215269","name":"Chime - iOS App (Prod)","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1e6f4020-0669-456e-8b8e-9ee1aeb932eb","sortOrder":10},"sortOrder":10,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"6ec0581a-610e-4bac-babe-3d347e8f5c27"}],"recentChangeFlags":null},{"id":"706da84f-6a5e-4da6-9c7f-c179461bb367","uri":"https://drive.google.com/file/d/17IX06JcI2Nn7hbg9kDps5iK6oVi9U71O/view?usp=sharing","name":"Chime - Android App (Beta)","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e4538435-6d10-4569-94e7-ae8c1e9fdccc","sortOrder":13},"sortOrder":13,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"706da84f-6a5e-4da6-9c7f-c179461bb367"}],"recentChangeFlags":null},{"id":"fdfad293-9a51-4e53-ac80-1187fe379070","uri":"http://member-qa.chime.com/enroll","name":"Enrollment - (QA)","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8a40d855-c600-4a4a-8eca-b206d9b2ad84","sortOrder":13},"sortOrder":13,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"fdfad293-9a51-4e53-ac80-1187fe379070"}],"recentChangeFlags":null},{"id":"89d21a7a-53ca-4a5e-b680-25f4881aa8a8","uri":"https://app-qa.chime.com/login","name":"Sign In - (QA)","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e7746067-9550-4289-b002-fc32111637a8","sortOrder":13},"sortOrder":13,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"89d21a7a-53ca-4a5e-b680-25f4881aa8a8"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"c92e8c82-b034-402f-90f7-ece30b7c1061","p1MaxCents":2000000,"p1MinCents":1000000,"p2MaxCents":500000,"p2MinCents":450000,"p3MaxCents":50000,"p3MinCents":25000,"p4MaxCents":10000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch1\u003eHow to Test\u003c/h1\u003e\n\n\u003ch2\u003eProduction Testing (U.S. Researchers Only)\u003c/h2\u003e\n\n\u003col\u003e\n\u003cli\u003eEnrollment: Register via \u003ca href=\"https://www.chime.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.chime.com\u003c/a\u003e using your @bugcrowdninja.com email alias. Complete standard KYC (requires valid US SSN, DOB, Address, and non-VoIP US phone number).\u003c/li\u003e\n\u003cli\u003eMultiple Test Accounts: To test member-to-member transfers, set up your primary account first. Then contact bugbounty[AT]chime[DOT]com with your Bugcrowd username to allow SSN reuse for alias emails (e.g., alias+test1@bugcrowdninja.com).\u003c/li\u003e\n\u003cli\u003eMobile Apps: Download production builds from the App Store / Play Store or obtain current beta IPA/APK builds via the program Scope tab.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch2\u003eStaging Testing (Non-U.S. Researchers \u0026amp; Non-KYC Testing)\u003c/h2\u003e\n\n\u003col\u003e\n\u003cli\u003eEnrollment: Register a QA account at \u003ca href=\"https://member-qa.chime.com/enroll/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://member-qa.chime.com/enroll/\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eLogin: Access the web portal at \u003ca href=\"https://app-qa.chime.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app-qa.chime.com/\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eTips: Use a US phone number and test SSN patterns (e.g., SSN ending in 1234 or 1235) to bypass transient QA validation errors. Download QA mobile builds from the program Scope page. If you don\u0026#39;t have a US phone number, you can use a VOIP US number or a Fictitious telephone number as phone verification is disabled by default on the QA environment.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003e\u003cstrong\u003eAccount enrollment tips:\u003c/strong\u003e If you encounter errors during enrollment, you can try again using a different randomly generated SSN pattern (e.g., one ending in \u0026quot;1234\u0026quot;, or \u0026quot;1235\u0026quot;). This can help bypass transient validation issues that occasionally occur in QA.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eTesting the Mobile App:\u003c/strong\u003e When testing the mobile app, make sure to use the test (staging) builds that can be downloaded from the bug bounty scope. Select the \u0026quot;QA\u0026quot; environment and log in using your staging test accounts.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNotes\u003c/strong\u003e \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eSSN values\u003c/strong\u003e: Because the staging environment is not stable by nature, you may need to try different random SSN patterns (e.g., SSN ending with 1234 or 1235) to create a test account.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUS phone number required\u003c/strong\u003e: You will need to use a US phone number to create an account. Non-US phone numbers are not supported.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003e\u003cstrong\u003eAdditional Information For Testing\u003c/strong\u003e\u003c/h1\u003e\n\n\u003cp\u003eWe encourage researchers to focus on vulnerabilities that could impact Chime member accounts and personal information or financial integrity. Business logic and API testing are especially valuable to us, these typically uncover issues that automated scanners can’t detect and can result in higher bounty payouts.\u003c/p\u003e\n\n\u003cp\u003eWhen you’re testing, please note:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eUse caution with real money\u003c/strong\u003e: If you test any functionality that involves moving money (e.g., transfers, deposits), use small amounts and preferably use your own two accounts to send money back and forth. We recommend limiting any test transfers to $50 or less, and using features like Pay Friends or bank transfers between accounts you control. We will reimburse reasonable testing-related losses if something unexpected happens, but you should not be attempting large-scale transactions as part of testing.\u003cbr\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eBe mindful of testing impact\u003c/strong\u003e: When testing in production, remember you are dealing with real data and systems. Do not do anything that could negatively affect other Chime members or the platform’s availability, or cause reputational damage. Follow the Program Rules at all times. If in doubt about an action (for example, testing a potential vulnerability that might disrupt service), stop and ask us. We will work with you to find a safe way to test, if possible.\u003cbr\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCredit checks are not required:\u003c/strong\u003e The Chime account sign-up will ask for personal details (see below), but note that we do not perform a credit inquiry for opening an account. You will receive a Chime debit card in the mail, but no credit line is involved.\u003cbr\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUSA-only for production testing\u003c/strong\u003e: As mentioned, only researchers in the United States (with an SSN) can create Chime accounts and test on production. We apologize if this limits some international researchers – you are still welcome to test on our development environment or review our public-facing assets for vulnerabilities that don’t require account access.\u003cbr\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRequired KYC information:\u003c/strong\u003e Chime is a financial institution, so we must collect certain information to open an account. You will need to provide: Full Name, Social Security Number (SSN), Date of Birth, Physical Address (your mailing address – note that a debit card will be sent here, even for test accounts), Mobile Phone Number (must be a valid US mobile number; VoIP or internet-based numbers are not accepted due to verification constraints), Email Address (use your Bugcrowd email alias as mentioned).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eAccount Support\u003c/h1\u003e\n\n\u003cp\u003eIf your test account is flagged or locked by fraud systems, do not create unapproved bypass accounts. Contact bugbounty[AT]chime[DOT]com with your Bugcrowd username to have your account unlocked.\u003c/p\u003e","rewardRangeData":{"1":{"min":10000,"max":20000},"2":{"min":4500,"max":5000},"3":{"min":250,"max":500},"4":{"min":50,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"99ad2777-357e-43e0-a0f0-460b800056f7","name":"Secondary Targets","targets":[{"id":"883b7866-a685-4dc9-b392-d926f71254a4","uri":"","name":"*.saltlabs.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8ff9d9cc-c5cf-4b8d-a3c5-ec541bd6ac6a","sortOrder":0},"sortOrder":0,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"883b7866-a685-4dc9-b392-d926f71254a4"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"883b7866-a685-4dc9-b392-d926f71254a4"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"883b7866-a685-4dc9-b392-d926f71254a4"}],"recentChangeFlags":null},{"id":"f75c4c39-1d27-497c-a777-32399c41bd5b","uri":"https://app.saltlabs.com/","name":"app.saltlabs.com\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f91198c7-5bf5-41a2-bd6a-f3d5231817c6","sortOrder":1},"sortOrder":1,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"f75c4c39-1d27-497c-a777-32399c41bd5b"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"f75c4c39-1d27-497c-a777-32399c41bd5b"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"f75c4c39-1d27-497c-a777-32399c41bd5b"}],"recentChangeFlags":null},{"id":"eb8dcd63-f8f7-450c-acb1-10e0c2397196","uri":"https://play.google.com/store/apps/details?id=com.saltlabs.app","name":"Salt Labs - Android App ","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"703b1c6c-2fd3-44a0-89c0-30f85afbc614","sortOrder":2},"sortOrder":2,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"eb8dcd63-f8f7-450c-acb1-10e0c2397196"}],"recentChangeFlags":null},{"id":"579bb23f-1832-471b-b343-ab754d7699b4","uri":"https://apps.apple.com/us/app/salt-work-and-get-rewarded/id1668462142","name":"Salt Labs - iOS App","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3b632ac2-5257-486c-905b-9ee128b96e5d","sortOrder":3},"sortOrder":3,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"579bb23f-1832-471b-b343-ab754d7699b4"}],"recentChangeFlags":null},{"id":"6000ed85-27a0-46ae-ae6c-5ce7261bf366","uri":"https://app.staging.saltlabs.com/","name":"Salt Labs - Staging Environment","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4b651b1d-9e25-4f88-8105-3028d8512754","sortOrder":4},"sortOrder":4,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"6000ed85-27a0-46ae-ae6c-5ce7261bf366"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"6000ed85-27a0-46ae-ae6c-5ce7261bf366"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"6000ed85-27a0-46ae-ae6c-5ce7261bf366"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"a98db032-936c-46bd-8455-2864ba18d94e","p1MaxCents":700000,"p1MinCents":450000,"p2MaxCents":400000,"p2MinCents":250000,"p3MaxCents":40000,"p3MinCents":20000,"p4MaxCents":10000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eSecondary Targets (Saltlabs Apps)\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eAll researchers\u003c/strong\u003e can test our production version of Saltlabs Apps. Only a U.S. phone number is needed to set up an account.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhere to sign up:\u003c/strong\u003e You can create an account here: \u003ca href=\"https://app.saltlabs.com/session/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.saltlabs.com/session/new\u003c/a\u003e\u003c/p\u003e\n\n\u003ch1\u003e\u003cstrong\u003eAdditional Information For Testing\u003c/strong\u003e\u003c/h1\u003e\n\n\u003cp\u003eWe encourage researchers to focus on vulnerabilities that could impact Chime member accounts and personal information or financial integrity. Business logic and API testing are especially valuable to us, these typically uncover issues that automated scanners can’t detect and can result in higher bounty payouts.\u003c/p\u003e","rewardRangeData":{"1":{"min":4500,"max":7000},"2":{"min":2500,"max":4000},"3":{"min":200,"max":400},"4":{"min":50,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"6617a7e8-dd9b-401a-bcc9-a1186cffd780","name":"Out of Scope","targets":[{"id":"d3207267-a7ee-403c-a36a-e69893abe394","uri":"","name":"Non Chime Owned Assets (see list above)","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"706c1716-9c2a-4929-ba02-a0e5e0d6d551","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"e6fb952b-d6c0-418f-8596-e116df1ea432","uri":"https://chime.financial","name":"chime.financial","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b1a001b4-6e1b-436d-ba7a-805b1f9fd749","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"b48ca66d-22cd-4f8f-b706-c0b4e87905b6","uri":"https://chimescholars.org","name":"chimescholars.org","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9e15d267-1a3e-4079-9a3a-28da11341d0d","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eAny asset not owned by Chime is considered out of scope. Please ensure that the asset you\u0026#39;re testing is owned by Chime.\u003c/p\u003e\n\n\u003cp\u003eTo help you get started, here’s a list of third-party assets that are currently out of scope:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre class=\"highlight plaintext\"\u003e\u003ccode\u003e_acme-challenge.chime.com\n_acme-challenge.chimebank.com\n_acme-challenge.interchange.chime.com\n_acme-challenge.wp-ci.chime.com\n_acme-challenge.wp-dev1.chime.com\n_acme-challenge.wp-dev2.chime.com\n_acme-challenge.wp-dev3.chime.com\n_acme-challenge.wp-dev4.chime.com\n_acme-challenge.wp-dev5.chime.com\n_acme-challenge.wp-integ.chime.com\n_acme-challenge.wp-qa.chime.com\n_acme-challenge.www.chime.com\n_acme-challenge.www.chimebank.com\n16002407.account.chime.com\n16002407.notify.chime.com\nattachments.chime.com\nbounce.accounts.chime.com\nbounce.chime.com\nbounce.chimebank.com\nbounce.updates.chime.com\nbounces.chimecard.com\ncareers.chime.com\ndeveloper.chime.com\nem.account.chime.com\nem.notify.chime.com\nemail.checkr-mail.chime.com\nemail.ethnio.chime.com\nemail.gh-mail.chime.com\nemail.gh-mail.ext.chime.com\nemail.mail.saltlabs.com\nemail.mail.staging.saltlabs.com\nemail.mg.chime.com\nemail.mg.chimecard.com\nemail.news.chime.com\nemail.talent.chime.com\nemail.teamable.chime.com\nenterpriseenrollment.chime.com\nenterpriseenrollment.ext.chime.com\nenterpriseregistration.chime.com\nftp.1debit.com\ngo.chm.life\ngt._domainkey.ext.chime.com\ngt2._domainkey.ext.chime.com\ngtmail.chime.com\ngtmail.ext.chime.com\nhandbooks.chime.com\nhelp-test.chime.com\nhelp.chime.com\nhelp.saltlabs.com\nhs1-45050040._domainkey.hubspot.chime.com\nhs2-45050040._domainkey.hubspot.chime.com\ninterchange.chime.com\njqldc44xpu3j.chimecard.com\nlinks.account.chime.com\nlinks.notify.chime.com\nnd.chime.com\np.chime.com\np.chimecard.com\nresearch.chime.com\ns1._domainkey.account.chime.com\ns1._domainkey.chime.com\ns1._domainkey.chimecard.com\ns1._domainkey.notify.chime.com\ns2._domainkey.account.chime.com\ns2._domainkey.chime.com\ns2._domainkey.chimecard.com\ns2._domainkey.notify.chime.com\nsafetyandsecurity.chime.com\nstatic-attachments.chime.com\nstatus.chime.com\nstatus.chimebank.com\nstatus.saltlabs.com\ntransaction-qa.chime.com\ntransaction.chime.com\nwww.saltlabs.com\n\n\nPlease note that this list may be incomplete. If you need any assistance or have questions, feel free to reach out to us at bugbounty\\[AT\\]chime\\[DOT\\]com.\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"fedac6ed-0e7b-45c3-87ae-0484e34c8b81","code":"chime","state":"in_progress","endsAt":null,"bountyId":"422acf35-4611-4b92-ac7b-93642979f194","startsAt":"2025-05-06T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/ab3b/361c/bd9cc487/9224892564269a0295542710ce8f7362_images.png","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-05-06T18:00:00.303Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/chime","changelogs":"/engagements/chime/changelog","submissions":null,"announcements":"/engagements/chime/announcements","hallOfFame":"/engagements/chime/hall_of_fames","crowdstream":"/engagements/chime/crowdstream"},"announcementsCount":7,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/chime/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=chime\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/chime/engagement_subscribers","engagementChangelogsUrl":"/engagements/chime/changelog","publishedAt":"2026-08-27T16:44:53.306Z","engagementChangelogUrl":"/engagements/chime/changelog/2a22afbc-7959-4be1-ad47-054ecc6db7d6","createUserFeedbacksUrl":"/engagements/chime/feedbacks","engagementCrowdstreamUrl":"/engagements/chime/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}