{"id":"93be9e4d-159a-4ea9-a2b9-c77f1efd62f7","engagementId":"b9533eb1-98fb-4b56-bc82-086cf2a35a46","data":{"brief":{"id":"7811fed0-0962-4154-9c70-9190b8dd9bfe","name":"TIDAL","tagline":"TIDAL is a global music streaming platform bringing fans closer to artists through unique experiences and the highest sound quality.","description":"\u003ch2\u003eBlock, Inc.\u003c/h2\u003e\n\n\u003cp\u003eThis program is part of Block, Inc. You can participate in our other bug bounty programs below:\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://bugcrowd.com/square?preview=3b034fbb39b8f94910e4ae07720b1d7f\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSquare\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://bugcrowd.com/cashapp?preview=741329c7a958c6d3ce61ac7970eb2ab7\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCash App\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://bugcrowd.com/afterpay\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAfterpay\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://bugcrowd.com/engagements/blockopensource\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBlock Open Source\u003c/a\u003e\u003c/p\u003e\n\n\u003ch2\u003eSerious about security\u003c/h2\u003e\n\n\u003cp\u003eWe adhere to industry-leading standards to manage our network, secure our web and client applications, and set policies across our organization. Part of our mission at TIDAL is to protect the information of our customers and artists. To do that we need to proactively find and fix any security issues in our software offerings. We recognize the important contributions the security research community can make and hope that you’ll help us protect our customers and artists.\u003c/p\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"\u003cp\u003eAny domain/property of Block (including TIDAL) not listed in the targets section is out of scope. This includes any/all subdomains not listed under “Target information”.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003etidal.com and any subdomains\u003c/li\u003e\n\u003cli\u003ewimpmusic.com and any subdomains\u003c/li\u003e\n\u003cli\u003etidalhifi.com and any subdomains\u003c/li\u003e\n\u003cli\u003etidalhi.fi and any subdomains\u003c/li\u003e\n\u003cli\u003etdl.sh and any subdomains\u003c/li\u003e\n\u003cli\u003eTIDAL Desktop Client (Electron application)\u003c/li\u003e\n\u003cli\u003eTIDAL Client for iOS: \u003ca href=\"https://apps.apple.com/us/app/tidal-music/id913943275\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eTIDAL for Android: \u003ca href=\"https://play.google.com/store/apps/details?id=com.aspiro.tidal\u0026amp;hl=en_US\u0026amp;gl=US\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHere\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eAny other official TIDAL clients for any platform.  If you’re unsure whether a client is official, please contact us for clarification before beginning work.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess:\u003c/h2\u003e\n\n\u003cp\u003ePlease sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cp\u003eFlaws within authentication or authorization workflows, especially\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities that might expose personal information\u003c/li\u003e\n\u003cli\u003eVulnerabilities that might expose unauthorized content\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRules of Engagement\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eTesting or messaging live Artist accounts is an automatic program expulsion.\u003c/li\u003e\n\u003cli\u003eDo not reach out to other TIDAL artists or users unless it’s an account you own.\u003c/li\u003e\n\u003cli\u003eIf you are able to access or modify personal data of TIDAL customers or other sensitive data, immediately contact Block - do not attempt to conduct post-exploitation work.\u003c/li\u003e\n\u003cli\u003eDo not use, share, publish, or disclose information obtained in the course of identifying issues. After submitting you must delete, purge, and/or destroy all copies of information or digital samples.\u003c/li\u003e\n\u003cli\u003eDo not attempt a denial-of-service attack without prior written approval.\u003c/li\u003e\n\u003cli\u003ePlease contact support@bugcrowd.com for any concerns or escalations. Do not contact TIDAL directly or other Block product lines. Doing so can result in point reduction or program expulsion.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSubdomain Takeovers\u003c/h2\u003e\n\n\u003cp\u003eFindings for subdomain takeovers are sorted by risk category. Please review the severity and descriptions below before submitting a report.\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eImpact\u003c/th\u003e\n\u003cth\u003eSeverity\u003c/th\u003e\n\u003cth\u003eReward\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eHigh Impact Subdomain Takeover\u003c/td\u003e\n\u003ctd\u003eP2\u003c/td\u003e\n\u003ctd\u003e$1,500\u003c/td\u003e\n\u003ctd\u003eAwarded for domains and subdomains with reputational or technical risk. Also for subdomains under a parent domain with reputational or technical risk, and access to sensitive data on that parent domain.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eBasic Subdomain Takeover\u003c/td\u003e\n\u003ctd\u003eP3\u003c/td\u003e\n\u003ctd\u003e$250 - $500\u003c/td\u003e\n\u003ctd\u003eAwarded for domains and subdomains under a parent domain with reputational or technical risk, but without access to sensitive data on that parent domain.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eConcession award\u003c/td\u003e\n\u003ctd\u003eP4\u003c/td\u003e\n\u003ctd\u003e$100\u003c/td\u003e\n\u003ctd\u003eAwarded for domains and subdomains that are owned by Block and have no risks except publicity risk (which is inherent in ownership).\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eKnown Issues:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eMember addition to family:\n\n\u003cul\u003e\n\u003cli\u003eAbility to create accounts without proof of email address control.\u003c/li\u003e\n\u003cli\u003ePlain text password in email.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSecrets embedded in application code (web, mobile or desktop). TIDAL client embeds a key to allow Last.FM scrobbling.\u003c/li\u003e\n\u003cli\u003eLack of certificate pinning enabling man-in-the-middle attack.\u003c/li\u003e\n\u003cli\u003eNo subscription is needed to play music.  TIDAL has a free tier that allows clients to play music even without a paid subscription, as long as they are logged in.\u003c/li\u003e\n\u003cli\u003ePersonal accounts with @tidal.com addresses \u003cem\u003e\u003cstrong\u003eare not\u003c/strong\u003e\u003c/em\u003e considered Admin/Employee accounts. Leaked credentials found via a web archive or info stealer are considered \u003cstrong\u003eout of scope\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003ePlaylists are explicitly left out of the block functionality. They are still accessible via uuid/shared url/favorites tab.\u003c/li\u003e\n\u003cli\u003eTIDAL app geo-restriction bypass.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope bugs for Android apps:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eInformation leaked through the system clipboard\u003c/li\u003e\n\u003cli\u003eSusceptibility to MITM attacks (e.g. Absence of certificate pinning or sensitive data in URLs or request bodies when protected by TLS)\u003c/li\u003e\n\u003cli\u003eSensitive data stored in app private directory\u003c/li\u003e\n\u003cli\u003eSensitive data stored unencrypted on external storage\u003c/li\u003e\n\u003cli\u003eLack of code obfuscation or anti-debugging controls\u003c/li\u003e\n\u003cli\u003eRecoverable secrets hard coded in APK (e.g. OAuth \"app secret\")\u003c/li\u003e\n\u003cli\u003eHijacking or installing a third-party app to attack the TIDAL platform\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope bugs for iOS apps:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eInformation leakage through Snapshot/Pasteboard\u003c/li\u003e\n\u003cli\u003eSusceptibility to MITM attacks (e.g. Absence of certificate pinning Sensitive data in URLs or request bodies when protected by TLS)\u003c/li\u003e\n\u003cli\u003eSensitive data stored unencrypted on the file system\u003c/li\u003e\n\u003cli\u003eLack of code obfuscation or anti-debugging controls\u003c/li\u003e\n\u003cli\u003eRecoverable secrets hard coded in app binary (e.g. OAuth \"app secret\")\u003c/li\u003e\n\u003cli\u003eLack of exploit mitigations ie PIE, ARC, or Stack Canaries\u003c/li\u003e\n\u003cli\u003eLack of jailbreak detection\u003c/li\u003e\n\u003cli\u003eExploits only possible in a jailbroken environment\u003c/li\u003e\n\u003cli\u003eHijacking or installing a third-party app to attack the TIDAL platform\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope for Tidal \u0026amp; related subdomains\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eCache poisoning resulting in DoS\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eThird Party Vendor Policy:\u003c/h2\u003e\n\n\u003cp\u003eThird party submissions will be considered Out of Scope. With that said, if you believe you’ve identified an issue with one of our third-party service providers as the result of Tidal’s misconfiguration or insecure usage of that service, we’d appreciate your report regarding the issue.\u003c/p\u003e\n\n\u003cp\u003ePlease keep in mind that any reports regarding third-party services are likely to NOT be eligible for a reward – both cash and Kudos points.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eDisclosure Procedures\u003c/h2\u003e\n\n\u003cp\u003eBlock recognizes the important contributions the security research community can make. We do not publicly disclose vulnerabilities by default. We take the security of our services very seriously and monitor their use for indications of a malicious attack. In order to distinguish legitimate security research from malicious attacks against our services, we promise not to bring legal action against researchers who:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eShare with us the full details of any problem found.\u003c/li\u003e\n\u003cli\u003eDo not disclose the issue to others until we’ve had a reasonable time to address it and disclosure has been approved by us.\u003c/li\u003e\n\u003cli\u003eDo not intentionally harm the experience or usefulness of the service to others.\u003c/li\u003e\n\u003cli\u003eNever attempt to view, modify, access, disclose, exfiltrate, use or damage data belonging to Block, its customers, or others.\u003c/li\u003e\n\u003cli\u003eDo not perform any research or testing in violation of the law.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSubmission Quality\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eDetailed steps for reproducing the bug. If valuable, please include any screenshots, links you clicked on, pages visited, etc. We prefer detailed repro steps and video demos.\u003c/li\u003e\n\u003cli\u003eDescribe the versions of all relevant components of the attack (e.g. browser, OS, mobile app version).\u003c/li\u003e\n\u003cli\u003eDescribe a concrete attack scenario. How will the problem impact TIDAL, its users, or content providers? Put the problem into context and demonstrate with clear evidence.\u003c/li\u003e\n\u003cli\u003ePlease group related issues into the same report rather than submitting nearly-identical reports. For example, an authorization bypass might affect a handful of endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eMultiple Submissions of the Same Vulnerability\u003c/h2\u003e\n\n\u003cp\u003eWe ask that researchers who identify the same or similar types of issues in multiple locations throughout an application combine those findings into a single submission whose description includes the locations where the issues were identified. This greatly assists us in our triage process and allows us to process your submissions faster. The combined submission will be evaluated holistically and will be rewarded corresponding to the collective findings. For example, if an application is discovered to have broken access control on a number of API endpoints, please submit a single submission that includes a list of those API endpoints. If separate submissions are made, they may be inadvertently closed as duplicates.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOpenPGP key\u003c/h2\u003e\n\n\u003cp\u003eIf you have data that you feel is particularly sensitive and would like to encrypt before sending it to our bug bounty, please use the following OpenPGP key for encryption:\u003c/p\u003e\n\n\u003cp\u003ehttps://tidal.com/.well-known/pgp-key.txt\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eWrite this key to a file (ie tidal-public.key)\u003c/li\u003e\n\u003cli\u003eThen import it:\n\u003cstrong\u003e\u003cem\u003egpg --import tidal-public.key\u003c/em\u003e\u003c/strong\u003e\n\u003c/li\u003e\n\u003cli\u003eEncrypt your report (ie report-tidal-security.docx):\n\u003cstrong\u003e\u003cem\u003egpg --output report-tidal-security.docx.gpg --encrypt --recipient security@tidal.com report-tidal-security.docx\u003c/em\u003e\u003c/strong\u003e\n\u003c/li\u003e\n\u003cli\u003eSend your encrypted report to us by email at security@tidal.com.\u003c/li\u003e\n\u003c/ol\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"3cbbe43b-ceda-4afb-81e7-2f68f1ecb45c","name":"████████████████","targets":[{"id":"5411a111-c12f-451f-8bc9-91e100149cb3","uri":null,"name":"███████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"03faf3b8-6f57-409b-b1eb-e4aee2721059","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5411a111-c12f-451f-8bc9-91e100149cb3"}],"recentChangeFlags":null},{"id":"2a577dbb-3bce-4fde-849b-90311d468ac6","uri":null,"name":"███████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"02993fee-9035-419d-a4ac-fcb4926cf923","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2a577dbb-3bce-4fde-849b-90311d468ac6"}],"recentChangeFlags":null},{"id":"dd416238-16dc-4c77-8f65-ef5e0d594f17","uri":null,"name":"███████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7bbc5d79-541f-477d-b00d-ffe8342ac566","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"dd416238-16dc-4c77-8f65-ef5e0d594f17"}],"recentChangeFlags":null},{"id":"c7508668-0974-4cc5-a7dd-927719340a1b","uri":null,"name":"█████████████","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"fb12b9c1-6b84-4dbc-8347-6c55b6ec6148","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"c7508668-0974-4cc5-a7dd-927719340a1b"}],"recentChangeFlags":null},{"id":"b78710fe-1069-4039-b417-9d4b207e2056","uri":null,"name":"███████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1c50fad1-721b-4cfd-bc79-d8b303a046e4","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b78710fe-1069-4039-b417-9d4b207e2056"}],"recentChangeFlags":null},{"id":"2339bb83-baac-4b00-ab64-2472a1a5cbf0","uri":null,"name":"████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"fbddf291-1817-423e-8c90-e003fa1d50e3","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2339bb83-baac-4b00-ab64-2472a1a5cbf0"}],"recentChangeFlags":null},{"id":"74442fda-83f0-48b9-bf93-9d51a34c2702","uri":null,"name":"████████████████████","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e095b1be-333d-4d35-8061-7bf3adefb9eb","sortOrder":0},"sortOrder":0,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"74442fda-83f0-48b9-bf93-9d51a34c2702"}],"recentChangeFlags":null},{"id":"63c047cb-bb75-4053-bd05-6144aa4f6301","uri":null,"name":"████████████████████████","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b5c8890e-c7a0-479d-b08e-475efe77e372","sortOrder":0},"sortOrder":0,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"63c047cb-bb75-4053-bd05-6144aa4f6301"}],"recentChangeFlags":null},{"id":"a8845bcc-a2bf-4133-9a13-efe295952bbc","uri":null,"name":"████████████████████","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"bc7a7172-02d2-45a3-8960-787b32c83428","sortOrder":0},"sortOrder":0,"tags":[{"id":"47f8649b-7612-4d6d-bb41-c0078e628292","name":"Electron","targetId":"a8845bcc-a2bf-4133-9a13-efe295952bbc"}],"recentChangeFlags":null},{"id":"2bd2749d-18aa-4af4-813b-7c9cf2b9c91b","uri":null,"name":"████████████████████████████████████████████████████████████████████████","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4431e43a-37d3-4795-a4a5-acfa4a451c0f","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"26e7e9da-1ca9-4352-bccc-3e2c1f2bb0f2","p1MaxCents":500000,"p1MinCents":250000,"p2MaxCents":150000,"p2MinCents":100000,"p3MaxCents":50000,"p3MinCents":25000,"p4MaxCents":20000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":2500,"max":5000},"2":{"min":1000,"max":1500},"3":{"min":250,"max":500},"4":{"min":100,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"d273d3b3-c2d5-4163-b079-5dd287a764e1","name":"████████████████████","targets":[{"id":"67f5c013-a77a-4f6e-bddd-a5413f8ca2e3","uri":null,"name":"███████████████████","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"391228ad-0ba8-4000-a854-5773ae4397d4","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"67f5c013-a77a-4f6e-bddd-a5413f8ca2e3"}],"recentChangeFlags":null},{"id":"7f781919-0ae7-4bb5-8caf-a728abb25c50","uri":null,"name":"███████████████","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9a4b75af-366e-4464-b3b3-f57a67760d9f","sortOrder":1},"sortOrder":1,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7f781919-0ae7-4bb5-8caf-a728abb25c50"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"b9533eb1-98fb-4b56-bc82-086cf2a35a46","code":"tidal-bugbounty","state":"in_progress_paused","endsAt":null,"bountyId":"da25f60e-161b-4371-8b2a-37c3dac6eefe","startsAt":"2022-07-12T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/engagement_brief_logos/engagement_brief/logo/7811fed0-0962-4154-9c70-9190b8dd9bfe/2afb5f20-88fe-4aff-b529-06578f10b5b9.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"This engagement is paused until further notice and will not reopen.","lastTransitionAt":"2026-10-01T05:59:50.916Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/tidal-bugbounty","changelogs":"/engagements/tidal-bugbounty/changelog","submissions":null,"announcements":"/engagements/tidal-bugbounty/announcements","hallOfFame":"/engagements/tidal-bugbounty/hall_of_fames","crowdstream":null},"announcementsCount":6,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":"updated","userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=tidal-bugbounty\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/tidal-bugbounty/engagement_subscribers","engagementChangelogsUrl":"/engagements/tidal-bugbounty/changelog","publishedAt":"2026-10-01T05:59:50.942Z","engagementChangelogUrl":"/engagements/tidal-bugbounty/changelog/93be9e4d-159a-4ea9-a2b9-c77f1efd62f7","createUserFeedbacksUrl":"/engagements/tidal-bugbounty/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}