Mettle

  • $50 – $5,000 per vulnerability

New Target added: Mettle web app

We hope your testing is going well. Here is an update that should make things a bit more interesting!

There have been some recent changes on the Mettle program. We highly recommend you take a look at this additional attack surface – which hopefully means more vulnerabilities! Here is what’s new:

Name URL Description Change
Mettle web app https://web-app.eevee.bbp-mettle.co.uk/login Trimmed down version of the Mettle mobile app that can be accessed through the browser Added

As always, please see the program brief for the full details around testing (spoiler: you will need a Mettle BBP account before being able to log into the Mettle web app).

If you have any questions, please reach out to security@mettle.co.uk.

Get out there and lay claim to those bugs!