avatar
Bug bounty
Public

DataDome Bot Bounty

Online fraud & bot management for mobile apps, websites & APIs

Reward

Bounty
€200
Low
€200
Medium
€500
High
€700
Critical
€1,000

Program

Avg reward
-
Max reward
-

Scopes
6
Supported languages
English
French

Hacktivity

Reports
105
1st response
< 3 days
Reports last 24h
-
Reports last week
-
Reports this month
-

About this program

The goal of this program is to find ways to bypass DataDome bot protection by implementing a scraping bot against our dedicated test environments. Reports about configuration weaknesses, information disclosure, or web application vulnerabilities are out of scope for this program.

DataDome publishes these websites dedicated to researchers:

Reward scenarios

All scenarios require scraping real content from a single IP address. The minimum threshold to qualify is 30,000 allowed requests confirmed in the DataDome Dashboard.

  • Minimum scenario: scraping content should be: 30000 web pages in less than an hour.
  • Medium scenario: 30000 web pages scraped in 30 minutes
  • High scenario: 30000 web pages scraped in 10 minutes
  • Critical scenario: 30000 web pages scraped in less than 1 minute

The report should contain:

  • A description of the attack vector used and the protection mechanism being bypassed.

  • The complete, runnable code to reproduce the scenario.

  • The single IP address used during the attack.

  • The scraped content in the form of hashes contained in the page from the scraped pages (not hashes of the raw HTML files themselves) and HTTP requests return code (must be 200). This flag has the form pagehash_<random_hash> (for example pagehash_b94337d90dafb27683afac39d2a24b3c)
    image.png

  • A CSV file with two columns: the page URL and its associated hash

  • The scraping speed (in hits per sec.)

How we validate

We verify all findings using the DataDome Dashboard Explore section. To qualify, we must observe at least 30,000 allowed requests from your declared IP within the stated time window. We will share a screenshot to confirm or reject the finding. Reports that do not meet this threshold will be closed regardless of the technique described.
Reference: https://docs.datadome.co/docs/how-to-explore-your-data

Important clarifications

Page hashes are the only valid proof of real content. Regardless of the HTTP status code returned, only requests that yield a valid pagehash_<random_hash> extracted from the page content count as bypassed.
Obtaining a DataDome cookie is not a bypass. Acquiring a cookie from any DataDome endpoint does not qualify on its own. Proof must include the full CSV of page hashes and Dashboard-confirmed allowed requests.
Scraping of static assets or URLs excluded from protection by configuration does not qualify. Only requests to protected content count toward the volume threshold.
Findings on DataDome supporting infrastructure only qualify as part of a demonstrated bypass. Any observation on endpoints outside the three target environments, including design characteristics of those endpoints, must be directly linked to a successful scraping scenario meeting the volume thresholds above. Informational findings will not be rewarded

Duplicate policy

A report is a duplicate if a previously accepted report identified the same root bypass mechanism, even if the implementation differs. Variants of a known technique that share the same underlying evasion logic will be closed as duplicates.

Multi-domain findings

If the same attack vector bypasses protection across multiple target domains, only one report will be accepted and rewarded.


Reward

Asset value CVSS
Low
CVSS
Medium
CVSS
High
CVSS
Critical
High
€200€500€700€1,000

Scopes

ScopeTypeAsset value
https://bounty-nodejs.datashield.co
Web application
High
Low
€200
Medium
€500
High
€700
Critical
€1,000
https://bounty-fastly.datashield.co
Web application
High
Low
€200
Medium
€500
High
€700
Critical
€1,000
https://bounty-nginx.datashield.co
Web application
High
Low
€200
Medium
€500
High
€700
Critical
€1,000
*.captcha-delivery.com
Web application
High
Low
€200
Medium
€500
High
€700
Critical
€1,000
js.datadome.co
Web application
High
Low
€200
Medium
€500
High
€700
Critical
€1,000
api-js.datadome.co
API
High
Low
€200
Medium
€500
High
€700
Critical
€1,000

Out of scopes

  • Distributed attacks (scraping must be performed from a single IP at a time)
  • Denial of service attacks or any technique whose goal is to degrade infrastructure availability. This falls outside the scope of bot protection bypass and will not be rewarded.
  • Social engineering of DataDome employees or contractors
  • Client-side web vulnerabilities

Vulnerability types

Qualifying vulnerabilities

  • A submission qualifies if it demonstrates a successful bypass of DataDome bot protection meeting all of the following conditions:
  • The scraping is performed from a single IP address against one of the three target environments.
  • The report includes the mandatory CSV file of page URLs and their associated hashes covering every scraped page.
  • The DataDome Dashboard confirms at least 30,000 allowed requests from the declared IP within the stated time window.
  • The report includes complete, runnable reproduction code.
  • The bypass exploits a weakness in DataDome's protection engine, not a misconfiguration specific to the test environment.
  • If a finding on endpoints outside the three target environments contributes directly and demonstrably to a successful scraping scenario meeting the above thresholds, it may qualify as part of that report.

Non-qualifying vulnerabilities

  • Reports without the mandatory CSV file of page URLs and hashes
  • Reports without runnable reproduction code
  • Cookie acquisition without demonstrated successful scraping at scale
  • Scraping of static assets or URLs excluded from protection by configuration
  • Techniques relying on multiple IPs, IP rotation, or distributed infrastructure
  • Findings based on a misconfiguration specific to the test environment rather than a weakness in DataDome's protection engine
  • Informational findings on DataDome infrastructure outside the three target environments that do not contribute to a demonstrated bypass at scale Reports where the Dashboard does not confirm the required volume of allowed requests

Hunters collaboration

When submitting new report, you can add up to 5 collaborators, and define the reward split ratio.

For more information, see help center.
Note: For reports that have already been rewarded, it is not possible to redistribute the rewards.

To submit a vulnerability report, you need to login with your hunter account.