DataDome Bot Bounty
Online fraud & bot management for mobile apps, websites & APIs
Reward
Program
Hacktivity
About this program
The goal of this program is to find ways to bypass DataDome bot protection by implementing a scraping bot against our dedicated test environments. Reports about configuration weaknesses, information disclosure, or web application vulnerabilities are out of scope for this program.
DataDome publishes these websites dedicated to researchers:
- bounty-nodejs.datashield.co (documentation on implementation)
- bounty-fastly.datashield.co (documentation on implementation)
- bounty-nginx.datashield.co (documentation on implementation)
Reward scenarios
All scenarios require scraping real content from a single IP address. The minimum threshold to qualify is 30,000 allowed requests confirmed in the DataDome Dashboard.
- Minimum scenario: scraping content should be: 30000 web pages in less than an hour.
- Medium scenario: 30000 web pages scraped in 30 minutes
- High scenario: 30000 web pages scraped in 10 minutes
- Critical scenario: 30000 web pages scraped in less than 1 minute
The report should contain:
-
A description of the attack vector used and the protection mechanism being bypassed.
-
The complete, runnable code to reproduce the scenario.
-
The single IP address used during the attack.
-
The scraped content in the form of hashes contained in the page from the scraped pages (not hashes of the raw HTML files themselves) and HTTP requests return code (must be
200). This flag has the formpagehash_<random_hash>(for example pagehash_b94337d90dafb27683afac39d2a24b3c)
-
A CSV file with two columns: the page URL and its associated hash
-
The scraping speed (in hits per sec.)
How we validate
We verify all findings using the DataDome Dashboard Explore section. To qualify, we must observe at least 30,000 allowed requests from your declared IP within the stated time window. We will share a screenshot to confirm or reject the finding. Reports that do not meet this threshold will be closed regardless of the technique described.
Reference: https://docs.datadome.co/docs/how-to-explore-your-data
Important clarifications
Page hashes are the only valid proof of real content. Regardless of the HTTP status code returned, only requests that yield a valid pagehash_<random_hash> extracted from the page content count as bypassed.
Obtaining a DataDome cookie is not a bypass. Acquiring a cookie from any DataDome endpoint does not qualify on its own. Proof must include the full CSV of page hashes and Dashboard-confirmed allowed requests.
Scraping of static assets or URLs excluded from protection by configuration does not qualify. Only requests to protected content count toward the volume threshold.
Findings on DataDome supporting infrastructure only qualify as part of a demonstrated bypass. Any observation on endpoints outside the three target environments, including design characteristics of those endpoints, must be directly linked to a successful scraping scenario meeting the volume thresholds above. Informational findings will not be rewarded
Duplicate policy
A report is a duplicate if a previously accepted report identified the same root bypass mechanism, even if the implementation differs. Variants of a known technique that share the same underlying evasion logic will be closed as duplicates.
Multi-domain findings
If the same attack vector bypasses protection across multiple target domains, only one report will be accepted and rewarded.
Reward
| Asset value | CVSS | CVSS | CVSS | CVSS |
|---|---|---|---|---|
| €200 | €500 | €700 | €1,000 |
Scopes
| Scope | Type | Asset value | Expand rewards grid |
|---|---|---|---|
https://bounty-nodejs.datashield.co | Web application | ||
Low Medium High Critical | |||
https://bounty-fastly.datashield.co | Web application | ||
Low Medium High Critical | |||
https://bounty-nginx.datashield.co | Web application | ||
Low Medium High Critical | |||
*.captcha-delivery.com | Web application | ||
Low Medium High Critical | |||
js.datadome.co | Web application | ||
Low Medium High Critical | |||
api-js.datadome.co | API | ||
Low Medium High Critical | |||
Out of scopes
- Distributed attacks (scraping must be performed from a single IP at a time)
- Denial of service attacks or any technique whose goal is to degrade infrastructure availability. This falls outside the scope of bot protection bypass and will not be rewarded.
- Social engineering of DataDome employees or contractors
- Client-side web vulnerabilities
Vulnerability types
Qualifying vulnerabilities
- A submission qualifies if it demonstrates a successful bypass of DataDome bot protection meeting all of the following conditions:
- The scraping is performed from a single IP address against one of the three target environments.
- The report includes the mandatory CSV file of page URLs and their associated hashes covering every scraped page.
- The DataDome Dashboard confirms at least 30,000 allowed requests from the declared IP within the stated time window.
- The report includes complete, runnable reproduction code.
- The bypass exploits a weakness in DataDome's protection engine, not a misconfiguration specific to the test environment.
- If a finding on endpoints outside the three target environments contributes directly and demonstrably to a successful scraping scenario meeting the above thresholds, it may qualify as part of that report.
Non-qualifying vulnerabilities
- Reports without the mandatory CSV file of page URLs and hashes
- Reports without runnable reproduction code
- Cookie acquisition without demonstrated successful scraping at scale
- Scraping of static assets or URLs excluded from protection by configuration
- Techniques relying on multiple IPs, IP rotation, or distributed infrastructure
- Findings based on a misconfiguration specific to the test environment rather than a weakness in DataDome's protection engine
- Informational findings on DataDome infrastructure outside the three target environments that do not contribute to a demonstrated bypass at scale Reports where the Dashboard does not confirm the required volume of allowed requests
Hunters collaboration
When submitting new report, you can add up to 5 collaborators, and define the reward split ratio.
For more information, see help center.
Note: For reports that have already been rewarded, it is not possible to redistribute the rewards.