Standard bounty (no multiplier):
• Pre-account squatting
• Customer storefront accounts (legacy)
• Enumeration
• Brute force w/o rate-limit bypass
• Self-XSS on login
• Generic bugs chained into an auth/ATO impact
Live Mon. https://t.co/0XH3Kbqq8k
Authentication & Account Takeover campaign on our bug bounty program. June 8 through June 26. Multipliers on auth & ATO findings, up to 2× for criticals ↓
Multipliers on standard bounty for auth & ATO findings:
• Medium = 1.25×
• High = 1.5×
• Critical = 2×
Open to any researcher on our HackerOne. No cohort, no invite list.
Recently @tobi shared the philosophy behind River, our Slack-native AI agent, and how it has become a teaching workshop for all of @Shopify.
Below River lies the Aquifer. Principal Engineers @burkelibbey & Javier Moreno share the engineering story of how River came to be, and the substrate it runs on:
⚡ @Shopify is running sub-agents in parallel to analyze complex data over a long horizon for more accurate merchant growth forecasts at a global scale.
Sometimes the most unobvious-but-correct architecture decision is just... using your primary database.
We tried it on one of our highest-stakes checkout paths, at BFCM scale. Here's how it went:
We reverse-engineered training data from thousands of merchant-created automations and fine-tuned Qwen3-32B into a tool-calling agent for Shopify Flow.
Results: 2.2x faster, 68% cheaper
The more interesting part: why we trained on Python instead of our own DSL, and what broke when benchmarks looked good but production didn't. ⬇️
🇧🇷 Come talk shop with Shopify at ICLR 2026 in Rio starting Thursday! 🇧🇷
We're building ML that runs 10% of e-commerce — from LLM-powered agents to production retrieval systems and sim-to-real pipelines. Real problems, real scale. Redefining commerce intelligence.
Stop by Booth #202 for deep dives on:
⚡️Sidekick — agentic merchant AI with MCP tools + multi-turn reasoning
⚡️ Commerce Foundation Model — cross-domain architecture for recs, search, catalog
⚡️ Global Catalog — multimodal LLMs, 10K+ categories, 40M inferences/day
⚡️ Search Rewriting — L1 retrieval + L2 LLM re-ranking at scale
⚡️ SimGym — sim-to-real agent training for storefronts (Expo Talk 📷)
⚡️ Tangle — the open source ml experimentation platform
Since we open-sourced pi-autoresearch, @Shopify teams have been running it on everything.
Results so far:
Unit tests: 300x faster
React component mounting: 20% faster
CI build time: 65% reduction
Made pnpm run faster
Autoresearch never stops trying things you'd never have time to try.
Repo: https://t.co/473UFWKanV