Two bounties on @intigriti. $3000 + $100
Both bypasses of previously resolved reports
1 year ago: ChatGPT + a lot of manual work to find one of these
Today: gave the old reports to Claude Code, it confirmed the fixes and found bypasses for both. Fully automated
Workflow has changed completely
Old writeup: https://t.co/IpJMqhxlLY
Old tweet: https://t.co/H9IjYOzNAW
@shazcodes Guys if you feel smart. Good at reading people and good at maths and you are working in IT without interest. Then leave IT and start playing poker. I earn 2L minimum per month using 5k to 10k
day 2: how to hit bounty quick $1,500.
Tip for bug bounty hunters: every AI chatbot on a website is an attack surface now.
I asked a company's AI support bot to "help me understand this error."
The error was a base64-encoded XSS payload.
The bot decoded it. Rendered it in the DOM. Zero sanitization.
That gave me JavaScript execution on their site.
From there:
→ Cookie downgrade via OAuth flow
→ Stole authentication tokens
→ Full account takeover
I reported it. 4 months of silence.
Then they quietly patched it and told me they "couldn't reproduce it."
So I sent video proof. Timestamps. Working PoC. Everything documented.
$500 → $1,500.
Every company is rushing to ship AI features. Nobody is auditing the output. If it renders in the DOM, it's probably vulnerable.
Go test them. Free XSS everywhere.
And if they try to lowball you — push back. Always push back.
Full YouTube lab breaking down the entire chain if this hits 2,000 ❤️