Work at Block Open Source? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
Block, Inc. This program is part of Block, Inc. You can participate in our other bug bounty programs below: Square Cash Tidal Afterpay Rewarding security bugs in our open source projects Block recognizes the important contributions the security research community can make. Part of keeping Block's customers safe is making sure that we find and fix any security issues in our open source projects. If you find any vulnerabilities in any of our participating open source projects, please submit a report. Even better, send us a fix! This program is to report issues in our open source projects. If you believe you have discovered a security vulnerability in one of Block's other product lines (squareup.com, square.com, cash.app, tidal.com, afterpay.com) or mobile applications (Square Point of Sale, Cash App, Tidal), please report them to the other bug bounty programs listed above. Attributes of a good report A well written, detailed explanation and proof-of-concept for the bug that’s easy to follow along. Include specific source code references for the issue from our GitHub organizations. Include repository, release version, branch and other information. Describe the real-world impact/exploitability of the bug. Ineligible reports Issues related to software that’s not within our control (such as external dependencies), not exploitable, and does not pose a significant risk to Block would not be eligible for a reward. Issues relating to outdated or insecure library versions we include. Most of our open source development is publicly visible. Reports related to an issue already being addressed in a branch or being tracked in a public way will therefore not be eligible for a bounty. Reports without a proof-of-concept or clear path to exploitation. Rules of Engagement Be sure to review the project’s README.md file for contributing guidelines before testing. If you are able to access or modify personal data of Block customers or other sensitive data, immediately contact Block - do not attempt to conduct post-exploitation work. Do not use, share, publish, or disclose information obtained in the course of identifying issues. After submitting you must delete, purge, and/or destroy all copies of information or digital samples. Do not attempt a denial-of-service attack. Do not use ChatGPT, Claude, DeepSeek, Google Gemini or any AI tools during your research. You may not disclose any information within these platforms. Please contact support@bugcrowd.com for any escalations. Do not contact Block or Block aliases to follow up on submissions. Doing so can result in point reduction or program expulsion. How to send a fix Please do not open a pull request or GitHub ticket to fix an issue you're reporting. This would unnecessarily reveal any potential vulnerabilities. Instead, if you'd like to send us a fix, please submit a vulnerability report within the repository’s Security tab. Rewards Rewards range from $100 to $5,000 depending on the type of issue and impact. We prioritize and reward issues based on the real-world impact to our software and systems as operated by Block.
Scope
7 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| ██████████████████████████████ | other | ✓ bounty | not set |
| ███████████████████████████████ | other | ✓ bounty | not set |
| █████████████████████████████████ | other | ✓ bounty | not set |
| ███████████████████████████████████ | other | ✓ bounty | not set |
| ███████████████████████████████████████ | other | ✓ bounty | not set |
Show all 7 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| ███████████████████████████████████████████████ | other | ✓ bounty | not set |
| ███████████████████████████████████████████████████ | other | ✓ bounty | not set |