Early access: this site has moved to bugrater.com.
NR Unrated
Whoop Bug Bounty
Whoop Bug Bounty HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Whoop Bug Bounty? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 22 Sep 2026.

What it pays, by severity

Critical $3,000 avg 3 reports thin
High $1,500 avg 17 reports indicative
Medium $500 avg 16 reports indicative
Low $150 avg 13 reports indicative

$45,600 paid to researchers in total, $10,750 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
103
in 90 days
Resolved
49
all time, last one yesterday
Participants
84
hunters engaged
Response efficiency
74%
below its own targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 15 days 101–113
25 Aug 103 reports 22 Sep

Response targets it sets itself

First response
1 day
Triage
10 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 31 days (17 snapshots): intake down 8 reports; response efficiency down 3 points; 90-day payout up $5,100.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

81 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 red_darkin 202 6 / 9 67%
2 xavoppa 114 1 / 2 50%
3 danielfarynski 88 5 / 16 31%
4 todayisnew 79 3 / 3 100%
5 galletitaconpate 59 2 / 7 29%
6 elmahdi 57 1 / 1 100%
6 lamscun 57 2 / 3 67%
6 probablyabug 57 0 / 1 0%
6 rcss 57 0 / 0
6 securityreapers 57 1 / 1 100%
6 shaonsec 57 1 / 1 100%
7 gu3rilla 32 1 / 1 100%
12 david96 56 3 / 3 100%
13 zhero_ 39 0 / 0
14 d0xing 32 1 / 1 100%
14 leebrich 32 1 / 1 100%
16 4drez 22 0 / 0
16 7odamoo 22 0 / 0
16 akashhamal0x01 22 1 / 2 50%
16 cainvsilf 22 1 / 1 100%
16 dilosec 22 2 / 7 29%
16 ehtabbu 22 1 / 1 100%
16 entit_y 22 1 / 1 100%
16 godiego 22 1 / 3 33%
16 hamzamalick 22 0 / 1 0%

Showing the top 25 of 81 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 16 Sep 2026.

Unlocking Human Performance

Responsiveness
75% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Feb 2025
Scope entries
15 HackerOne’s count

Scope

15 assets
AssetTypeEligibilityMax severity
*.whoop.com WILDCARD ✓ bounty Critical
**.whoop.com WILDCARD ✓ bounty Critical
api.prod.whoop.com URL ✓ bounty Critical
app.whoop.com URL ✓ bounty Critical
com.whoop.android GOOGLE PLAY APP ID ✓ bounty Critical
Show all 15 assets
AssetTypeEligibilityMax severity
com.whoop.iphone APPLE STORE APP ID ✓ bounty Critical
https://support.whoop.com/Battery_Pack_Updater OTHER ✓ bounty Medium
join.whoop.com OTHER ✓ bounty Critical
shop.whoop.com URL ✓ bounty Critical
WHOOP 4.0 STRAP OTHER ✓ bounty Critical
WHOOP 5.0/MG STRAP OTHER ✓ bounty Critical
Azure AD, Google Drive, Link Sharing Websites OTHER out None
Credit/Debit Card Testing OTHER out None
okta.whoop.com URL out None
Support System OTHER out None