Bug Bounties

DuckDuckGo

Powered by: 

Allows bounty splitting: 

Average time to first program response: 17

Average time to bounty awarded null: 

Average time to report resolved: 

Handle duckduckgo

Managed program: true

Name: DuckDuckGo

Offers bounties: false

Offers swag: true

Response efficiency percentage: 100

Submission state: open

Url: https://hackerone.com/duckduckgo

Website: https://duckduckgo.com

In scope:

  • Asset identifier: *.duckduckgo.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.duckduckgo.mobile.android
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.duckduckgo.mobile.ios
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: https://github.com/duckduckgo/duckduckgo-privacy-extension
  • Asset type: SOURCE_CODE
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical