Bug Bounties

Kindred Group

Powered by: 

Allows bounty splitting: 

Average time to first program response: 24

Average time to bounty awarded null: 44

Average time to report resolved: 237

Handle kindred_group

Managed program: false

Name: Kindred Group

Offers bounties: true

Offers swag: false

Response efficiency percentage: 100

Submission state: open

Url: https://hackerone.com/kindred_group

Website: https://www.kindredgroup.com

In scope:

  • Asset identifier: *.bingo.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Platform 1**
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.casinohuone.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Platform 2**
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.highrolling.nu
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Platform 1**
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.igame.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Platform 2**
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.kindredext.net
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.kolikkopelit.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Platform 2**
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.mariacasino.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Platform 2** The only other localized TLD eligible for bounties is .se
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.ottokasino.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Platform 2** Registration requires a Finnish SSN. Please do not conduct any testing against Trustly, the identity provider for this application.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.storspiller.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Platform 1** *.storspelare.se is also in scope.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.unibet.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Platform 1** This includes all localized TLDs and localized subdomains (with exceptions below), for example: * *.unibet.co.uk * *.unibet.se * be.unibet.com **EXCEPTIONS** All US markets are **out of scope**, which includes the following localized TLDs and subdomains: * *.nj.unibet.com * *.pa.unibet.com * *.in.unibet.com * *.va.unibet.com * *.ia.unibet.com * *.az.unibet.com
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.unibet.fr
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: 
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: *.vladcazino.ro
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: **Platform 1**
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: 463335337
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Unibet - Live Sports Betting https://itunes.apple.com/gb/app/unibet-live-sports-betting/id463335337
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: 669969610
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Unibet Paris Sportifs https://apps.apple.com/fr/app/unibet-paris-sportifs/id669969610
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: 905382680
  • Asset type: APPLE_STORE_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: Unibet Casino - Slots & Games https://itunes.apple.com/gb/app/unibet-casino-slots-games/id905382680
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: Components
  • Asset type: OTHER
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The following gaming components are in-scope: * https://www.unibet.co.uk/betting/racing#/
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.unibet.casino
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The APK file is available for download: Unibet Casino - Slots & Games https://cdn.unicdn.net/apk/UnibetCasino.apk
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: com.unibet.unibetpro
  • Asset type: GOOGLE_PLAY_APP_ID
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: The APK file is available for download: Unibet - Live Sports Betting https://cdn.unicdn.net/apk/UnibetSports.apk
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: https://www.32red.com
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: * Only the `www` subdomain is in scope – other subdomains are explicitly out of scope. * We are currently not accepting client-side bugs that **only** affect the HTTP site. Please verify that any client-side bugs work on the HTTPS site before submitting.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: maria.casino
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: unibet.me and maria.casino share the same platform, we will only reward the initial report for any bug, as one fix will solve the bug on both domains.
  • Integrity requirements: high
  • Max severity: critical



  • Asset identifier: relaxcdn.unibet.com
  • Asset type: URL
  • Availability requirement: none
  • Confidentiality requirement: none
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: Operated by a third-party. Reports for this domain will be triaged but are ineligible for a bounty.
  • Integrity requirements: low
  • Max severity: low



  • Asset identifier: unibet.me
  • Asset type: URL
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: true
  • Eligible for submissions: true
  • Instruction: unibet.me and maria.casino share the same platform, we will only reward the initial report for any bug, as one fix will solve the bug on both domains.
  • Integrity requirements: high
  • Max severity: critical