Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

duckduckgo

HackerOneView on HackerOne
RawAI Enhanced
4
In Scope
0
Out of Scope
In-Scope Assets (4)
AssetCategoryBountyQuick Links
*.duckduckgo.comWILDCARDNo
com.duckduckgo.mobile.androidANDROIDNo
com.duckduckgo.mobile.iosIOSNo-
https://github.com/duckduckgo/duckduckgo-privacy-extensionCODENo-
Scope Changes (12)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Added*.duckduckgo.comWILDCARDIn Scope19:09
Addedhttps://github.com/duckduckgo/duckduckgo-privacy-extensionCODEIn Scope19:09
Addedcom.duckduckgo.mobile.iosIOSIn Scope19:09
Addedcom.duckduckgo.mobile.androidANDROIDIn Scope19:09
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedhttps://github.com/duckduckgo/duckduckgo-privacy-extensionCODEIn Scope00:40
Addedcom.duckduckgo.mobile.iosIOSIn Scope00:40
Addedcom.duckduckgo.mobile.androidANDROIDIn Scope00:40
Added*.duckduckgo.comWILDCARDIn Scope00:40
Feb 21, 2026
ChangeAssetCategoryScopeTime
Addedcom.duckduckgo.mobile.iosIOSIn Scope19:11
Added*.duckduckgo.comWILDCARDIn Scope19:11
Addedhttps://github.com/duckduckgo/duckduckgo-privacy-extensionCODEIn Scope19:11
Addedcom.duckduckgo.mobile.androidANDROIDIn Scope19:11