# A Decade of Defense: Celebrating Grab's 10th Year Bug Bounty Program

[Grab](https://yomu.fyi/company/grab) · Pei Shan Yap · Dec 1, 2025

## Summary

Grab's bug bounty program has operated for a decade in partnership with HackerOne, expanding from an initial cohort of 23 researchers to over 850 active participants across global regions. The program's scope broadened between 2023 and 2024 to encompass artificial intelligence systems, Indonesian financial services, and a dedicated bounty table for mobile-specific security issues. Grab extended external testing coverage through live hacking appearances at ThreatCon 2023 and DEFCON 32, as well as invite-only anniversary campaigns with regional clubs in Germany, Morocco, and India. Internal cybersecurity teams manage vulnerability reports by emphasizing rapid triage times, direct communication, and payouts upon triage. Over the decade, reported vulnerabilities transitioned from foundational flaws toward more sophisticated and emerging threat categories.

## Takeaways

- Grab expanded its bug bounty scope during 2023–2024 to include AI systems, Indonesian financial services, and a specialized bounty structure for mobile vulnerabilities.
- A dedicated August 10th-anniversary bug bounty campaign generated 461 vulnerability submissions alongside invite-only regional club events in Germany, Morocco, and India.
- The program evolved from an initial group of 23 researchers into a network of over 850 active security researchers protecting more than 187 million users.

**Tags:** [Authentication](https://yomu.fyi/topic/authentication), [Testing](https://yomu.fyi/topic/testing)

[Read original post](https://engineering.grab.com/a-decade-of-defense)
