---
title: "One Million Dollars in Bug Bounties"
description: "Shopify announces that it has awarded more than $1M USD through its bug bounty programs, which complement its security strategy by bringing in researchers with varied perspectives to assess the platform. The company says it is the fifth public program among 176 on HackerOne to reach that milestone, after four years of working with researchers. It describes three resolved vulnerabilities: an SSRF in Shopify Exchange that could provide root access within one infrastructure subset, an admin authentication bypass involving duplicate partner accounts, and stored cross-site scripting from improperly sanitized sales-channel SVG files. Shopify disabled or audited affected services, deployed a metadata-concealment proxy, corrected account verification, removed unnecessary admin functionality, and checked for exploitation. It plans to experiment with ways to increase hacker engagement and make the program more attractive."
---

# One Million Dollars in Bug Bounties

[Shopify](https://yomu.fyi/company/shopify) · 2023-10-18 · Apr 3, 2019

**Type:** Announcement

## Summary

Shopify announces that it has awarded more than $1M USD through its bug bounty programs, which complement its security strategy by bringing in researchers with varied perspectives to assess the platform. The company says it is the fifth public program among 176 on HackerOne to reach that milestone, after four years of working with researchers. It describes three resolved vulnerabilities: an SSRF in Shopify Exchange that could provide root access within one infrastructure subset, an admin authentication bypass involving duplicate partner accounts, and stored cross-site scripting from improperly sanitized sales-channel SVG files. Shopify disabled or audited affected services, deployed a metadata-concealment proxy, corrected account verification, removed unnecessary admin functionality, and checked for exploitation. It plans to experiment with ways to increase hacker engagement and make the program more attractive.

## Context

Shopify uses bounty programs as part of its security strategy, relying on researchers with different perspectives and specialties to evaluate its platform and help secure commerce for more than 800,000 businesses.

## Approach / What changed

Shopify rewards external researchers, publicly discloses vulnerability reports, and remediates findings through measures including service shutdowns and audits, metadata concealment, internal-IP restrictions, corrected account verification, removal of unnecessary functionality, and exploitation checks.

## Takeaways

- Shopify became the fifth public program among 176 on HackerOne to reach $1M USD in awarded bounties.
- An SSRF in Shopify Exchange could provide root access to any container in one infrastructure subset; Shopify deployed a metadata concealment proxy and blocked internal IP access.
- A stored XSS issue came from incorrectly sanitizing sales-channel SVG uploads, and the related admin functionality was removed during remediation.

**Tags:** [Bug Bounty](https://yomu.fyi/topic/bug-bounty), [Security](https://yomu.fyi/topic/security)

- Source: [Shopify](https://shopify.engineering/one-million-dollars-in-bug-bounties)
- Source URL: https://shopify.engineering/one-million-dollars-in-bug-bounties
- Ingested by Yomu: 2026-08-31T01:14:27.607Z

[Read original post](https://shopify.engineering/one-million-dollars-in-bug-bounties)
