Rewards can only be credited to a Paytm wallet, KYC is mandatory.
The minimum reward for eligible bugs is 1000 INR, Bounty amounts are not negotiable.
1 valid bug equals 1 reward.
Multiple reports over time can be eligible for Hall of Fame or a digital certificate.
In situations where a bug does not warrant a bounty, we may issue a digital certificate. Our certification process is multi-leveled:
Our Hall of Fame page recognizes the contributions of reporters who have demonstrated a high level of dedication to our program.
Acceptance requires multiple valid reports and remains at the discretion of our team.
Must contain sufficient information including a proof of concept screenshot, video, or code snippet where needed.
You agree to participate in testing the effectiveness of the countermeasure applied to your report.
You agree to keep any communication with Paytm private.
Cross-Site Request Forgery **
On sensitive actions
Cross-Site Scripting **
Self-XSS is out of scope
Open Redirects **
Which allow stealing secrets/tokens
Server Side Request Forgery
Local File Inclusion
Remote File Inclusion
Leakage of Sensitive Data
Remote Code Execution
We will pay significantly (4 times) more for vulnerabilities which would ultimately result in data leakages, authentication bypasses, code execution or payment manipulations.
Don't violate the privacy of other users, destroy data, disrupt our services, etc.
Don't request updates on an hourly basis. We are handling dozens of reports daily and spam impacts Paytm's Bug Bounty Program efficiency.
Only target your own accounts in the process of investigating any bugs/findings. Don't target, attempt to access, or otherwise disrupt the accounts of other users without the express permission of our team.
Don't target our physical security measures, or attempt to use social engineering, spam, distributed denial of service (DDOS) attacks, etc.
In case you find a severe vulnerability that allows system access, you must not proceed further.
It is Paytm’s decision to determine when and how bugs should be addressed and fixed.
Disclosing bugs to a party other than Paytm is forbidden, all bug reports are to remain at the reporter and Paytm’s discretion.
Threatening of any kind will automatically disqualify you from participating in the program.
Exploiting or misusing the vulnerability for your own or others' benefit will automatically disqualify the report.
Bug disclosure communications with Paytm’s Security Team are to remain confidential. Researchers must destroy all artifacts created to document vulnerabilities (POC code, videos, screenshots) after the bug report is closed.