Account take-over

Max payout:

$130k*

Guidelines

This guideline illustrates how we assess the security impact of Account Takeover (ATO) vulnerabilities. We cap the maximum base payout for an ATO vulnerability at $130,000* and then apply any applicable deductions based on required user interaction, prerequisites, and any other mitigating factors to arrive at the final awarded bounty amount.

2FA account protection We do not apply any deduction if your ATO vulnerability doesn’t work on accounts which have 2FA enabled; however, if the vulnerability bypasses 2FA, we’ll award an additional bounty based on our 2FA bypass payout guidelines.

Payouts

Account take-over
up to
$130k*

Our payout guidelines are based on required user interaction, and we measure this based on how many clicks are required from the targeted person (in a reasonable scenario) in order for their account to be compromised. Visiting a malicious link would be considered a 1-click ATO.

Based on the type of interaction required by the target of the attack, we might apply additional deductions not listed here. An example interaction where we would apply a deduction is authorizing a malicious app.

These guidelines apply to our main technologies (Facebook, Instagram, and Meta accounts).

Maximum payouts

0-Click ATO
up to
$130k*
1-Click ATO
up to
$50k*
2-Click ATO
up to
$25k*
>2-Click ATO
up to
$10k*
As we strive to reward for the maximum security impact of any given vulnerability, specific classifications of issues such as XSS which directly result in ATO will be rewarded under the same guidelines.
Business & page take-over
up to
$50k*

This guideline illustrates how we assess the security impact of Business and Page Takeover vulnerabilities.

Maximum payouts

0-Click takeover
up to
$50k*
1-Click takeover
up to
$25k*
2-Click takeover
up to
$12k*
>2-Click takeover
up to
$10k*
Please note that N-Click Takeover vulnerabilities that require a specific, more unlikely action/setup to trigger may face additional deductions. Additionally, on a case-by-case basis, there may be other factors beyond unlikely action/setup that may warrant additional deductions.

Vulnerabilities that require a malicious app are deemed 1-Click Takeovers, and if the vulnerability requires special permissions on the app, each required permission counts as one additional click. That means a third-party app with public profile permission is already 1-Click, and each required permission on top of that adds one additional click.