Status DataClose notification

Hack the Bank 2.0: A Private Bug Bounty Case Study for Banks

Dmytro Matviiv
Dmytro Matviiv
CEO HackenProof

Banks invest heavily in security audits, penetration testing, and internal security teams. Yet adding external expertise through a private bug bounty program can help uncover vulnerabilities that traditional assessments may miss.

At the end of 2022, HackenProof and PUMB, one of Ukraine's largest banks, organized Hack the Bank 2.0 — a two-week private bug bounty event.

Twenty invited security researchers tested selected banking systems within a defined scope and submitted more than 50 vulnerability reports. Among the validated findings were several critical vulnerabilities that could have led to data leakage.

Hack the Bank 2.0 demonstrated how a private bug bounty can complement traditional security testing while giving organizations full control over participation, scope, and vulnerability disclosure.


What Was Hack the Bank 2.0?

Hack the Bank 2.0 was a two-week private bug bounty event organized for PUMB.

It followed the first Hack the Bank, which took place a year earlier. Following the success of the first event, HackenProof and PUMB organized a second edition with a new group of invited security researchers.

Unlike a public bug bounty, participation was limited to invited researchers. This gave PUMB full control over who could participate while benefiting from the expertise of external security researchers.

The event included:

  • 20 invited security researchers
  • Two-week testing period
  • Clearly defined testing scope
  • Professional vulnerability validation and triage
  • Rewards for confirmed findings

This format gave the bank a focused testing period while keeping the process clear and controlled.


Why Use a Private Bug Bounty?

While penetration testing and security audits provide structured assessments, a private bug bounty brings together multiple experienced researchers with different approaches to testing.

One researcher may focus on authentication, another on APIs, while others examine business logic or application workflows. Together, these perspectives help uncover vulnerabilities that might otherwise go unnoticed.

For banks and other regulated organizations, the private format also provides greater control by allowing teams to:

  • Invite selected researchers.
  • Define the testing scope.
  • Receive validated vulnerability reports.
  • Reward only confirmed findings.

Results

During the two-week event, researchers submitted more than 50 vulnerability reports.

Among the validated reports were several critical vulnerabilities that could potentially have resulted in data leakage.

The program offered rewards of up to $2,000 for a valid critical finding.

The most active participants also received HackenProof merchandise, including hoodies, trophies, and stickers.


Hack the Bank 2.0 at a glance

  • 20 invited security researchers
  • Two-week online security event
  • 50+ vulnerability reports
  • Multiple critical vulnerabilities identified
  • Up to $2,000 bounty for a critical finding

From a Security Event to Continuous Testing

Hack the Bank 2.0 marked an important milestone in the collaboration between HackenProof and PUMB.

After the event, PUMB continued testing its systems through its active bug bounty program on HackenProof.

The case shows how organizations can begin with a focused private event and later expand into continuous vulnerability testing.

What Businesses Can Learn from Hack the Bank 2.0

Hack the Bank 2.0 demonstrated that a private bug bounty can be an effective addition to an existing security program.

For organizations considering a similar initiative, several principles stand out:

  • Define a clear testing scope.
  • Invite researchers with relevant expertise.
  • Validate and prioritize every report.
  • Be prepared to remediate confirmed findings.
  • Choose a bug bounty format that fits your security goals.

For many organizations, a time-limited private event is a practical first step before launching a long-term bug bounty program.


Conclusion

Hack the Bank 2.0 showed how a private bug bounty can complement traditional security testing by bringing together internal teams and experienced security researchers.

For organizations considering a similar initiative, a time-limited private bug bounty offers a practical way to test systems, improve vulnerability management, and decide whether a long-term bug bounty program is the right next step.

To learn more, explore how to launch a private bug bounty program with HackenProof.

Share article:

Read more on HackenProof Blog