The white hat hacker community is one of the pillars HackenProof is built on. No bug bounty platform can function without a dedicated community of security researchers behind it, and meeting those researchers face to face is part of HackenProof's culture. That belief led to Hacken Cup, an onsite bug bounty marathon held in Kyiv, Ukraine, in October 2018, where 25 of the world's top hackers spent nine hours hunting for vulnerabilities in real products.
Here's how the event came together, who took part, and what the hackers found.
Announcing Hacken Cup
Hacken Cup was billed as an onsite bug bounty marathon where a select group of hackers would test web apps, mobile apps, and smart contracts, giving participating companies a rare chance to meet top researchers face to face, build relationships with the hacker community, and surface vulnerabilities before they turned into financial or reputational damage.
The event was scheduled to run over three days, from October 7th to 9th, 2018, in Kyiv:
- Day 1 – Hackers arrive in Kyiv, check into their hotel, and kick things off with a networking evening.
- Day 2 – The main event: a full day of onsite bug hunting, capped with an award ceremony and a bar party.
- Day 3 – Entertainment day, with a trip to the Chornobyl Exclusion Zone for those who wanted to go (a Kyiv sightseeing tour was offered as an alternative), followed by a goodbye dinner.
Only 20 hacker slots were available, and anyone could apply through the Hacken Cup page for a shot at one of them. Companies interested in having their products tested were invited to reach out directly. Blockchain Hub Kyiv supported the event.
A change to the application process
As the September 5th, 2018 application deadline approached, HackenProof adjusted how hackers could apply. Originally, getting access to the application form required passing a CTF challenge embedded in the invitation email. In the final days before the deadline, that requirement was dropped: the application became publicly accessible to every bounty hunter in the community, giving more people a fair shot at one of the limited spots. Applications would be screened carefully, with selected participants announced on September 7th, 2018.
Hackers who had already completed the original CTF weren't forgotten—each received 50 reputation points and 50 HKN tokens on their HackenProof account as a thank-you for the effort.
Crypviser confirms its spot
Shortly before the event, German cybersecurity company Crypviser confirmed it would be one of the companies putting its product in front of the assembled hackers. The Crypviser Network is an all-in-one decentralized communications platform combining instant messaging, voice and video calls, a built-in crypto wallet, and local protection features, accessible through mobile apps. Crypviser was also set to appear at HackIT, an international cybersecurity conference taking place in Kyiv that same October 2018, giving the community a second chance to connect with the team.
By the time hackers began arriving, HackenProof had pulled in researchers from the US, the Netherlands, India, Denmark, Germany, France, Egypt, Ukraine, and Sweden—a group with a collective track record of finding vulnerabilities at companies like Google, Microsoft, Twitter, Yahoo, Apple, Adobe, Uber, Dell, IBM, and SANS, spanning web, mobile, smart contract, and IoT specializations.
The Event

Hacken Cup wasn't HackenProof's first onsite marathon—the previous year, the team had run HackIT Cup in Kharkiv. Planning for Hacken Cup began months earlier, with the team scouting for companies whose products would make compelling targets. Applicants worked through a CTF challenge to earn their spot (with community members Arbin and Sahil later publishing a video walkthrough and written write-up of the challenge). In the end, 25 hackers made it to Ukraine.
The marathon itself took place on October 8th, 2018, at Blockchain Hub in Kyiv, with three targets lined up for the hackers: Crypviser, Uklon (Ukraine's largest peer-to-peer ridesharing app), and an international social platform. Hacking began at 10:30 a.m., with nine hours on the clock.

Throughout the day, HackenProof's triage team worked through a steady stream of incoming reports while resolving issues as they surfaced. HackenProof's head, Evgenia Broshevan, spent part of the day speaking with local media about the role bug bounty programs play in modern security, and the team also hosted a visit from partner LongHash.
By the end of the nine hours, hackers had submitted 102 vulnerability reports—a result both HackenProof and its client companies described as far beyond what they'd expected from a single working day.
Results and awards

The team Taxi Drivers—made up of Sahil, Geekboy, and Yassine—topped the leaderboard, reporting 23 bugs between them.

CUBETEAM (Sam and Abdullah) was recognized for earning the most rewards at the event.

After the award ceremony, hackers, clients, and guests headed to an afterparty to celebrate the day's work, with keynote guest Mike Boxmining receiving a surprise gift from Hacken for his wedding anniversary. It was also a chance for hackers—many of whom had been quietly reporting bugs from the same room all day—to finally compare notes on what they'd each found.

The next morning, the group set off for the promised trip to Chornobyl.
What the Hackers Found: Crypviser Network

Crypviser was one of the three companies tested at Hacken Cup, and the results offer a good look at what a focused, time-boxed marathon can surface. In the days leading up to the event, hackers received partial recon information on their targets and formed teams to coordinate their approach. Every report went through validation by HackenProof's triage team, working alongside Crypviser's own technical staff on site.
Within Crypviser's scope, hackers submitted 11 vulnerability reports, of which 4 were validated: two rated medium and two rated low severity under CVSSv3. In summary:
- iOS app doesn't validate server certificates (Medium)—The Crypviser iOS app accepted any TLS certificate presented for its node endpoint, meaning certificate validation wasn't enforced.
- Non-constant-time HMAC comparison during container decryption (Low)—A timing-attack-style weakness in how the app compared HMAC values during decryption. Crypviser's team assessed the practical risk as minimal, since exploiting it would require an attacker who had already passed authentication and a feedback channel the app doesn't expose.
- Username lookups sent over unencrypted HTTP (Low)—Requests checking whether a username existed were sent in the clear, making them interceptable—for example, while adding a contact.
- Missing URL scheme validation enabling file deletion/overwrite (Medium)—The mechanism used to share files between apps only checked that a URL pointed to a file, without validating session or account ownership. That gap could let an attacker overwrite or delete files belonging to other accounts, and the file-existence checks involved created a possible side channel for leaking filenames.
Crypviser fixed all four validated vulnerabilities. Notably, no vulnerabilities were found in the Crypviser Network's underlying nodes during the event. HackenProof credited Sophia d'Antoine, Ryan Stortz, and Dima Kovalenko for the reports.
Crypviser launches a public bug bounty program
Following its participation in Hacken Cup, Crypviser Network announced a 30-day public bug bounty program on HackenProof for its Crypviser Secure Messenger iOS app, offering researchers up to $3,000 for critical vulnerabilities. The program opened to researchers on October 24th, 2018. HackenProof noted its appreciation for companies willing to be public about the security of their products.
Closing Thoughts
Hacken Cup brought together 25 hackers from nine countries, three target companies, and 102 vulnerability reports in a single working day—a clear demonstration of what a well-organized, in-person bug bounty marathon can produce compared to a purely remote program. For HackenProof, the event reinforced why face-to-face time with the community matters: it's a chance to gather direct feedback, deepen relationships with researchers, and give client companies a front-row seat to how their products hold up under focused scrutiny.



