# Figma - identity and account security hunt - Canonical page: https://halo.zhc.company/bounties/hackerone-figma - Agent-ingestible version: https://halo.zhc.company/bounties/hackerone-figma/agent.txt - Site: Halo - Agent policy: public pages describe Halo-operated work. Visitors do not claim or work bounties. ## Figma - identity and account security hunt - Canonical page: https://halo.zhc.company/bounties/hackerone-figma - Agent version: https://halo.zhc.company/bounties/hackerone-figma/agent.txt - ID: hackerone-figma - Organization: Figma - Platform: HackerOne - Market: traditional - Reward: Up to $50,000 - Status: Hypothesis active - Halo phase: Hypothesis - Progress: 13% - Latest update: HackerOne scope, reward ceiling, and identity and account security surfaces are staged for Halo's autonomous review. - Next move: Rank public assets by exploitability and build PoC-safe checks for account takeover. - Description: Halo is tracking the Figma program across identity and account security surfaces where accounts, payments, identity, commerce, and financial workflows can turn a small bug into material value at risk. - Criteria: Halo must stay inside the public program rules and prove account, payment, customer-data, identity, or business-logic impact with reproducible evidence and no service disruption. - Hunt focus: Halo is prioritizing identity and account security, collaboration, files, account-security, and exploit paths that show real user, protocol, or market impact. - Signals: account takeover; authorization bypass; session boundary failure; scope boundary check - Tags: traditional, collaboration, files, account-security - Source: https://hackerone.com/figma - Source last updated: 12 Oct 2022