Feed
Bounty Rolling

German EUDI Wallet bug bounty on HackerOne: up to $40,000

Common Codes pays up to $40,000 for security bugs in the d-you app and backend of Germany's EUDI Wallet. The HackerOne program opened September 16, 2026.

The German EUDI Wallet bug bounty is a public program on HackerOne run by Common Codes GmbH, the wallet provider. It covers d-you, the national wallet app that will let people store and present government issued identity data and other digital credentials on their phone. The wallet is set to launch on January 2, 2027.

At the start the scope covers the d-you test apps for Android and iOS, the Remote WSCA, the Wallet Provider Backend, the Mobile Device Vulnerability Management service, the Status List Service and the Push Notification Service. Common Codes says more components will be added in the coming weeks, including the PID Provider and the EUDI Check DE App.

Rewards follow the impact that a researcher can show. Critical findings pay $5,000 to $15,000 depending on the asset. The Extreme rating pays $15,000 to $40,000 and is kept for outcomes such as remote impersonation, forged identities, mass leaks of identity data or a compromise of the trust and signing systems.

Researchers test with a virtual test identity inside the test apps and must not use real personal data. The program sets rate limits, asks for set request headers and excludes denial of service and social engineering. Reports made only by automated tools or language models, with no human testing, are closed.

To get paid, a researcher must submit through a HackerOne account and complete identity checks, tax forms and sanctions screening. Common Codes publishes the architecture documents and the source code of the apps and backend on GitHub, and asks researchers to read them before testing.

Source · hackerone.com/common_codes Published 16 September 2026 · Added here 25 September 2026