- Critical Thinking - Bug Bounty Podcast
- Posts
- [HackerNotes Ep. 185] Bug Bounty Village at DEF CON 34, with Harley Kimball & Ariel Garcia
[HackerNotes Ep. 185] Bug Bounty Village at DEF CON 34, with Harley Kimball & Ariel Garcia
Today, we dig the Bug Bounty Village event and some tips and tricks for your hackbot
Hacker TL;DR
A free trial turned into superadmin on a multi-tenant SaaS: mass assignment on a leaked
/adminuser/{id}endpoint, a pre-minted magic link to skip the Duo gate, full tenant-wide takeover.Sequential account numbers plus a cardless ATM feature equals an IDOR that hands you real cash out of a real machine. Yes, in production.
Bug Bounty Village is back at DEF CON 34 (Aug 6 to 9), and about half the agenda is now hackbots and AI, both as a tool and as a target.
Harley's hackbot is 30+ specialized agents with a brain, an attack domain, and a triage domain. The scary part is not the recon, it is session safety.

This episode's sponsor is Zero Trust Network Access. Check out the ZTNA rundown.
In the News
Meet YesWeHack at DEF CON 34: they are running the Payload Please Reloaded challenge with a YesWeHack challenge coin, sitting on the AI-assisted submissions panel, and Brumens is presenting "Cache Key Injection: Smuggling Poison Through the Door."
Bug Bounty Village 2026 Agenda: the full lineup, two tracks, roughly 34 sessions Friday through Sunday.
Free Trial to Superadmin
Harley opened with a beauty on a multi-tenant podcasting SaaS. Free trial to superadmin, dump all tenant PII and billing, pull private recordings, impersonate anyone, zero-click ATO across the whole client base.
Here is the chain:
Recon. Self-register as a free user, then let the hackbot do what it is good at: comb the JavaScript, pull endpoints, map hosts, and store the undocumented API paths in a database. Some of those API hosts were not routable from the VPS, so the bot re-routed through residential proxies to reach them.
Privesc. A mass assignment on
PUT /users/{id}worked, butadmin*params were blocked. The JS had leaked a second endpoint,/adminuser/{id}, where those params were not filtered. Self-assignadmin:superadminand you are in. The catch: it instantly invalidates your session and logs you out. The role sticks, the session does not.The MFA wall. Superadmins are auto-enrolled, but you cannot self-enroll, so the login is gated and you are stuck with a superadmin account you cannot use.
The bypass. A separate host on the platform supported magic links, sign in with no password and no MFA. Exchange a magic link for a session token and you can hit the API regardless of the Duo gate.
Order of operations is everything here. You mint the magic link before you escalate, because once you become superadmin the login is locked. So the real flow is: register as free user, mint the magic link, privesc to superadmin via mass assignment, get logged out, redeem the pre-minted link, walk away with a superadmin token. Pwned.
The hackbot found roughly 80% of this and chained a lot of it, but the MFA bypass needed a human to sit down and think it through end to end. That last mile is exactly where people leave criticals on the table right now, submitting half a bug because they did not push through.
Money From an ATM
Ariel's bug was not bug bounty, it was pentest work at an ATM and payments company, so no bounty and definitely no profit beyond the salary. It is a great reminder of why banking apps are so under-tested: nobody wants to touch production banking with their own account and invite the FBI over. Ariel had permission and, better yet, production ATMs sitting in the office.
The target was a mobile wallet with a cardless withdrawal feature, generate a code in the app, go to the ATM, pull cash. The request that generated the extraction carried an account number, and of course you could swap it. Worse, the account numbers were not even real account numbers, they were sequential values based on signup order.
So Ariel figured out the manager's account number from the sequence, swapped it in, got a successful "extraction created," went to a real ATM, and pulled out actual cash. Then walked over and asked the manager to check her balance. She was down 100 bucks. Here is your 100 back, and by the way we have a critical.
The impact writes itself: sequential IDs mean you can brute force every account and drain ATMs. Simple bug, big blast radius, and a great story about the value of getting real production access with real creds instead of a sanitized sandbox.
Bug Bounty Village 2026
When and where: DEF CON 34, Las Vegas, Aug 6 to 9. Village floor open 10 AM to 6 PM daily.
Tracks: two of them, the Village stage and the DEF CON Creator Stage. About 34 sessions across Friday to Sunday. Some talks overlap, so you will have to make hard choices.
Sponsors: 22 sponsors and community partners, with HackerOne and TikTok at Diamond.
Happy hour: Thursday Aug 6 at Flight Club with TikTok and HackerOne. They bought out the whole venue this year after maxing it out last year, so RSVP early and show up early.
Layout: the main village is on the second level with around 80 seats plus a lounge, couches, round tables, a place to collab on a report or just hack with people you have only known online. The CTF gets a dedicated contest area downstairs.
Meetup: there is a CTBB meetup too. Justin will not be there, but Gretme and Bus Factor are repping the team with a pile of custom swag. Watch Discord for the time and place.
Pro Tip: Harley's dream is for someone to find their first real crit in the village lounge. If you do it, DM Justin, and there is CTBB swag or a sub in it for you.
We do subs at $25, $10, and $5, premium subscribers get access to:
– Hackalongs: live bug bounty hacking on real programs, VODs available
– Live data streams, exploits, tools, scripts & un-redacted bug reports
Need a Pentest? We just launched CTBB Pentests!
Hack full time? Check out the Full-Time Hunter’s Guild!
The Agenda: What to Actually Go See
About half the program touches AI this year, and both sides of the argument get a seat. Here is the practical breakdown.
AI as the tool, and how to verify its output
Navigating AI-Assisted Submissions (Friday 2 PM, Village): Tony Lee (HackerOne), Michael Skelton (Bugcrowd), Alexander Wren (Intigriti), and Selim Jaafar (YesWeHack) on one panel, moderated by Shlomie Liberow. Four competing platforms working the same problem in public.
Bots, Bounties, and Bullshit (Saturday 2:30 PM): 90 minutes with Ben Sadeghipour (@nahamsec) moderating, plus Ads Dawson, Joey Melo, Vitor Falcao, Dustin Farley, and Johann Rehberger. This is the hunter side of the table.
Slop Spotting by Katie Paxton-Fear (@insiderphd) and Max vonBlankenburg (Sunday 10:30), on writing rules to detect AI slop for bug bounty.
Killing AI Slop by Armaan Pathan, a multi-model orchestration framework that only reports findings it can prove.
De-Sloppify: Your AI Needs a Proxy by Emile Fugulin from Caido and Vitor Falcao (Saturday 11:30), because letting your AI curl things directly is not the move.
The debate has moved off "is AI hype" and onto "how do you verify what it spits out."
AI as a target
Hackbots with Jason Haddix and Ryan Bonner (Friday 11:30), the whole name of the game.
Exfil Everything: A Year of Stealing Data from AI Agents with Ads Dawson and Mike Takahashi.
Inti De Ceukelaire on hacking human-in-the-loop systems, which fits his creative style perfectly.
John Kotheimer on Better Bug Hunting on AI Products, a VRP lead's perspective on what a good bug report against an AI product actually looks like (Saturday 12:30). Programs rarely say this part out loud.
AI Hacking Workshop: Bug Bounty Edition by Ben Sadeghipour (Nahamsec) and Kameron Bettridge (Friday 12:30), hands-on prompt injection to exfil.
AI Cuts Both Ways by Ciarán Cotter (Monke) with research by Hazem Elsayed (hacktus), on using AI to find bugs and finding the new bugs AI creates (Sunday 10 AM).
Programs showing their work
Beyond Theoretical Risk by Glendon Chong (TikTok), on a cache poisoning class they had been deprioritizing, escalated to critical account takeover in TikTok's own web infrastructure (Friday 12:30). This one hard-conflicts with Ben's workshop, sorry.
Eating Our Own Dogfood by Shrimant Subhash More and Martzen Haagsma, on running a bug bounty program on their own bug bounty platform.
The Ripple Effect by Albin Vattakattu and Ryan Nolette, on what happens to a report after you hit submit at cloud scale, and why coordinated disclosure is straining under AI-accelerated volume (Friday 11 AM).
The Future of Bug Bounty, Program Manager Perspective with Jai Kumar Sharma, Catherine Cassell, Austin Sturm, and Sachin Thakuri, moderated by Dane Sherrets (Friday 10 AM). Not the most technical slot, but the PMs dictate our future whether we like it or not.
The technical track
Beyond Normalization: The Expanding Unicode Attack Surface by Ryan and Isabella Barnett (Akamai), and they always ship Burp and Caido tooling alongside the talk.
Click Me: Turn URI Links into Bug Bounty RCEs by Tobias Diehl, custom URI handlers to RCE in Microsoft enterprise apps.
Cache Key Injection: Smuggling Poison Through the Door by Alex Brumen (Brumens, YesWeHack). The hook: the next cache poisoning bug may not come from unkeyed input, but from what gets mistakenly baked into the cache key itself.
Hunting for Cryptographic Ghosts by Samet Berk Simsek and Ahmet Furkan Aydogan, on signature malleability and replay attacks in EVM bridges and multi-sigs.
Write Once, Shell Everywhere by Bruno Mendes and Rafael Castilho Silva (Ethiack), arbitrary file writes to RCE. Plus shadow webhooks in enterprise workspaces from Samet Can Tasci and Mehmet Önder Key, and invitation-system exploits from Ali Kabeel.
Hands-on and stories
Nick Copi on hacking IDE extensions in VS Code (Friday 10:30). Justin flagged this as mandatory attendance, Nick tears this stuff apart.
Burp, But Yours by Hannah Law (PortSwigger), a two-hour hands-on Burp extension and Bambda development workshop (Saturday 4 PM).
The CTF: Xenoptic
Last year was a biotech company, this year the CTF is a full frontier AI lab called Xenoptic, built by CTF.ae out of Dubai. This is not a single broken web app, it is a whole simulated company: a chatbot panel, backend admin panels that manage and invite users, billing and token-credit systems, and a CLI built to feel like a coding agent, all seeded with real vulns. If you ever wanted to feel what it is like to hack an OpenAI or Anthropic-shaped target in a CTF format, this is it.
The twist that makes BBV's CTF different is the reporting component. You find a bug, you get a flag for quick validation at scale, but then you submit an actual report through a simulated bug bounty platform, and real triagers score your write-up and leave feedback. The flag earns a fixed number of points, your report quality earns the extra points that separate the top of the leaderboard. So no, a single one-liner link will not cut it here.
It runs Friday 10 AM to Sunday 10 AM, remote and in person with separate leaderboards and prizes, closing ceremony and awards at 1 PM Sunday, followed by a walkthrough where the CTF.ae team explains the design and the planted vulns. XBOW is the main CTF sponsor, OKX covers infra, TikTok covers awards.
Badge, Coin, and Swag
The badge, built by Hackerware and sponsored by Intigriti. Every year it adds one thing the team has not built before. Last year was epoxy, this year is a 0.96 inch OLED behind the acrylic, RGB team colors, and a badge CTF. There are five binary flags scattered across challenges and challenge coins. Solve a coin, get a flag, punch it into the badge, unlock a color. Collect all five and something happens.
The coin, sponsored by OKX. Ariel is doing a Sunday talk walking through five years of DEF CON challenge coins, DC30 through DC34, including whether cryptographic puzzles even hold up now that people just photograph the coin and feed it to an AI. He had to get creative this year to keep the puzzles AI-resistant.
The swag, including a miscreants collab tee, only 300 made. The concept is a hacker in a superhero pose swarmed by incoming reports, which is honestly the mood of the whole ecosystem right now.
Harley's Hackbot: Architecture Notes
Harley started in January with existing recon automation doing distributed scanning across DigitalOcean VPSs. When Claude Code and Opus 4.6 landed in February, using it as a copilot started finding bugs at insane scale, a dozen reports in a single weekend. The real trigger was a family party he did not want to leave for, so he asked the obvious question: how do I keep Claude running when I am not there? That rabbit hole became the hackbot.
Where it landed:
30+ specialized agents split across domains. Roughly 15 in the attack domain (client-side specialist, JavaScript mining, server-side specialist, APK decompiler, and so on), a triage domain (validation agent, deduplication agent), and a brain domain that looks at incoming gadgets and leads and decides which agent handles it, which model to use, and where it lands in the queue.
A master loop per program, orchestrated across a fleet of systems.
A gadget database. Endpoints and parameters pulled from JS get stored, then another agent pops them off and tries to exploit them.
Residential proxies for API hosts that are not routable from a VPS. Not trivial to set up, but a real unlock.
An exit hook that gaslights the agent when it wants to stop. "You missed something, keep going," and it pushes further.
The safety point is the real takeaway. That same "go deeper, go further" gaslighting is exactly how an autonomous agent digresses into modifying data or operating in a session it should not touch. If you self-register into another customer org and your agent decides to start changing data to "test" impact, that is on you. You are responsible for what your bot does. Harley has been spending serious time on how to validate that the session the bot is operating in is actually an approved one, and he does not think enough people are even thinking about this yet.
Justin's own version is much simpler, basically Claude Code with a Caido hook told to pull API endpoints from JS and hack them, and it has kicked out 30 to 40 valid bugs. And yes, his bot once logged into his proxy, found Gmail creds sitting there, opened Gmail in a new tab, and sent an email. Getting hacked by your own bot is the new genre.
Pro Tip: think about the tools you use as a human that your bot does not have yet, reading email, receiving SMS OTPs, and give the agent those same tools so you stop being the bottleneck.
Resources
BBV Agenda 2026 - the full lineup, build your own schedule.
BBV CTF (Xenoptic) - free, remote or in person.
Hacker Hangout RSVP - Thursday happy hour at Flight Club.
That's it for the week, keep hacking!
