Hola Security Vulnerabilities Reward Program

Hola is committed to protecting the privacy and security of our users. We welcome responsible vulnerability reports and appreciate the efforts of those who help us identify and fix security vulnerabilities.

Submit a vulnerability
hero_bounty

Program Scope

This program applies to previously unknown security and privacy vulnerabilities affecting Hola-owned products and services, including:

  • homeHola website: hola.org or its mirrors
  • userUser accounts and subscription flows
  • puzzelHola browser extensions
  • devicesHola desktop applications
  • mobileHola mobile applications
  • browserHola Browser
  • settingsHola-owned APIs and backend services used by Hola products

*Only the latest publicly available versions of Hola products are considered in scope.

Rewards

Rewards are determined at Hola’s sole discretion based on severity, impact, exploitability, report quality, and whether the issue was previously known.

$50

  • Low-impact XSS
  • Low-risk CSRF
  • Minor security misconfiguration with limited impact
  • Valid security issue with limited exploitability

Up to$100

  • Stored or reflected XSS with meaningful user impact
  • CSRF enabling sensitive account actions
  • Authorization issue with limited account impact
  • Exposure of non-sensitive internal information
  • Security misconfiguration on production systems with practical impact

Up to$200

  • Account takeover risk
  • Access control flaw revealing personal info
  • Unauthorized access to user accounts
  • Sensitive data leak from production systems
  • Remote Code Execution in Hola app
  • Major privacy vulnerability
  • Remote Code Execution on Hola server
  • Critical authentication bypass in production
  • Vulnerability exposing sensitive data broadly
  • Severe vulnerability impacting many Hola users

*Hola may decide to pay higher rewards for unusually severe vulnerabilities or lower rewards for issues with limited likelihood, limited impact, or incomplete proof of concept.

*Duplicate reports are not eligible for a reward. The first report that clearly demonstrates a valid vulnerability will be considered the original report.

*Any reward that remains unclaimed for more than two months may be canceled.

Qualifying Vulnerabilities

Any design or implementation issue that affects the confidentiality, integrity, or availability of Hola user data, user accounts, or Hola-owned production systems may qualify.

Out of Scope

There are several important issues that do not qualify for a bounty. These include specific cases that fall outside the established guidelines and criteria set forth by our bounty program.

All participants must make a good-faith effort to avoid privacy violations, data destruction, service disruption, or degradation of Hola services. Failure to do so may result in disqualification from the program.

Submit a vulnerability

Reporting Bugs

Reports should be submitted in English and include the following sections:

Please provide clear reproduction steps, including the test account used if applicable, the URLs, endpoints, or parameters involved, and any screenshots, videos, logs, or examples of requests and responses. Also, include any necessary configuration or environment details.

Safe Harbor

We support responsible security research conducted in good faith. If you comply with this policy, we will not initiate legal action against you for your research. To remain eligible, you must:

  • Test only systems that are in scope
  • Use only your own accounts and test data
  • Avoid accessing, changing, deleting, or copying data that does not belong to you

Disclosure Guidelines

Please do not publicly disclose the vulnerability until Hola has completed its investigation and remediation.

We aim to:

  • Acknowledge valid reports within a reasonable timeframe
  • Investigate and reproduce reported issues
  • Keep researchers updated where appropriate

Bounty Payments

Bounty payments are subject to the following restrictions:

  • Payments are made in US dollars, USD.
  • Payments must comply with applicable local laws, regulations, and sanctions rules.
  • You are responsible for any tax consequences resulting from bounty payments.
  • If you are employed, it is your responsibility to comply with your employer’s policies regarding participation in bug bounty programs.
  • Minors may participate, but if you are under the legal age required to receive payment in your jurisdiction, payment may need to be claimed by a parent or legal guardian.
  • Hola may request identity, tax, or payment information before issuing a reward.

Thank You!

We appreciate the security research community’s help in keeping Hola safe. Responsible disclosure helps us protect our users, improve our products, and maintain trust.

Submit a vulnerability