Root cause
Account-conversion logic did not preserve the distinction between identity linkage and authorization to collaborate on a merchant’s store. The vendor attributes the issue to automatic conversion of ordinary accounts into collaborator accounts.
Demonstrated impact
The vendor confirms unintended store access without merchant interaction in a partner-account context, and says it fixed the issue within hours. Its retrospective does not establish data extraction, the exact permissions obtained or the researcher’s discovery process.
Lessons for review
- Editorial lesson: require an independently verified entitlement for each role transition; matching identity attributes do not prove resource access rights.
- Editorial lesson: preserve merchant approval when accounts are linked, merged or automatically converted.
- Editorial lesson: model authorization before and after lifecycle transitions, including repeated or conflicting identities, using approved test accounts.
Award and evidence
One report, separate from event totals. USD is a contextual inference from HackerOne’s 2026 platform policy, nine years after the 2017 award; that policy does not prove settlement.
Read public primary-source text and checked award scope, provenance and dates. No target testing.
- The underlying linked HackerOne report was JavaScript-only in text retrieval and was not independently reviewed.
- Currency context is platform-wide and later than the award; no independent payment audit is claimed.
- No exact reporting, fix or payment date was established.
Recorded timeline
- Published
- 2018-02-22explicit
- Awarded
- 2017explicit · The vendor identifies the award as occurring during 2017; no precise day is supplied.
Sources and provenance
- 2017 Bug Bounty Year in Review Peter Yaworski / Shopify · reviewed 2026-10-03
- Vulnerability Disclosure Standards HackerOne · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.