Critical Thinking - Bug Bounty Podcast · Justin Gardner (Rhynorater), Joseph Thacker (Rez0), & Brandyn Murtagh (gr3pme)

Episode 167: Stealing Bugs with Valeriy Shevchenko

March 26, 2026·52 min·1 clip
I discovered the credentials were legit and it was like okay they weren't expired yet they wasn't rotated even.
Episode 167 features a conversation between Jason and Valeriy Shevchenko, a highly-ranked HackerOne bug bounty hunter (98th percentile impact). The episode opens with This Week in Bug Bounty segment discussing HackerOne's maturity framework. Valeriy then details two sophisticated vulnerability discoveries: first, a Node.js path traversal leading to exposed AWS credentials that remained valid even after the server shut down, yielding a $10-12K bounty; second, a WordPress credential exposure across multiple domains via third-party integration, demonstrating scope complexity in microservices architectures. Key themes include meticulous documentation, screenshot evidence, understanding company acquisition timelines, and thoughtful restraint before escalating attacks. Valeriy emphasizes treating scope ambiguity carefully while documenting findings thoroughly to prove legitimacy.

As heard by us

A grounded bug bounty conversation about preparation, speed, and knowing when to step away.

This episode frames bug bounty success as something less glamorous, and more useful, than a sudden flash of technical genius. It starts with a sharp joke about stolen reports and borrowed credit, then settles into the practical rhythm behind faster, cleaner submissions: prepare…

Read the full review in PlayNext →

Why you'd press play

Press play for a bug bounty conversation about draft reports, speed, and doing the homework early so future-you gets a little more sofa time.

Read the full recommendation in PlayNext →
Listen to the show on