| Company | Asset | Asset Type | Coverage | Severity | Bounty | Create Date | Resolved |
|---|---|---|---|---|---|---|---|
| Vercel Platform Protection | Vercel Platform Protection | OtherAsset | In Scope | Critical | Eligible | 2025-12-05 | 0 |
| Basecamp | fizzy.do | Domain | In Scope | Critical | Eligible | 2025-12-03 | 3 |
| A.S. Watson Group | Look at Me PH (subdomains) | OtherAsset | In Scope | Critical | Eligible | 2025-11-24 | 0 |
| A.S. Watson Group | lookatme.com.ph | Domain | In Scope | Critical | Eligible | 2025-11-24 | 0 |
| A.S. Watson Group | Lookatme.Philippines.IOS | IosAppStore | In Scope | Critical | Eligible | 2025-11-24 | 0 |
| A.S. Watson Group | Lookatme.Philippines.Android | IosAppStore | In Scope | Critical | Eligible | 2025-11-24 | 0 |
| Circle BBP | https://github.com/circlefin/stablecoin-near | SmartContract | In Scope | Critical | Eligible | 2025-11-24 | 0 |
| Circle BBP | https://github.com/circlefin/evm-cpn-contracts | SmartContract | In Scope | Critical | Eligible | 2025-11-24 | 0 |
| Circle BBP | https://github.com/circlefin/starknet-cctp | SmartContract | In Scope | Critical | Eligible | 2025-11-24 | 0 |
| Circle BBP | https://github.com/circlefin/aptos-cctp | SourceCode | In Scope | Critical | Eligible | 2025-11-24 | 0 |
| Circle BBP | https://github.com/circlefin/evm-xreserve-contracts | SmartContract | In Scope | Critical | Eligible | 2025-11-24 | 0 |
| MetaMask | mUSD Stablecoin | OtherAsset | In Scope | Critical | Eligible | 2025-11-24 | 0 |
| Notion Labs, Inc. | Github Repositories or other public artifacts owned by makenotion | OtherAsset | In Scope | Critical | Eligible | 2025-11-24 | 0 |
| Superhuman (formerly Grammarly) | *.coda.io | Wildcard | In Scope | Critical | Eligible | 2025-11-21 | 0 |
| Superhuman (formerly Grammarly) | coda.io | Domain | In Scope | Critical | Eligible | 2025-11-21 | 0 |
| Superhuman (formerly Grammarly) | coda.grammarly.com | Domain | In Scope | Critical | Eligible | 2025-11-21 | 0 |
| Superhuman (formerly Grammarly) | *.superhuman.com | Wildcard | In Scope | Critical | Eligible | 2025-11-20 | 0 |
| Superhuman (formerly Grammarly) | id.superhuman.com | Domain | In Scope | Critical | Eligible | 2025-11-20 | 0 |
| Superhuman (formerly Grammarly) | gateway.superhuman.com | Domain | In Scope | Critical | Eligible | 2025-11-20 | 0 |
| Superhuman (formerly Grammarly) | codacontent.io | Domain | In Scope | Critical | Eligible | 2025-11-20 | 1 |
| Superhuman (formerly Grammarly) | codahosted.io | Domain | In Scope | Critical | Eligible | 2025-11-20 | 4 |
| Superhuman (formerly Grammarly) | io.coda.codaapp | AndroidPlayStore | In Scope | Critical | Eligible | 2025-11-20 | 3 |
| Superhuman (formerly Grammarly) | io.coda | IosAppStore | In Scope | Critical | Eligible | 2025-11-20 | 0 |
| Superhuman (formerly Grammarly) | Coda Chrome Extension | OtherAsset | In Scope | High | Eligible | 2025-11-20 | 0 |
| Superhuman (formerly Grammarly) | settings.superhuman.com | Domain | In Scope | Critical | Eligible | 2025-11-20 | 0 |
| Eternal | Data Protection Program | OtherAsset | In Scope | Critical | Eligible | 2025-11-19 | 0 |
| Spotify | https://www.whosampled.com/ | Url | In Scope | Critical | Eligible | 2025-11-19 | 0 |
| Ripio | sandbox-b2b.ripio.com | Domain | In Scope | Critical | Eligible | 2025-11-18 | 0 |
| Consensys | https://etherscan.io/address/0xaca92e438df0b2401ff60da7e4337b687a2435da | SmartContract | In Scope | Critical | Eligible | 2025-11-17 | 0 |
| Verily Life Sciences | https://*.verilyme.com/ | Wildcard | In Scope | Critical | Eligible | 2025-11-17 | 0 |
| TikTok | *.tiktokcdn.com | Wildcard | In Scope | Critical | Eligible | 2025-11-13 | 0 |
| TikTok | *.tiktokpublishers.com | Wildcard | In Scope | Critical | Eligible | 2025-11-13 | 0 |
| Superbet | *.happening.dev | Wildcard | In Scope | Critical | Eligible | 2025-11-12 | 0 |
| Superhuman (formerly Grammarly) | superhuman.com | Domain | In Scope | Critical | Eligible | 2025-11-12 | 0 |
| Mozilla | pontoon.allizom.org | Domain | In Scope | Critical | Eligible | 2025-11-11 | 3 |
| Faraday, Inc. | vault2.faraday.ai | Domain | In Scope | Critical | Eligible | 2025-11-07 | 0 |
| Faraday, Inc. | gs://faraday-secret | OtherAsset | In Scope | Critical | Eligible | 2025-11-07 | 0 |
| Faraday, Inc. | gs://fdy-production-sdk-uploads | OtherAsset | In Scope | Critical | Eligible | 2025-11-07 | 0 |
| Bybit Fintech Ltd | http://www.byreal.io | Url | In Scope | Critical | Eligible | 2025-11-06 | 0 |
| Bybit Fintech Ltd | http://www.bybit.com/en/alpha/overview/ | Url | In Scope | Critical | Eligible | 2025-11-06 | 0 |
| Bybit Fintech Ltd | http://www.bybit.com/trade/tradfi/ | Url | In Scope | Critical | Eligible | 2025-11-06 | 0 |
| Elastic | *.elastic.dev | Wildcard | In Scope | Critical | Eligible | 2025-11-06 | 1 |
| Elastic | Elastic Distributions of OpenTelemetry (EDOT) | Executable | In Scope | Critical | Eligible | 2025-11-06 | 0 |
| Elastic | Beats - Osquerybeat | Executable | In Scope | Critical | Eligible | 2025-11-06 | 0 |
| Valve | *.steamstatic.com | Wildcard | In Scope | Critical | Eligible | 2025-11-04 | 0 |
| Epic Games | dev.epicgames.com/* | Wildcard | In Scope | Critical | Eligible | 2025-10-30 | 4 |
| Epic Games | http://urc-auth-uefn.live.ucs.on.epicgames.com/ | Url | In Scope | Critical | Eligible | 2025-10-29 | 0 |
| Epic Games | http://nexus.live.ucs.on.epicgames.com/ | Url | In Scope | Critical | Eligible | 2025-10-29 | 0 |
| Epic Games | http://urc-uefn.live.ucs.on.epicgames.com | Url | In Scope | Critical | Eligible | 2025-10-29 | 0 |
| Ping Identity | https://console.ort-one-pingone.com/?env=361b34ef-2725-4fd9-af1b-a2b189df3d05 | Url | In Scope | Critical | Eligible | 2025-10-29 | 0 |