Bypassing Bronze Partner Wallet Restriction to Accept Trips with Negative Balance
Medium
B
Bykea
Submitted None
Team Summary
Official summary from Bykea
@bugbountywithmarco discovered a business logic flaw that allowed Bronze-tier partners with negative wallet balances to bypass platform restrictions and accept trips. By chaining three backend endpoints `GET /v2/:city_id/bookings`, `PUT /api/v2/driver/update/location` (with any trip_id), and `POST /api/v2/offer/bid` a negative balance driver could reset their availability and successfully submit bids, enabling unauthorized access to trips despite wallet limitations.
Actions:
Reported by
bugbountywithmarco
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Business Logic Errors