ZKB Bug Bounty Challenge

Put your skills to the test: Join the ZKB challenge from April 30 - May 10, 2024. Help secure Zürcher Kantonalbank's Federated Identity Management application. There's a total bounty pool of CHF 15'000 waiting to be claimed - valid critical findings will be rewarded with CHF 2'000.

Sign up by April 25!

GBF_Blog-ZKB-Online Challenge-EN.png.png

The Challenge

From April 30 to May 10, explore and secure ZKB’s Federated Identity Management tool. A total bounty pool of CHF 15'000 is up for grabs, with CHF 2'000 awarded for each valid critical finding. This is your chance to identify potential security flaws in a real-world application.

Leaderboard prizes

In addition to the bounties, there will also be prizes for the leaderboard:

  • 1st Place: Meta Quest 2 VR headset
  • 2nd Place: Samsung Galaxy Buds2 Pro
  • 3rd Place: WD My Passport (4 TB) external hard drive

How to Join

Registration: Register now on the GObugfree platform to secure your participation.

Account Setup: You’ll be required to provide three temporary email addresses and a mobile number for ZKB to set up your test accounts.

Briefing: On April 30, we will share details of the in-scope application and functionality.

Seize this opportunity to showcase your skills within the cybersecurity community and grab your slice of the bounty.

Happy hunting!

Sign up by April 25!