Skip to content
← All posts
4 min read

How we reported a critical login bug without publishing exploit details

Nobody hired us to look at this site. We looked anyway, found a critical bug in the only login it had, and chose to disclose it quietly instead of writing a how-to.

Nobody paid us to audit this site. We found a critical login bug anyway, and chose not to explain how.

An event site was paying to run Instagram ads. It had exactly one way in: a phone number, then a code by text. We were trying to buy a ticket, and everything else about the site felt rushed, so we tested that one step. It did not hold.

The habit that does not switch off

Nobody hired us. There was no invoice, no scope document, no permission email sitting in a thread somewhere. We were a customer at a checkout screen.

What we found was critical severity. Serious enough to affect every user on the site, sitting on the only door into the app, on a product actively buying traffic to send strangers through that door.

We are deliberately not describing what the bug was or what it would have let someone do. That detail is exactly what turns a private disclosure into a public how-to, and not handing it out was the whole point of disclosing privately. What we will say is that it was bad enough to send the same day rather than sit on.

Why we emailed instead of posting

The easy version of this story is a screenshot and a joke at a stranger's expense. We wrote two documents instead. One in plain language for whoever opens the inbox, one technical enough for the engineer who has to fix it, both sent straight to the company.

No public callout. No company name, here or anywhere else.

The point was never to prove we could find something. It was to make sure a stranger with worse intentions did not find it first.

What the audit habit costs to run

This is also, bluntly, the job. GattyWorks sells software audits: a senior engineer and designer pair reading a live product the way an attacker would, before an attacker does. Doing that repeatably, on products that are not ours, needs more than curiosity. It needs a way to work out who at a company will actually read the email, the same structured checks every time instead of poking around by hand, and a record so a second pass a month later does not start from zero. We have built our own tooling for that, and none of it is specific to this one company.

The reason that machinery is worth building is the size of the bill on the other side. The bug sat on the only login the app had. Leave it until a busy event and the cheap version of that day is a drained text-message budget. The expensive version is every paying customer locked out at once, support on fire, and people leaving for whoever is still up. Two days of senior attention on that one flow is a rounding error next to that.

The part we are not going to tell you

We do not know whether it is fixed. We sent both writeups, attached no deadline, and asked for nothing, which means the honest end of this story is an open question rather than a resolution. That is the trade you accept when you disclose quietly: you give up the leverage that would have made it move faster.

Next step, if the login, checkout, or signup flow is the only thing standing between your product and a bad week: a Surface Audit puts a senior pair on it in 48 hours. Email hello@gattyworks.com; every brief gets a reply within 24 hours.

EngineeringSecurityAuditsSoftwareAuditsResponsibleDisclosureAppSecWebSecurityCyberSecuritySecurityBugLoginSecuritySoftwareEngineeringGattyWorksBuildInPublic

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.
Book a call