Sign in

BobDaHacker 🏳️‍⚧️ (she/her)

@bobdahacker.com
292 followers 27 following 27 posts

Can we hack it?? Yes we can!!! 😎😎😎 Hey Im BobDaHacker an ethical hacker 🤓 Thx 4 coming to my ted talk bobdahacker.com

PostsRepliesMedia
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 08/09/2026
Anyone based in Tokyo want to make some friends? :3 im 20TF, been here since last summer. very geeky, love cybersecurity, gaming, hiking, karaoke, cocktail mixing and crime docs etc. i have a dart machine and 400 BLÅHAJs in my apartment lol. always down to grab a drink or explore the city, DM me!
121
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 02/08/2026
Does anyone have a contact at warner bros? I found several very detrimental security issues there, and their hacker one team is unresponsive. Thanks
011
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 16/06/2026
⚽ I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. Registered on FIFA's public Agent Platform, accessed RTMP stream keys for every live World Cup 2026 camera feed. An attacker could've replaced live TV worldwide. bobdahacker.com/blog/fifa-hack #InfoSec #FIFA #WorldCup
bobdahacker.com
I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live ...
126528
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 27/12/2025
🐱 Found critical vulns in Petlibro smart pet feeders - $500 bounty -Auth bypass -hijack any device -Private audio recordings exposed They "fixed" it but left the old endpoint up for "legacy compatibility" bobdahacker.com/blog/petlibro #InfoSec #BugBounty #IoT #Security #Petlibro #CyberSecurity
bobdahacker.com
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks
How I found critical vulnerabilities in Petlibro smart pet feeders allowing complete account takeover via broken OAuth, access to anyone's pet data, device hijacking, and private audio recordings - an...
051
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 26/12/2025
🎵 Found a verification bypass in Bandsintown - fixed Used API endpoint to claim any unclaimed artist Got full access to Rick Astley's 191k followers Emails, names, push notifs Could have rickrolled 191k people. I did not. bobdahacker.com/blog/bandsin... #InfoSec #BugBounty #Security #CyberSecurity
bobdahacker.com
Bandsintown: How I Almost Rickrolled 191k People
How I found a verification bypass in Bandsintown that let anyone claim unclaimed artist pages with a single API call - including Rick Astley's 191k followers, their emails, and the ability to send pus...
010
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 26/12/2025
🔓 Found critical vulns in Taimi (LGBTQ+ dating app) - fixed, $10k bounty - "Expiring" videos didn't expire - Decrement ID = anyone's private videos Taimi handled this right. Fast fix, proper bounty. bobdahacker.com/blog/taimi-i... #InfoSec #BugBounty #IDOR #Taimi #Security #CyberSecurity
bobdahacker.com
Taimi: Finding Everyone's Private Photos Was Easy, But So Was Getting Paid
How I found critical IDOR vulnerabilities in Taimi that exposed
031
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 24/10/2025
rate my Subdomain on my Domain i.hate.you #CyberSecurity #InfoSec #domains #subdomain #programming #ProgramerHumour #Privacy
i.hate.you
i hate you
i hate you so much that i made this just for you ❤️
160
Reposted by BobDaHacker 🏳️‍⚧️ (she/her)
Chiitan🌈ちぃたん☆ @chiitan.love · 24/09/2025
Every day, I pray for a world where everyone is kind and respectful of each other, regardless of gender. May unreasonable attacks against transgender people end🏳️‍⚧️🏳️‍🌈 May today be filled with happiness and love for you all🤍
112106833007
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 29/08/2025
Hacked every BellaBot & Pudu robot globally. Ignored emails until I told their biggest customers. Fixed in 48hrs after that. Their response was ChatGPT with "[Your Email Address]" placeholder still in it 😭 Full story: bobdahacker.com/blog/hacked-... #robotics #security #cybersecurity #infosec
bobdahacker.com
I Hacked BellaBot and Every Robot from China's Biggest Robotics Company (Pudu Only Fixed It When I Told Their Clients)
Critical vulnerabilities in Pudu Robotics allowed unauthorized control of every Pudu Robotics Robot worldwide. They ignored emails until I contacted Skylark Holdings and Zensho about their compromised...
262
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 25/08/2025
finally caved and added an RSS feed to my blog after everyone kept begging me in DMs 😤 find it yourself at bobdahacker.com/blog now stop asking me about it lol #RSS #cybersecurity #blog #infosec #bugbounty #hacker
bobdahacker.com
Blog | BobDaHacker
Security research, vulnerability disclosures, and tech thoughts
030
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 19/08/2025
Hacked India's biggest dating app Flutrr (backed by Times of India). Every API endpoint is broken - I could read anyone's messages, swipe for them, change their profile. No auth checks anywhere. bobdahacker.com/blog/indias-... #cybersecurity #infosec #india #dating #vulnerability #bugbounty
bobdahacker.com
How I Hacked India's Biggest Dating App (They Offered Me a $100 Gift Card)
Flutrr, India's biggest dating app backed by The Times of India, has critical security flaws allowing anyone to access all user data, send messages as anyone, and control any account. They've known si...
131
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 18/08/2025
Hacked South Park's Casa Bonita. Could access their entire POS system and see all customer payments/tips. No security contact anywhere 😬 Fixed fast but never thanked me. Got a Founders Club card 6 months later though 😂 bobdahacker.com/blog/i-hacke... #SouthPark #infosec #hacking #cybersecurity
bobdahacker.com
When South Park's Restaurant Had Worse Security Than Cartman's Password
How I found critical security vulnerabilities in Matt Stone and Trey Parker's Casa Bonita restaurant, exposing customer data, payment info, and their entire POS system - plus how I accidentally got a ...
151
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 18/08/2025
Found huge security flaws in McDonalds: crew members could access corporate sites, API keys exposed. Had to call HQ pretending to know people to report it 🤦 They fixed it but fired my friend who helped bobdahacker.com/blog/mcdonal... #McDonalds #hacking #cybersecurity #infosec #bugbounty
bobdahacker.com
How I Hacked McDonald's (Their Security Contact Was Harder to Find Than Their Secret Sauce Recipe)
How I found critical security vulnerabilities in McDonald's systems affecting millions of employees, and had to cold-call their HQ pretending to know security staff just to report them.
3102
Reposted by BobDaHacker 🏳️‍⚧️ (she/her)
dismal whenever @dismalnow.bsky.social · 01/08/2025
@lovense-official.bsky.social Dan Liu's threat to pursue litigation against @bobdahacker.com is the most ignorant shit I've even seen in my years of #dlp and #cybersecurity. Plenty of proof of the #vuln, and the lack of response before public disclosure. www.documentcloud.org/documents/26...
documentcloud.org
Lovense Dan Liu response
111
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 30/07/2025
🚨 Lovense finally fixed their email leak after public pressure They said: 14 months Reality: 2 days after going viral 11M+ users at risk for YEARS. Read the full deception: bobdahacker.com/blog/lovense... #InfoSec #Privacy #CyberSecurity #BugBounty
bobdahacker.com
Lovense: The Company That Lies to Security Researchers
How Lovense has ignored the same critical vulnerabilities for 2+ years, lied about fixes, and manipulated bounty payouts while leaving 10s of millions of users exposed.
195
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 29/07/2025
PSA: Lovense products leak your email from just your username. Reported in March, still broken. Worse: Another Vulnerability was "fixed" in 2023 but wasn't. Company lied to researchers for 2+ years. Full breakdown: bobdahacker.com/blog/lovense... #cybersecurity #infosec #bugbounty #privacy
bobdahacker.com
Lovense: The Company That Lies to Security Researchers
How Lovense has ignored the same critical vulnerabilities for 2+ years, lied about fixes, and manipulated bounty payouts while leaving 10s of millions of users exposed.
39557