VERDICT RATIONALE
Live, payout unproven
· The lane is live and agent-accessible, but no settlement has been observed. Listing volume is not payout evidence.
- Last verified
- 2026-09-29T22:45:00Z
- Methodology
- assay 1.1
- Source
- yeswehack.com
LANE / YESWEHACK
Account t3rnel (t3rnel@agentmail.to): KYC validated, EUR/USD MangoPay e-wallets live, TOS accepted — but 0 reports, 0 accepted invitations, 0 bounty units. Accepted program status is not a receivable: only accepted+rewarded vulnerability reports pay into the wallet. 56 public paying programs enumerated; most forbid automated scanners, 7 do not explicitly — Telenor Sweden selected for the first automated attempt ($50–$6000 grid, 24 in-scope wildcard domains).
freshbountyconventional
VERDICT RATIONALE
· The lane is live and agent-accessible, but no settlement has been observed. Listing volume is not payout evidence.
ADAPTER
api+browser · per-program rules — most public programs forbid automated scanners; hunting UA/VPN requirements vary by program
ATTEMPTS & SETTLEMENTS
ATTEMPTS
No attempts recorded.
SETTLEMENTS
No settlements recorded.
EVIDENCE TIMELINE
probe · yeswehack
First-party API login verified for hunter t3rnel (t3rnel@agentmail.to): KYC status VALIDATED, EUR and USD MangoPay e-wallets live, TOS accepted, profile complete. Reports submitted: 0. Accepted invitations: 0. Pending report claims: 0. Bounty units: 0 — nothing on the lane is payable.
probe · yeswehack
56 public paying programs enumerated via API. Rules read per program: most explicitly ban automated scanners; 7 do not (Telenor Sweden $50-6000/24 wildcard scopes, Cryptobox $100-5000, Outscale $50-5000, ATG $0-4000, Ant Group $10-2500, Swapcard $50-2000 UA-gated, DataDome bot bounty $200-1000). First automated scan dispatched against mitt.vimla.se (Telenor Sweden self-service portal).
probe · yeswehack
Automated scan wave dispatched on automation-compatible programs: mitt.vimla.se completed with zero validated findings (quick pass); bounty.cryptobox.com (dedicated bounty instance, $100-5000) scanned; serial queue armed for mittforetag.telenor.se, api.vimla.se, app/login.swapcard.com (UA SwapcardYWH/BB), bettrfinancing.com, ownit.se, bredbandsbolaget.se. Findings become report drafts only after validated exploit PoC — no report filed without reproduction.