• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechChanging Face of Security

Twitter Paid a Hacker $10,000 For Filching Vine’s Source Code

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
July 25, 2016, 7:55 PM ET
FRANCE-WEATHER-VINEYARD-RAINBOW-FEATURE
A picture taken in Vertou, western France, on June 17, 2016, shows a rainbow over a vineyard. / AFP / LOIC VENANCE (Photo credit should read LOIC VENANCE/AFP/Getty Images)Loic Venance—AFP via Getty Images

Avinash Singh, an Indian computer security researcher, stumbled across a prized possession earlier this year: the entire source code for Twitter’s short-form video service, Vine.

Singh, who goes by the nickname “avicoder,” uncovered a security hole that allowed him to easily access the cache of code online. In March, he reported the issue to Twitter (TWTR), which has owned the six-second video service since 2012. Soon after the company fixed the problem and awarded him $10,080 through a partner, bug bounty startup HackerOne.

(Twitter pays bug bounty rewards in amounts that are divisible by $140, a nod to the 140-character limit imposed by the microblogging service on its flagship message board.)

Get Data Sheet, Fortune’s technology newsletter.

Singh discovered Vine’s valuable code after poking around online with Censys.io, a network-scanning search engine that helps hackers discover vulnerable Internet-connected devices. While doing some reconnaissance, he saw an address that caught his attention: https://docker.vineapp.com.

The subdomain in that URL refers to Docker, a fast-growing Silicon Valley startup that creates technology and data center tools that let developers more quickly spin up software applications and share data. The servers that Singh found hosting the data were unsecured (no passwords or two-factor authentication needed to log in). “If it is supposed to be private, then why is it publicly accessible?” Singh wondered during his probe, which he recently described in a blog post.

After a bit more digital prodding, he said he “was able to see the entire source code of vine, its API keys and third party keys and secrets.”

Not only that, but Singh was able to boot up a virtual replica of Vine on his machine—a scammer’s dream. “Just imagine how handy that would be to a phishing gang,” wrote Paul Ducklin, a computer security expert, on a blog sponsored by the cybersecurity firm Sophos. “No need to create home-made mockups of Vine’s service with fake login screens when you can run a pre-prepared visual clone that looks and feels like the real deal.”

For more on Twitter, watch:

Twitter, once alerted, swiftly took the server off the network. “We fixed this issue within five minutes of it being reported to Vine through Twitter’s Bug Bounty program,” a Vine spokesperson told Fortune in an email. “We also took precautionary steps like revoking and reissuing credentials to ensure that our systems remain safe.”

Singh swore on his blog that he would not release the source code, and there are no indications that it fell into anyone else’s hands.

Singh has reported nearly 20 bugs to Twitter since he started contributing as a so-called bounty hunter last year. He said he primarily focuses on Twitter since they fix problems and pay up quickly, though he has also submitted bugs to Coursera, OwnCloud, and Imgur for a total of 40 vulnerabilities reported through HackerOne to date.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

duke
Big TechAmazon
Amazon Prime Video reaches deal with Duke Blue Devils to air 3 games per season
By The Associated PressMay 1, 2026
11 minutes ago
valerie
CommentaryLayoffs
Tesla’s former HR chief: the AI layoff panic Is built on a false premise—here’s what most workers need to know
By Valerie Capers WorkmanMay 1, 2026
19 minutes ago
AI
AIdisruption
Meet the Americans dismissing AI hype and using it with ingenuity: ‘The efficiencies gained out of it have been tremendous’
By Cathy Bussewitz and The Associated PressMay 1, 2026
20 minutes ago
Tim Cook, chief executive officer of Apple Inc., inside the Steve Jobs Theater during an event at Apple Park campus in Cupertino, California, US.
AICFO Daily
Apple just posted $111 billion in revenue. Now its CFO and incoming CEO are teaming up
By Sheryl EstradaMay 1, 2026
30 minutes ago
Exclusive: Startup Fun raises $72 million for the serious business of converting crypto and cash
CryptoVenture Capital
Exclusive: Startup Fun raises $72 million for the serious business of converting crypto and cash
By Ben WeissMay 1, 2026
1 hour ago
The fruit fly cancer researcher who built his first prototype out of lollipop sticks and straws
NewslettersTerm Sheet
The fruit fly cancer researcher who built his first prototype out of lollipop sticks and straws
By Allie GarfinkleMay 1, 2026
2 hours ago

Most Popular

China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
North America
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
By Jake AngeloApril 30, 2026
19 hours ago
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
4 days ago
Accenture's Julie Sweet blew up 50 years of company history. She says the hardest part is still ahead
Conferences
Accenture's Julie Sweet blew up 50 years of company history. She says the hardest part is still ahead
By Nick LichtenbergApril 29, 2026
2 days ago
America shot its arsenal empty in 2 wars. Now it needs Beijing's permission to reload
Commentary
America shot its arsenal empty in 2 wars. Now it needs Beijing's permission to reload
By Steve H. Hanke and Jeffrey WengApril 30, 2026
20 hours ago
Google Cloud revenue is now 18% of Alphabet's business. Is this the beginning of the end of Google's search identity?
Big Tech
Google Cloud revenue is now 18% of Alphabet's business. Is this the beginning of the end of Google's search identity?
By Alexei OreskovicApril 29, 2026
2 days ago
Exclusive: America's largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth
Banking
Exclusive: America's largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth
By Nick LichtenbergApril 29, 2026
2 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.