• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechChanging Face of Security

Twitter Paid a Hacker $10,000 For Filching Vine’s Source Code

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
July 25, 2016, 7:55 PM ET
FRANCE-WEATHER-VINEYARD-RAINBOW-FEATURE
A picture taken in Vertou, western France, on June 17, 2016, shows a rainbow over a vineyard. / AFP / LOIC VENANCE (Photo credit should read LOIC VENANCE/AFP/Getty Images)Loic Venance—AFP via Getty Images

Avinash Singh, an Indian computer security researcher, stumbled across a prized possession earlier this year: the entire source code for Twitter’s short-form video service, Vine.

Singh, who goes by the nickname “avicoder,” uncovered a security hole that allowed him to easily access the cache of code online. In March, he reported the issue to Twitter (TWTR), which has owned the six-second video service since 2012. Soon after the company fixed the problem and awarded him $10,080 through a partner, bug bounty startup HackerOne.

(Twitter pays bug bounty rewards in amounts that are divisible by $140, a nod to the 140-character limit imposed by the microblogging service on its flagship message board.)

Get Data Sheet, Fortune’s technology newsletter.

Singh discovered Vine’s valuable code after poking around online with Censys.io, a network-scanning search engine that helps hackers discover vulnerable Internet-connected devices. While doing some reconnaissance, he saw an address that caught his attention: https://docker.vineapp.com.

The subdomain in that URL refers to Docker, a fast-growing Silicon Valley startup that creates technology and data center tools that let developers more quickly spin up software applications and share data. The servers that Singh found hosting the data were unsecured (no passwords or two-factor authentication needed to log in). “If it is supposed to be private, then why is it publicly accessible?” Singh wondered during his probe, which he recently described in a blog post.

After a bit more digital prodding, he said he “was able to see the entire source code of vine, its API keys and third party keys and secrets.”

Not only that, but Singh was able to boot up a virtual replica of Vine on his machine—a scammer’s dream. “Just imagine how handy that would be to a phishing gang,” wrote Paul Ducklin, a computer security expert, on a blog sponsored by the cybersecurity firm Sophos. “No need to create home-made mockups of Vine’s service with fake login screens when you can run a pre-prepared visual clone that looks and feels like the real deal.”

For more on Twitter, watch:

Twitter, once alerted, swiftly took the server off the network. “We fixed this issue within five minutes of it being reported to Vine through Twitter’s Bug Bounty program,” a Vine spokesperson told Fortune in an email. “We also took precautionary steps like revoking and reissuing credentials to ensure that our systems remain safe.”

Singh swore on his blog that he would not release the source code, and there are no indications that it fell into anyone else’s hands.

Singh has reported nearly 20 bugs to Twitter since he started contributing as a so-called bounty hunter last year. He said he primarily focuses on Twitter since they fix problems and pay up quickly, though he has also submitted bugs to Coursera, OwnCloud, and Imgur for a total of 40 vulnerabilities reported through HackerOne to date.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Nima Ghamsari smiles
NewslettersTerm Sheet
Blend’s post-IPO reset: CEO Nima Ghamsari bets that AI can turn it all around
By Lily Mae LazarusApril 2, 2026
48 minutes ago
Photo: President Trump
Big TechMarkets
Trump hails ‘tremendous progress’ in Iran but all Wall Street heard was ‘back to escalation’
By Jim EdwardsApril 2, 2026
1 hour ago
Can Elon Musk take SpaceX IPO to infinity and beyond?
NewslettersFortune Tech
Can Elon Musk take SpaceX IPO to infinity and beyond?
By Alexei OreskovicApril 2, 2026
1 hour ago
Asia’s AI playbook gets a reality check as the Iran war sends energy prices higher and snarls supply chains
AsiaTech
Asia’s AI playbook gets a reality check as the Iran war sends energy prices higher and snarls supply chains
By Angelica AngApril 2, 2026
2 hours ago
The tax escape map: Billionaires are bolting for Florida from the West Coast and taking billions in tax revenue with them
Real EstateBillionaires
The tax escape map: Billionaires are bolting for Florida from the West Coast and taking billions in tax revenue with them
By Marco Quiroz-GutierrezApril 2, 2026
5 hours ago
A SpaceX Falcon 9 rocket is displayed outside a Space Exploration Technologies Corp. facility in Hawthorne, California.
Startups & VentureElon Musk
SpaceX has filed confidentially for IPO ahead of AI rivals
By Bailey Lipschultz, Edward Ludlow and BloombergApril 1, 2026
15 hours ago

Most Popular

Two-thirds of parents say their adult Gen Z kids still rely on them financially  for support—even though it's putting them under strain
Success
Two-thirds of parents say their adult Gen Z kids still rely on them financially  for support—even though it's putting them under strain
By Fortune EditorsMarch 31, 2026
2 days ago
Current price of gold as of April 1, 2026
Personal Finance
Current price of gold as of April 1, 2026
By Fortune EditorsApril 1, 2026
23 hours ago
Jerome Powell says the $39 trillion national debt is ‘not unsustainable,’ but warns the trajectory ‘will not end well’
Economy
Jerome Powell says the $39 trillion national debt is ‘not unsustainable,’ but warns the trajectory ‘will not end well’
By Fortune EditorsMarch 30, 2026
3 days ago
Current price of oil as of April 1, 2026
Personal Finance
Current price of oil as of April 1, 2026
By Fortune EditorsApril 1, 2026
24 hours ago
Gen Z fled San Francisco for Texas and Florida. Now they're turning 'welcomer cities' into the next big tech towns
Real Estate
Gen Z fled San Francisco for Texas and Florida. Now they're turning 'welcomer cities' into the next big tech towns
By Fortune EditorsApril 2, 2026
4 hours ago
A man used AI to call 3,000 Irish bartenders to track the cost of Guinness. Now pubs are lowering their prices to compete
AI
A man used AI to call 3,000 Irish bartenders to track the cost of Guinness. Now pubs are lowering their prices to compete
By Fortune EditorsMarch 30, 2026
3 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.