i independently found and responsibly reported two significant security bugs. one affected a major ai platform and the other sat in a major quick-commerce pricing api. the bounties were five figures and six figures respectively.
the targets and exploit details stay private. both reports reached the engineering teams, both issues were fixed, and both teams paid. their feelings about the timing were mixed.