He Sent 200,000 Reset Codes to Instagram in 10 Minutes. Instagram Paid Him $30,000.
1 min read
Summary
Member-only story
He Sent 200,000 Reset Codes to Instagram in 10 Minutes. Instagram Paid Him 30,000.Quicknote—Ibuilt[HackThrough].Itturnsrealbugbountywriteupsintointeractivestep−by−stepchallenges.Thisbugisonthere.Goplayitinsteadofjustreadingifthatsoundsinteresting.Mostdevelopersassumethatifyouputa6−digitOTPbehindaratelimiter,bruteforceisdead.Youhave1,000,000possiblecombinations.Thecodeexpiresin10minutes.Ifsomeonetypesthewrongcode5times,youlockthemoutforanhour.Problemsolved.That’sthetheory.Inpractice,concurrencyanddistributedinfrastructuremakeratelimitingoneofthehardestthingstogetrightatscale.In2019,securityresearcherLaxmanMuthiyahlookedatInstagram’spasswordresetendpointandfoundtwologicblindspots.Bychainingthemtogether,heprovedhecouldresetthepasswordonanyInstagramaccountinunder10minutesforabout150 in cloud compute.
Facebook acknowledged the critical severity and paid him $30,000.
Here’s the breakdown of how he did it, why the rate limiter broke, and what backend engineers keep getting wrong about OTP verification.