AI-assisted bug bounty research
Use Hackcat to organize authorized bug bounty research, inspect Web and API behavior, and prepare findings with evidence you can verify.
Read the guideExplore practical Hackcat workflows for authorized bug bounty research, Web and API testing, and smart contract security review.
Start with the question you need to answer and the assets you are allowed to test. These guides show where Ask mode helps you reason about a problem and where Agent mode can execute checks, collect evidence, and prepare a report.
Use Hackcat to organize authorized bug bounty research, inspect Web and API behavior, and prepare findings with evidence you can verify.
Read the guidePlan authorized Web and API security checks with Hackcat, compare access-control behavior, and collect reproducible evidence for fixes.
Read the guideUse Hackcat to review smart contract code, design local security tests, and examine evidence from authorized forks and test networks.
Read the guideShare the authorized scope, exclusions, permitted request rates, and expected behavior. Provide only the files and test accounts needed for the task. A specific goal makes it easier to choose relevant tools and interpret their results.
Ask mode is useful for reviewing code, documentation, or observations. Agent mode adds terminal and browser execution in a supported cloud or connected local environment. The Agent should inspect a selected tool's actual availability and documentation before using it; a catalog entry alone does not prove the tool is installed or functional.
Check preconditions, reproduction steps, outputs, and the claimed impact. Separate confirmed findings from hypotheses. Export a report where available and reproduce important results independently. A clean scan or an AI explanation cannot guarantee that a system is secure.