ExpressVPN, a leading consumer privacy and security company, is offering US$100,000 via Bugcrowd’s Bug Bounty solution to researchers who can find and demonstrate a critical security bug on ExpressVPN’s in-house technology, TrustedServer.

It is the highest single bounty offered on the Bugcrowd platform and 10 times higher than the top reward previously offered by ExpressVPN.
ExpressVPN is inviting Bugcrowd security researchers to test the following types of security issues within its VPN servers:
# unauthorized access to a VPN server or remote code execution
# vulnerabilities in ExpressVPN’s VPN server that result in leaking the real IP addresses of clients or the ability to monitor user traffic
“ExpressVPN’s partnership with Bugcrowd since 2020 demonstrates its commitment to a strong security posture and a constant drive to improve the security of its products and services,” Nick McKenzie, Chief Information & Security Officer, Bugcrowd, said.
ExpressVPN engineers have built TrustedServer technology to significantly minimize problems that traditional server management pose. Independent audit by PwC confirmed TrustedServer’s security-enhancing claims.
“TrustedServer is the world’s first and most advanced VPN server technology, and we want to work with the community to elevate it further,” said Shaun Smith, Software Engineering Fellow at ExpressVPN and the architect behind TrustedServer.

