> When we submitted this to HackerOne, they responded that this is an “out-of-scope” issue since it requires stolen PayPal accounts. As such, they closed the issue as Not Applicable, costing us 5 reputation points in the process.
But Paypal's policy really couldn't be clearer:
> Out-of-Scope Vulnerabilities
> Vulnerabilities involving stolen credentials or physical access to a device
( https://hackerone.com/paypal )
If Paypal says "don't send us this type of report", and you send one anyway, are you really surprised when your account gets a warning attached saying "this person usually files low-value reports"?