does hackerone cover social engineering exploits? I doubt it.
The following issues are outside the scope of our vulnerability rewards program (either ineligible or false positives):
...
- Social engineering of Twitter staff or contractors
...
https://hackerone.com/twitterPretty standard for most if not all of the program rules I have come across.
In theory, any sensitive operation (such as changing the email address of a verified account) could be made to require approval from a second (randomly chosen) employee, and that second employee should see a log of recent actions taken by the first employee. An attacker may still manage to avoid raising suspicion for the first few targets, though.
That's never going to fly; all Twitter bounties are multiples of $140.