Reminds me of this hilarious bug bounty:
1. Person reports some vuln in HackerOne itself to HackerOne
2. A HackerOne employee tries to reproduce it, and unknowlingly copies and pastes his/her cookies into the HackerOne report
3. The reporter takes those cookies, and logs in as the HackerOne employee
4. The reporter files a new vuln report "You are disclose for me you session. you are gevi me your session on last report. I am can use your session(sorry)"
5. $20,000 bounty