$600k in 6 months - BruteCat's Google Hacking Story (Ep. 178)

$600k in 6 months - BruteCat's Google Hacking Story (Ep. 178)

Source: YouTube · Critical Thinking - Bug Bounty Podcast · published Jun 11, 2026 · 1:23:56

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

BLUF: The speaker details a successful bug bounty effort involving hacking Google, which resulted in a payout of $670k within three to four months 0:05.

Key Takeaways:
• The initial title "hacking Google for 500k" was updated to reflect the actual final payout of $670k achieved in just a few months 0:05.
• The process was highly structured, involving a comprehensive review of all API key types and request variations 0:42.
• The researcher tested approximately 800 API keys, conducting end-to-end testing from top to bottom 0:52.
• The strategy utilized discovery docs and information leaked through previous bugs or gadgets to guide the testing 1:00.

This case highlights the significant financial rewards possible through systematic and thorough security research on major tech platforms.

Sources:

  • 0:05 Discussion of the blog post title and the actual $670k payout.
  • 0:42 Description of the structured approach to testing API keys and requests.
  • 0:52 Details on testing 800 API keys comprehensively.
  • 1:00 Explanation of using discovery docs and leaked info for testing.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

like in three months it got like okay 
so I wrote the title of this blog post is is hacking Google for 500k but 
it's actually 670k right now oh my god in basically three four months oh my 
gosh from just running this that's crazy best part of backing when you can 
just you know critical thing right Yeah, dude. I literally have done the exact same thing you did 
in this blog post and I did it for like 3 weeks and I had and it was extremely structured. It was 
like you know consider all the types of O consider all the types of requests consider all the types 
you know uh like all the different API keys we have you know like the 800 API keys we have like 
let's test everything comprehensively from end to from top to bottom with all the discovery docs 
that we've had access to or that we've l…