👤 Human-Only Submissions
If you made the report with GPT/LLM/Agents - don’t send it.
GPT-generated crap will not be reviewed.
Give the human steps to follow, assuming we have WAHA installation already, just plain curl or commands
💵 Bug Bounty – $2,100 if You Can Bypass WAHA API Key Validation
Hi 👋
We're offering 2,100 USDT to anyone who can bypass the WAHA_API_KEY check on the WAHA HTTP API and:
- Send a WhatsApp message
- Or fetch the session list
Conditions:
- Installed using the guide https://waha.devlike.pro/docs/how-to/install/
WAHA_API_KEY is a SHA-512 hash of a random UUIDv4
- HTTPS connection (so you can not inspect the traffic)
devlikeapro/waha image is enough, no WAHA Plus required
- No knowledge of the api key should be assumed
How to submit:
Email your exploit privately to waha@devlike.pro with steps, payloads, and evidence.
Notes:
- First valid report wins (if reports about the same exploit)
- No known or theoretical issues – must be reproducible
- Related source code you can find in /src/core/auth folder!
Thanks for helping secure WAHA! 🙏

👤 Human-Only Submissions
If you made the report with GPT/LLM/Agents - don’t send it.
GPT-generated crap will not be reviewed.
Give the human steps to follow, assuming we have WAHA installation already, just plain curl or commands
💵 Bug Bounty – $2,100 if You Can Bypass WAHA API Key Validation
Hi 👋
We're offering 2,100 USDT to anyone who can bypass the
WAHA_API_KEYcheck on the WAHA HTTP API and:Conditions:
WAHA_API_KEYis a SHA-512 hash of a random UUIDv4devlikeapro/wahaimage is enough, no WAHA Plus requiredHow to submit:
Email your exploit privately to waha@devlike.pro with steps, payloads, and evidence.
Notes:
Thanks for helping secure WAHA! 🙏