Youssef Sammouda (sam0)
@samm0uda
Followers
38K
Following
4K
Media
22
Statuses
1K
Hacker, bug bounty hunter, guy behind https://t.co/TBAtP71Cop. 1st in Meta bug bounty program for the last 6 years. YES Team Member
Yes™
Joined October 2016
Multiple bugs chained to takeover Facebook Accounts which uses Gmail. ( $42k ) https://t.co/tdXO3u5ddA
59
476
2K
Due to the repeated screw-ups and zero transparency around bans by @Hacker0x01, I’ve chosen to leave with dignity. My account is now fully deactivated and to be removed. If you need my services, I’m still available at @Bugcrowd @intigriti @immunefi @HackenProof @StandoffBB
I’ve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. I’ve earned around $500k in bounties and was on the road to $1M. Yet I don’t even have HSM, and I feel I haven’t been recognized as I should 1/4
12
34
502
I’ve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. I’ve earned around $500k in bounties and was on the road to $1M. Yet I don’t even have HSM, and I feel I haven’t been recognized as I should 1/4
@Hacker0x01 is now banning people without explanation or providing how the terms and conditions were violated. While other platforms are advancing, H1 revolutionary new vision is to track hackers on social media, make assumptions and ban them without a real proof.
40
130
796
After that, it’s up to you. PS: Don’t fool yourself, you're just the middleman in this game. You're not doing anything special. Without the honest, talented hackers that companies came looking for, you'd be nothing but a spam folder clogged up by bunch of AIs and script kiddies.
0
5
202
What you're doing is just childish. My friend who was banned is one of the best hackers and persons i known. What we're asking for is for you to first remember who made you, then to have the courtesy and professionalism to explain your reasons and give him a chance to explain.
1
2
164
it's your platform and hell you can do whatever, but failing to provide a reason and saying "no other communications on this matter can be provided" means what ? we should trust your "wisdom", that you don't make mistakes and we can't even have a case to defend or justify?
1
1
151
It’s disappointing to see what Meta(Facebook) bug bounty program has turned into. It feels like an endless cycle of waiting, the interactions have become frustrating, almost like it's a new program.I’ve decided to step away for good, don’t expect to see my name in the top anymore
24
14
328
Great and simple tool to follow vulns, you can see trends and also find social media posts related to one CVE, making it easier to gather additional information about the vulnerability or find PoCs.
1/4 dbugs LIVE https://t.co/Cd6L8AD6Bt — vulnerabilities’ home See trends, discover more, read AI summaries, have all references at hand, and your profile with all your CVEs and CVSS score on a leaderboard. ⬇️ See thread: what’s live + what’s next ⬇️
2
13
129
Hacking Windsurf: I asked the AI for the shell, it said yes. new video’s out. I show how I could’ve hacked you… just by getting you to click my link. Link posted below.
19
77
411
I believe we shouldn't categorize a company security and safety as our own success and achievement in life, it's actually theirs, and they actually paid for it. If you're working with them, it's another thing since you're part of it, you believe in it, but as an outsider not sure
1
2
79
I think bug bounty is great as a start point, to gain skills and make money, however your future should be on how to use the acquired skills and money to actually make a difference in the world or your life.
4
5
108
Alhamdulillah, $250,000 in total with bonuses for this bug, another record broken. Many thanks to @Meta and the Yes Team @phwd_ @JosipFranjkovic @vulnano , crazy we're still doing it after all these years.
179
116
2K
0
19
106
I got $66000 once for an XSS. The impact to the business and its users is the important thing in a report and not the bug itself.
16
27
539
To all triagers out there, stop trying to reproduce client-side pocs from a local html file.
3
3
92
Yay, I was awarded a $30,000 bounty on @Hacker0x01 ! https://t.co/5UdNTQkdhX
#TogetherWeHitHarder Should have been another $50,000, however no consistently in payouts, going back to Meta.
21
15
451
Hyped! On the 28th of September i will be hosting the annual Truesec Cybersecurity Summit & present the talk I performed at Blackhat, Defcon and soon Sec-t! Get your tickets at: https://t.co/mUol5egQ1I
2
11
100