Get the latest tech news

I hacked Monster Energy


Monster Energy's corporate infrastructure exposed: employee training, customer stereotypes, Beast Bux rewards, and a file system API that's STILL wide open.

Full access to Monster University, complete with all their training materials, including this absolute masterpiece about their target demographic: On a subdomain called Kermometer ( kermometer.monsterenergy.com), I discovered Monster had integrated ClickUp into their workflow, but they made a critical mistake: they exposed an admin's private account token directly in their website's JavaScript. They did fix the Monster University registration issue, but I don't think they even read my emails - they probably just noticed someone had signed up through their broken system and patched it.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of monster energy

monster energy