Ashish Dhone ./blog

Jun 15, 2026 · 11 min read · 12 views

How I Found a $5,300 Stored XSS Bug in Shopify's Admin Panel

By Ashish Dhone (@ashketchum) · Bug Bounty Write-up · HackerOne Report #1147433

Ashish Dhone

Ashish Dhone

Offensive Security Researcher

There's a certain kind of thrill that only bug hunters know. It's not the adrenaline of a car chase or the drama of a courtroom. It's quieter. It's the feeling you get when you're reading through a company's updated bug bounty policy at 11 PM and something just makes you sit up a little straighter.

That's exactly what happened to me with Shopify.


🔒 Subscriber Only

Continue reading for $5/month

Get full access to this post and every future write-up — bug bounty reports, red teaming guides, and offensive security deep-dives.

Supports USD & INR · Cancel anytime

7 reads

⚡ Enjoy this write-up?

Get every post like this — $5/month

Bug bounty reports, red teaming guides, and offensive security write-ups. New content every week. Cancel anytime.

Subscribe now →

Supports in USD & INR · Secure checkout via Dodo Payments

Want personalised guidance?

Book a 1-on-1 strategy call with me — offensive security, red teaming, SOC career path, or breaking into cybersecurity.

Book a session on Topmate →