# McDonald’s App Bug = Unlimited Free Food

Source: https://www.youtube.com/watch?v=uk1AjAwZuvU
Recap page: https://rapidrecap.app/video/uk1AjAwZuvU
Generated: 2025-08-21T17:33:56.034+00:00

---
## Quick Overview

A security researcher named Bob the Hacker discovered multiple critical vulnerabilities in McDonald's systems, including an unlimited points bug for free food, client-side password protection bypass for the Feelgood Design Hub, exposed API keys, insecure executive-level portal access, and coupon reuse bugs in the Cosmic spin-off, with McDonald's slow to respond to most issues.

**Key Points:**
- Bob the Hacker discovered an unlimited points bug in the McDonald's app, allowing users to spoof their points balance for free food, as the "server does not verify your points balance at all."
- The McDonald's Feelgood Design Hub, a confidential marketing platform, was initially protected only by client-side passwords, leading to easy unauthorized access.
- After a patch, a new vulnerability allowed creating accounts to access hidden functionality and retrieve an admin password "in plain text," revealing McDonald's "magic bell" API key.
- Bob gained access to corporate executive-level portals using "credentials of a mere crew member," enabling him to "search for any McDonald's employee globally, even up to the level of CEO, and hamburgle their personal details."
- McDonald's spin-off restaurant, Cosmic, had a bug that allowed reusing a "coupon only meant for new customers as many times as you want, giving you an unlimited number of free drinks."
- McDonald's removed its security.txt file, making it difficult for researchers to report vulnerabilities, though Bob eventually contacted the company and most issues were fixed.

**Context:** This analysis focuses on security vulnerabilities discovered within McDonald's digital systems by a researcher known as "Bob the Hacker." The transcript details a series of critical flaws that allowed for unauthorized access to sensitive platforms, manipulation of loyalty points for free food, and exposure of internal data, highlighting significant security oversights by the fast-food giant. Additionally, it briefly touches upon a separate cyber incident involving the compromise of a North Korean hacker's computer.

## Detailed Analysis

Security researcher Bob the Hacker uncovered a series of severe vulnerabilities within McDonald's digital infrastructure. Initially, he found a bug in the McDonald's app where client-side validation allowed users to spoof their points balance, enabling unlimited free food redemptions without the server verifying the actual points. McDonald's initially dismissed this until the potential for "gold card holder" privileges was mentioned, after which it was patched within days. Bob then discovered the McDonald's Feelgood Design Hub, a confidential marketing platform, was protected only by client-side passwords, allowing easy unauthorized access. Although fixed after three months, a subsequent vulnerability allowed creating new accounts to access hidden functionality and retrieve an admin password in plain text. This access also revealed McDonald's "magic bell" API key for push notifications, allowing impersonation. Further investigation revealed that corporate executive portals could be accessed using basic crew member credentials, granting access to employee personal details globally. The Global Restaurant Standards portal also had minimal security for admin functions, allowing HTML modifications. Finally, McDonald's spin-off, Cosmic, had a bug allowing new customer coupons to be reused infinitely for free drinks. McDonald's removed its security.txt file, making reporting difficult, though Bob eventually reached a relevant contact to get most issues addressed. The transcript also briefly covers a separate story about activists hacking a North Korean hacker's computer, revealing espionage operations targeting South Korea and various cybercrime tools.

### McDonald's App Vulnerabilities

- Unlimited free food via points spoofing
- Client-side validation flaws across multiple platforms
- Exposed API keys for push notifications
- Insecure executive portal access using crew credentials
- Coupon reuse bugs in spin-off restaurant Cosmic

### Feelgood Design Hub Security Flaws

- Client-side password protection bypass
- Post-patch vulnerability allowing account creation and plain text password retrieval
- Exposed "magic bell" API key enabling push notification impersonation

### Other McDonald's System Weaknesses

- Global Restaurant Standards portal with zero admin authentication
- Insecure access to corporate executive portals with crew credentials

### Reporting and Patching

- Initial dismissal of critical bugs by McDonald's
- Delayed response to some vulnerabilities (e.g., Design Hub)
- Removal of security.txt file hindering reporting process

### North Korean Hacker Computer Breach

- Activists "Saber" and "Cyborg" compromised a North Korean hacker's computer
- Revealed ongoing espionage targeting South Korea
- Dump included source code, backdoors, exploits, and credentials

