Washington | 24°C (overcast clouds)
When IIIT‑Hyderabad students got free food for six months by exploiting a payment‑gateway loophole, says Scaler founder

Scaler founder reveals how a client‑side bug let students order meals without paying

A recent podcast revealed that a group of IIIT‑Hyderabad students manipulated a major food‑delivery app’s payment verification, enjoying free meals for almost half a year before the flaw was fixed.

It sounds like something out of a college‑prank movie, but according to Anshuman Singh – the founder of the coding‑boot‑up Scaler – a handful of tech‑savvy students from IIIT Hyderabad actually pulled off a six‑month free‑food spree. The story surfaced during a light‑hearted chat with comedian Biswa Kalyan Rath, and it’s been buzzing around tech circles ever since.

Singh recounted that the food‑delivery platform (he didn’t name it, but hinted it was one of the big players) used its own payment gateway. The catch? The gateway’s final “payment‑successful?” check happened in the user’s browser, not on a secure server. In plain terms, the app trusted the client to tell it whether the money had cleared.

Enter the students. By tinkering with the page’s JavaScript – essentially telling the browser, “hey, the payment went through” even though no transaction actually occurred – they managed to have the system mark the order as paid. The result? A dinner, lunch, or midnight snack that cost the restaurant chain nothing. Singh said the bug went unnoticed for months, letting the kids place order after order without ever reaching for their wallets.

"The checking whether the payment had gone through and the confirmation happened on the browser itself," Singh explained during the podcast. "IIIT Hyderabad students figured it out." He added that the loophole stayed open for roughly six months before the company finally patched it.

Listeners found the tale amusing, especially when Rath joked that the smartest move for a company facing such a hack would be to simply hire the hackers. Another participant noted how the students kept a low profile, avoiding any flashy bulk orders that might raise alarms. It’s a classic reminder that a tiny design oversight – trusting the client for critical validation – can spiral into a massive security hole.

While the story is still circulating on social media, it also serves as a cautionary note for developers: never rely on client‑side checks for anything that involves money or personal data. The backend should always be the final gatekeeper.

Comments 0
Please login to post a comment. Login
No approved comments yet.

Editorial note: Nishadil may use AI assistance for news drafting and formatting. Readers can report issues from this page, and material corrections are reviewed under our editorial standards.