UIDAI Launches Bug Bounty Programme to Further Strengthen Aadhaar Security
In this note
1. At a Glance
- UIDAI's first structured Bug Bounty Programme, launched 11 March 2026, invites vetted ethical hackers to discover vulnerabilities in core Aadhaar digital assets in exchange for severity-graded rewards [1].
- Marks a shift from closed in-house security audits to a coordinated vulnerability disclosure (CVD) model — a global best practice now formalised for India's largest digital ID system [1].
- UPSC relevance: intersects GS-II (governance, digital ID, privacy) and GS-III (cyber security, internal security via IT infrastructure).
2. Why in the News
- On 11 March 2026, the Unique Identification Authority of India (UIDAI) under the Ministry of Electronics & Information Technology (MeitY) launched its first structured Bug Bounty Programme with a 20-member panel of ethical hackers/researchers [1].
- Programme is operated in partnership with M/s ComOlho IT Pvt. Ltd., a cybersecurity firm acting as the platform partner [2].
3. Background & Evolution
- UIDAI established in Jan 2009 under Planning Commission; statutory body since Aadhaar Act, 2016 under MeitY.
- Predecessor government bug-bounty: Aarogya Setu Bug Bounty Programme announced in 2020 by MeitY/NIC — first government-of-India bug bounty [3].
- UIDAI's prior security tie-ups: UIDAI–SETS (Society for Electronic Transactions and Security, Chennai) MoU in 2023 for R&D in quantum computing, IoT and cyber security [4].
- 2025–26 challenges (deepfake/spoofing detection for face authentication) under PRID 2179959 preceded the bug bounty [5].
4. Core Static Facts
- Parent ministry: Ministry of Electronics & Information Technology (MeitY) [1].
- Implementing body: UIDAI (statutory authority under Section 11, Aadhaar Act 2016).
- Launch date: 11 March 2026 [1].
- Participants: 20 selected security researchers/ethical hackers (closed panel, invite-based) [1].
- Scope (in-scope assets): UIDAI official website, myAadhaar portal, Secure QR Code application [1].
- Reward basis: Severity-tiered — Critical / High / Medium / Low [2].
- Platform partner: M/s ComOlho IT Pvt. Ltd. [2].
- Model: Responsible/coordinated vulnerability disclosure (RVD/CVD).
5. Multi-Dimensional Analysis
Scientific / Technological
- Crowdsources offensive security testing — uncovers flaws in-house audits and CERT-In empanelled auditors may miss [1][6].
- Targets web, mobile and crypto-attestation (Secure QR Code) layers — covers full stack of resident-facing Aadhaar services [1].
Legal / Constitutional
- Operates within the Aadhaar Act 2016 (Section 28 — security & confidentiality of identity information) and Digital Personal Data Protection (DPDP) Act 2023 duties on data fiduciaries.
- Reinforces compliance with Puttaswamy (2017) privacy judgment by hardening technical safeguards demanded as "reasonable security".
Governance / Ethical
- Closed-panel model balances transparency vs. risk — limits exposure of critical national infrastructure while still tapping external expertise [1].
- Aligns with CERT-In's Cyber Crisis Management Plan and the National Cyber Security Policy 2013 ecosystem [6].
Administrative
- Builds an institutional pipeline of vetted researchers UIDAI can re-engage; reduces reliance solely on empanelled auditors.
- Tiered reward structure incentivises focus on high-impact bugs (auth bypass, data exposure) over cosmetic issues [2].
6. Recent Developments (last 12-18 months)
- Mar 2026: Bug Bounty Programme launched [1].
- Feb 2026: UIDAI Data Hackathon 2026 showcased data-driven governance solutions [7].
- 2025: UIDAI Grand Challenge for deepfake/mask/spoofing attack detection in Aadhaar face authentication (applications till 15 Nov 2025) [5].
- 2024: UIDAI partnered with Sarvam AI (indigenous GenAI) for Aadhaar service UX [8].
7. Prelims Hooks
- UIDAI launched its first structured Bug Bounty Programme on 11 March 2026 [1].
- Programme covers three assets: UIDAI website, myAadhaar portal, Secure QR Code application [1].
- Panel size: 20 ethical hackers/researchers (invitation-based) [1].
- Industry partner: ComOlho IT Pvt. Ltd. [2].
- Reward tiers: Critical, High, Medium, Low (severity-based) [2].
- UIDAI is a statutory body under the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016.
- Parent ministry: MeitY (NOT Ministry of Home Affairs, NOT Finance).
- India's first government bug bounty was for Aarogya Setu (2020) — not Aadhaar [3].
- UIDAI signed cyber-security R&D MoU with SETS, Chennai [4].
- CERT-In (under MeitY) is India's nodal cyber-incident response agency [6].
- Puttaswamy v. Union of India (2017) made privacy a fundamental right (Art. 21).
- DPDP Act 2023 governs personal data processing in India.
8. Mains Relevance
- GS-II: e-Governance — applications, models, successes & limitations; citizens' charters; protection of vulnerable sections (digital ID).
- GS-III: Challenges to internal security through communication networks; basics of cyber security; role of agencies.
- Probable stems: 1. "Bug-bounty programmes mark a maturing of India's approach to securing critical digital public infrastructure. Discuss with reference to UIDAI's 2026 initiative." (GS-III, 250 words) 2. "Coordinated vulnerability disclosure must coexist with statutory liability under the Aadhaar Act and DPDP Act. Examine." (GS-II, 150 words) 3. "Trust in Aadhaar rests as much on perception as on technical safeguards. Evaluate UIDAI's recent measures." (GS-II)
9. Related Topics to Study Next
- Aadhaar Act 2016 & Puttaswamy judgment — statutory & constitutional base.
- DPDP Act 2023 — data fiduciary obligations relevant to UIDAI.
- CERT-In & CERT-In Directions of April 2022 — incident reporting regime [6].
- Digital Public Infrastructure (DPI) / India Stack — Aadhaar as foundational layer.
- National Cyber Security Policy 2013 & upcoming National Cyber Security Strategy.
- Aarogya Setu Bug Bounty (2020) — first GoI precedent [3].
- SETS, Chennai — DST-promoted cyber R&D body [4].
- Face authentication / deepfake challenge by UIDAI [5].
10. Common Errors / Trap Areas
- Wrong ministry: UIDAI is under MeitY, not Ministry of Home Affairs or Finance.
- "First Indian govt bug bounty" — that title belongs to Aarogya Setu (2020), not UIDAI [3].
- Open vs. closed model: UIDAI's programme is closed/invite-only (20 researchers), not a public bug bounty like HackerOne open programmes [1].
- Scope confusion: The programme covers front-end public assets (website, myAadhaar, QR app) — not the CIDR (Central Identities Data Repository) core [1].
- Don't confuse UIDAI's bug bounty with CERT-In's RVDP (Responsible Vulnerability Disclosure Programme) — separate frameworks.
Sources
- 1UIDAI Launches Bug Bounty Programme to Further Strengthen Aadhaar Security (PIB, 11 Mar 2026)pib.gov.in · tier 1
- 2PIB Detail page (same release, additional reward/partner detail)pib.gov.in · tier 1
- 3Government announces Bug Bounty Programme for Aarogya Setu (PIB, 2020)pib.gov.in · tier 1
- 4UIDAI and SETS join hands for R&D in Quantum Computing, IoT Security and Cyber Security (PIB)pib.gov.in · tier 1
- 5UIDAI Seeks Solutions to Defeat Deepfakes/Spoofing in Face Authentication (PIB)pib.gov.in · tier 1
- 6CERT-In: India's Frontline Defender against Cyber Threats (PIB document, Jan 2026)static.pib.gov.in · tier 1
- 7UIDAI Data Hackathon 2026 (PIB)pib.gov.in · tier 1
- 8UIDAI partners with Sarvam AI (PIB)pib.gov.in · tier 1