I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny
A series of API flaws in McDelivery India made it possible to order food for a penny, hijack other people’s delivery orders, view user information, and more.
I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny Eaton • Dec 19, 2024 Copy Link Share Discussion links: Reddit | Hacker News Thank you to the Reddit netsec community for making this the most upvoted post of 2024 with 300k+ views ! 🏆 News coverage: TechCrunch Verdict Food Service SecurityWeek Heise (German) WinFuture (German) TechRadar Want to watch a video version? Check out this great video by LowLevelTV covering this disclosure. Key Points / Summary API flaws in the McDonald’s McDelivery system in India, one of the world’
saved by
related reading
- They Hacked McDonald’s Ice Cream Machines—and Started a Cold War | WIREDwired.com
- Riley Walzwalzr.com
- Turbo MCPmcp.run
- The Indytheindy.org
- Mastercard Developersdeveloper.mastercard.com
- Shopify Editions | Winter '26shopify.com
- Doordash and Pizza Arbitragereadmargins.com
- Lakera – Test your AI hacking skillsgandalf.lakera.ai
- Internetinternetlabs.co
- GitHub - public-apis/public-apis: A collective list of free APIsgithub.com
- Pipedream - Autonomous Underground Deliverypipedreamlabs.co
- Why We Don’t Trust the Database With Authentication – Sturdy Statisticsblog.sturdystatistics.com