Anaya Iyer 8 min readA bug bounty is a standing offer: find a security flaw in our systems, report it responsibly, and we will pay you. The idea is older than most people assume โ Netscape launched one for its Navigator 2.0 browser in 1995 โ but it became an industry in the 2010s when platforms such as HackerOne (2012), Bugcrowd (2012), Intigriti and YesWeHack turned ad-hoc rewards into managed marketplaces. Today the U.S. Department of Defense, Google, Microsoft, Apple, airlines, banks and car makers all run them. The question this article answers is the one both sides quietly ask: are they actually worth it? We look at it from the organisation's side, the researcher's side, and the wider security ecosystem.
Short answer: For organisations with a working vulnerability-management process, a well-scoped bounty is one of the most cost-efficient sources of real-world findings. For organisations without one, it is an expensive way to discover that they cannot fix bugs quickly. For researchers, it pays very well for a small elite and very poorly for most.
The numbers behind the market
Public disclosures from the largest programs show how big bounties have become:
| Program | Reported payout | Period / note |
|---|---|---|
| Google Vulnerability Reward Program | โ USD 10 million to 632 researchers | 2023 (Google VRP annual review) |
| Google Vulnerability Reward Program | โ USD 11.8 million to 660 researchers | 2024 |
| Microsoft Bounty Programs | USD 16.6 million to 343 researchers | Fiscal year to mid-2024 |
| HackerOne platform (all customers) | More than USD 300 million cumulative | Milestone announced 2023 |
| Apple Security Bounty | Top award raised to USD 2 million | Announced 2025 for exploit chains |
| U.S. DoD "Hack the Pentagon" | 138 valid vulnerabilities in first pilot | 2016 pilot, ~USD 150,000 paid |
Those figures are large in absolute terms, but they are small compared with the cost of a single serious breach โ IBM's 2024 report put the global average at USD 4.88 million. That ratio is the core economic argument for bounties.
How a bounty program actually works
- Policy and scope. The organisation publishes what is in scope (domains, apps, APIs), what is out of scope, testing rules and a safe harbor promise not to pursue legal action against good-faith researchers.
- Submission. Researchers submit reports with reproduction steps and impact.
- Triage. The platform or internal team validates the report, removes duplicates and assigns severity โ commonly using CVSS.
- Reward. Payment follows a published table; critical issues pay the most.
- Fix and disclosure. The organisation remediates and, in many programs, the report is disclosed publicly after the fix.
Bounty vs. VDP vs. penetration test
A bounty is often confused with two related practices. A vulnerability disclosure program (VDP) is simply a published, safe channel for reporting flaws โ usually without payment. The U.S. CISA Binding Operational Directive 20-01 (2020) required federal civilian agencies to publish one, and ISO/IEC 29147 and 30111 describe how disclosure and handling should work. A penetration test is a time-boxed engagement by a contracted team with a defined methodology and a report.
| Factor | VDP | Bug bounty | Penetration test |
|---|---|---|---|
| Cost model | Staff time only | Pay per valid finding + platform fees | Fixed fee per engagement |
| Coverage | Opportunistic | Continuous, many testers | Deep but time-boxed |
| Predictability | Low volume | Variable volume and spend | High |
| Compliance evidence | Weak alone | Supplementary | Strong (PCI DSS, SOC 2, etc.) |
| Best for | Everyone, as a baseline | Mature teams with large attack surface | Release gates, audits, new systems |
| Main risk | Ignored reports | Noise, duplicates, budget spikes | Snapshot in time |
Practical rule: Run a VDP first. Add penetration tests for depth and compliance. Add a bounty when you can reliably fix what the first two find โ otherwise you pay to learn the same lesson more expensively.
Is it worth it for organisations?
The case for
- Pay for results, not hours. Rewards are tied to validated findings, so spending scales with real exposure discovered.
- Diversity of testers. Thousands of researchers bring techniques, tools and perspectives no single consultancy has.
- Continuous coverage. Code ships every day; a bounty tests in production continuously rather than once a year.
- Talent pipeline. Many companies hire top researchers from their own programs.
- Public trust signal. A visible program tells customers and regulators that security reports are welcome and handled.
The case against
- Noise. Platforms report that a large share of submissions are duplicates, out of scope or informational. Without good triage, internal teams drown.
- Budget volatility. A new attack technique can produce a burst of critical findings in one month.
- Fix debt exposed. If median time to remediate is months, researchers lose interest and findings sit unresolved โ a risk in itself.
- Scope gaps. Researchers go where rewards are; internal systems, business logic and supply chain often get less attention.
- Legal and reputational friction. Disputes over severity or payment can become public quickly.
A simple cost model
Consider an illustrative mid-sized SaaS company. The figures below are an example model, not market averages, to show how to reason about return on investment.
| Line item | Example value | Comment |
|---|---|---|
| Platform subscription + managed triage | USD 60,000โ120,000 | Varies widely by vendor and tier |
| Rewards paid (e.g. 40 valid findings) | USD 80,000 | Mix of low, medium, a few highs |
| Internal engineering time to fix | USD 50,000 | Often omitted from ROI calculations |
| Total annual cost | โ USD 190,000โ250,000 | Comparable to 2โ4 large pentests |
| Value if one critical breach is prevented | Up to millions | IBM average USD 4.88M |
The deciding variable is rarely the reward table; it is whether the company can turn reports into fixes quickly. A program with a 7-day median fix time for criticals is a strong investment. One with a 120-day median is mostly paying for a backlog.
Is it worth it for researchers?
Bounty income follows a steep power-law distribution. Platform reports have repeatedly highlighted researchers who have passed USD 1 million in lifetime earnings, yet the same data shows most registered users never earn a bounty at all. Competition, duplicates (only the first valid report is paid) and time spent on dead ends make the effective hourly rate unpredictable.
| Motivation | Reality | How to improve the odds |
|---|---|---|
| Income | Highly concentrated among top performers | Specialise in one technology or bug class |
| Learning | Excellent real-world training ground | Read public disclosed reports systematically |
| Career | Strong portfolio for security jobs | Write up findings where disclosure is allowed |
| Recognition | Hall of fame, leaderboards, CVEs | Choose programs that publish disclosures |
| Flexibility | Work anywhere, any time | Treat it as a business: track hours and win rate |
Legal safe harbor: the quiet foundation
Bounties only work if researchers are not treated as criminals. In May 2022 the U.S. Department of Justice revised its charging policy under the Computer Fraud and Abuse Act, stating that good-faith security research should not be prosecuted. The open-source disclose.io project offers standard safe-harbor language organisations can adopt. Researchers should still read every policy carefully: safe harbor applies only to activity within scope and rules, and laws differ by country.
Where bounties are heading
- AI as a target. Google added generative-AI issues to its VRP in 2023, and several AI labs now run bounties for model jailbreaks and data-leakage paths.
- AI as a hunter. In 2025 an autonomous system named XBOW reached the top of HackerOne's U.S. leaderboard, prompting debate about how platforms rank and pay automated submissions.
- Private, invite-only programs continue to grow as companies prefer vetted researchers and predictable volume.
- Regulatory pull. Disclosure requirements in the EU Cyber Resilience Act and sector rules raise the baseline: every product maker needs at least a coordinated disclosure channel.
A readiness checklist before you launch
- A published VDP with a security.txt file (RFC 9116) on your domains.
- An owner for incoming reports with a response-time target.
- A severity and reward table you can afford even in a bad month.
- Clear scope, including what testers must not touch (production data, denial of service).
- A measured fix process: target times per severity, tracked monthly.
- Safe-harbor language reviewed by counsel.
- A plan to start private and expand to public once triage is stable.
Verdict
Bug bounties are worth it when they sit on top of a functioning security program โ not instead of one. For organisations, the return depends far more on remediation speed and triage quality than on reward size. For researchers, bounties are a superb learning and career platform, and a lucrative business for a specialised few. For the ecosystem, they have done something valuable: they have made reporting a flaw a normal, legal, even celebrated act.
Frequently asked questions
How much does a bug bounty pay?
It ranges from tens of dollars for low-severity issues to six or seven figures at the top of programs such as Apple's and Google's. Each program publishes its own table.
Do small companies need a bounty?
Usually not at first. A disclosure policy and periodic penetration testing give better value until the team can handle a steady stream of reports.
Is bug hunting legal?
Testing within a program's published scope and rules, under safe harbor, is generally protected. Testing outside scope, or systems without a program, can be illegal.
References and further reading
- Google Security Blog, Vulnerability Reward Program year in review
- Microsoft Security Response Center, bounty programs
- Apple Security Bounty
- HackerOne, Hacker-Powered Security Report
- U.S. Department of Justice, revised CFAA charging policy (May 2022)
- CISA Binding Operational Directive 20-01
- disclose.io safe harbor framework
- RFC 9116: security.txt
- IBM, Cost of a Data Breach Report 2024
- FIRST, Common Vulnerability Scoring System
From our own rounds
Measured on The Curator, from real sessions people played on this site โ not a third-party dataset.
- Rounds played here
- 167
- Questions per round
- 1.7
Rate this article
Discussion
Comments are moderated. Read our editorial policy.