Overview
A bug bounty program is a deal offered by many websites, organizations, and software developers by which individuals can receive recognition and compensation for reporting bugs, especially those pertaining to security vulnerabilities. If no financial reward is offered, it is called a vulnerability disclosure program.
These programs, which can be considered a form of crowdsourced penetration testing, grant permission for unaffiliated individuals—called bug bounty hunters, white hats or ethical hackers—to find and report vulnerabilities. If the developers discover and patch bugs before the general public is aware of them, cyberattacks that might have exploited it are no longer possible.
Participants in bug bounty programs come from a variety of countries, and although a primary motivation is monetary reward, there are a variety of other motivations for participating. Hackers could earn much more money for selling undisclosed zero-day vulnerabilities to brokers, spyware companies, or government agencies instead of the software vendor. If they search for vulnerabilities outside the scope of bug bounty programs, they might find themselves facing legal threats under cybercrime laws. The scale of bug bounty programs increased dramatically in the late 2010s.
3 sources for this section
- 1Bug bounty program — Wikipedia, revision 1375023325
- 2Ding, Aaron Yi; De Jesus, Gianluca Limon; Janssen, Marijn (2019). "Ethical hacking for boosting IoT vulnerability management". Proceedings of the Eighth International Conference on Telecommunications and Remote Sensing. Ictrs '19. Rhodes, Greece: ACM Press. pp. 49–55. arXiv:1909.11166. doi:10.1145/3357767.3357774. ISBN 978-1-4503-7669-3. S2CID 2026
- 3Weulen Kranenbarg, Marleen; Holt, Thomas J.; van der Ham, Jeroen (November 19, 2018). "Don't shoot the messenger! A criminological and computer science perspective on coordinated vulnerability disclosure". Crime Science. 7 (1): 16. doi:10.1186/s40163-018-0090-8. hdl:1871.1/8cdcfab0-9864-46c2-a7b7-a295c8ee511a. ISSN 2193-7680. S2CID 54080134.
History
In 1851, Alfred Charles Hobbs was paid US$20,000 (adjusted for inflation) to pick a lock. In 1983, the Hunter & Ready company posted an advertisement with the tagline "Get a bug if you find a bug", offering to reward hackers who discovered bugs in its VRTX operating system a Volkswagen Beetle car. In 1995, Netscape launched its bug bounty program, for the beta version of its Netscape Navigator 2.0 browser. Later on, other enterprises opened their own bug bounty programs. These were supplemented by crowdsourcing platforms that made it easier for professionals to find bug bounties.
5 sources for this section
- 1Bug bounty program — Wikipedia, revision 1375023325
- 4"VRTX poster - 102782474 - CHM". www.computerhistory.org. Retrieved March 20, 2026.
- 5Conger, Kate (January 19, 2017). "Hacking the Army". TechCrunch. Retrieved March 20, 2026.
- 6"Bounty attracts bug busters". CNET. June 13, 1997. Retrieved October 17, 2023.
- 7Friis-Jensen, Esben (April 11, 2014). "The History of Bug Bounty Programs". Cobalt.io. Archived from the original on March 16, 2020. Retrieved October 17, 2023.
Motivation
Despite developers' goal of delivering a product that works entirely as intended, virtually all software contains bugs. If a bug creates a security risk, it is called a vulnerability, and if the vendor is unaware of it, it is called a zero-day. Vulnerabilities vary in their potential to be exploited by malicious actors. Some are not usable at all, while others can be used to disrupt the device with a denial of service attack. The most valuable allow the attacker to inject and run their own code, without the user being aware of it. The harms of an attack can be severe.
Organizations seeking to improve security test their systems to see if they can be breached. Many contract with external services that conduct penetration testing, but this is not enough to find all vulnerabilities, motivating some companies to supplement with crowdsourced information. Many companies are skeptical of third-party reports, afraid that these programs will increase malicious activity, cost too much money, or bring fraudulent reports.
Unlike conventional penetration testing, bug bounty programs can provide more continuous vulnerability discovery and scale security testing through a larger pool of crowd-sourced researchers. Alternatively, bug bounty programs might be ignored because of confidence in their application's security or in favor of other security measures. Some studies have found that the cost per vulnerability found is much lower via bounty programs rather than by hiring software engineers to search for vulnerabilities.
1 source for this section
Rewards
The size of the reward offered varies on such factors such as the size of the company, the difficulty of finding the vulnerability, and how severe its effects could be if exploited. Successful bug bounty hunters can often make more than software developers. Many bug bounty programs are focused on web applications.
In August 2013, a Palestinian computer science student reported a vulnerability that allowed anyone to post a video on an arbitrary Facebook account. According to the email communication between the student and Facebook, he attempted to report the vulnerability using Facebook's bug bounty program but the student was misunderstood by Facebook's engineers. Later he exploited the vulnerability using the Facebook profile of Mark Zuckerberg, resulting in Facebook refusing to pay him a bounty.
Facebook started paying researchers who find and report security bugs by issuing them custom-branded "White Hat" debit cards that can be reloaded with funds each time the researchers discover new flaws.
Reports
Because submissions are open to anyone, a large number of reports (estimated at 50-70 percent for HackerOne, the largest platform) are invalid. One study found that the largest number of reports were rejected as previously known vulnerabilities, followed by false positives, out-of-scope, duplicates, and for lack of proof-of-concept. Another study found that bounty programs offering more money received a higher number of valid reports. One cause of invalid reports is that it may be easier for hackers to submit a report rather than do additional work to check their solution.
Some bug bounty platforms, including HackerOne, have implemented measures to cut down on the number of invalid reports. Bug bounty programs may be invite-only to trusted security researchers instead of public. To validate the vulnerability and receive an award, the hacker usually has to create an exploit to prove that the vulnerability found is a genuine security bug. The most commonly reported vulnerabilities in bug bounty programs include SQL injection, cross-site scripting (XSS), and design flaws.
1 source for this section
The source notesEvidence & further reading9 sources
- Bug bounty program — Wikipedia, revision 1375023325 Wikipedia contributors · Reference source · accessed 2026-09-22
- Ding, Aaron Yi; De Jesus, Gianluca Limon; Janssen, Marijn (2019). "Ethical hacking for boosting IoT vulnerability management". Proceedings of the Eighth International Conference on Telecommunications and Remote Sensing. Ictrs '19. Rhodes, Greece: ACM Press. pp. 49–55. arXiv:1909.11166. doi:10.1145/3357767.3357774. ISBN 978-1-4503-7669-3. S2CID 2026 dl.acm.org · Reference source · link imported 2026-09-22
- Weulen Kranenbarg, Marleen; Holt, Thomas J.; van der Ham, Jeroen (November 19, 2018). "Don't shoot the messenger! A criminological and computer science perspective on coordinated vulnerability disclosure". Crime Science. 7 (1): 16. doi:10.1186/s40163-018-0090-8. hdl:1871.1/8cdcfab0-9864-46c2-a7b7-a295c8ee511a. ISSN 2193-7680. S2CID 54080134. hdl.handle.net · Reference source · link imported 2026-09-22
- "VRTX poster - 102782474 - CHM". www.computerhistory.org. Retrieved March 20, 2026. computerhistory.org · Reference source · link imported 2026-09-22
- Conger, Kate (January 19, 2017). "Hacking the Army". TechCrunch. Retrieved March 20, 2026. techcrunch.com · Reference source · link imported 2026-09-22
- "Bounty attracts bug busters". CNET. June 13, 1997. Retrieved October 17, 2023. cnet.com · Reference source · link imported 2026-09-22
- Friis-Jensen, Esben (April 11, 2014). "The History of Bug Bounty Programs". Cobalt.io. Archived from the original on March 16, 2020. Retrieved October 17, 2023.