Virtual Event: Threat Detection and Incident Response Summit - Watch Sessions
Connect with us

Hi, what are you looking for?


Management & Strategy

HackerOne Says Bug Bounty Hunters Earned $100 Million Through Its Platform

HackerOne announced on Wednesday that its bug bounty platform has helped researchers earn more than $100 million since the company started paying hackers in October 2013.

HackerOne announced on Wednesday that its bug bounty platform has helped researchers earn more than $100 million since the company started paying hackers in October 2013.

The San Francisco-based company reported in late February that it had paid out a total of over $82 million in bounties, $40 million of which was awarded in 2019 alone. At the time, it also said that seven white hat hackers exceeded $1 million in lifetime earnings, and 13 others surpassed $500,000. In April 2020, hackers earned nearly $6 million.

HackerOne says it currently has nearly 300 employees and more than 700,000 hackers have signed up on its platform, looking for vulnerabilities in the systems and products of over 1,900 government and private organizations.

The company says an average of 84 new hackers signed up on its platform every hour in the past 7 years, with $6,000 being paid out every hour.

Business seems to be good even during the current coronavirus pandemic — a 17.5% increase was allegedly recorded since February — and HackerOne estimates that the total amount paid to hackers will reach $1 billion within five years.

HackerOne has raised more than $110 million in funding, including $36.4 million in a Series D round last year.

Bugcrowd, one of HackerOne’s main competitors, told SecurityWeek it is not disclosing total payouts at this time.

Advertisement. Scroll to continue reading.

However, the company, which is also based in San Francisco, reported in November 2019 that it paid out over half a million dollars in bug bounties in one week of October. It awarded 550 hackers a total of $1.6 million that month.

Bugcrowd has raised over $80 million, including $30 million announced last month as part of a Series D funding round.

Related: Hacker Earns $8,500 for Vulnerability in HackerOne Platform

Related: Hacker Accessed Private Reports on HackerOn

Related: Zoom Revamps Bug Bounty Program

Written By

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.


Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.


Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.


Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

Management & Strategy

SecurityWeek examines how a layoff-induced influx of experienced professionals into the job seeker market is affecting or might affect, the skills gap and recruitment...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...


The latest Chrome update brings patches for eight vulnerabilities, including seven reported by external researchers.


Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.