Connect with us

Hi, what are you looking for?


Management & Strategy

HackerOne Surpasses $82 Million in Paid Bounties

With $40 million in bug bounties paid in 2019, hacker-powered bug bounty platform HackerOne nearly doubled the amount paid out in all previous years combined, reaching $82 million.

With $40 million in bug bounties paid in 2019, hacker-powered bug bounty platform HackerOne nearly doubled the amount paid out in all previous years combined, reaching $82 million.

The platform, which in 2019 also doubled the number of registered hackers, surpassing the 600,000 mark, received over 150,000 valid vulnerability reports last year, as part of more than 1,700 customer programs, run by both companies and government agencies.

HackerOne also announced that a total of seven hackers surpassed $1 million in lifetime earnings, thirteen more hitting $500,000 in lifetime earnings, and 146 hackers earning $100,000.

HackerOne’s 2020 hacker report shows that 78% of hackers are using their hacking experience as a career opportunity. Roughly 40% of hackers spend 20 hours or more per week searching for vulnerabilities, and 18% consider themselves full-time hackers.

The report also reveals that 84% of hackers learned their craft through online resources and self-directed educational materials. Only 16% completed a formal class or certification.

Hackers from 146 countries submitted reports last year. Of the total bounties paid, 19% went to hackers in the U.S. Those in India earned 10% of bounties, followed by Russia at 8%, China at 7%, Germany at 5%, and Canada at 4%.

In 2019, federal governments experienced the strongest year-over-year industry growth at 214% — 22 new programs were launched with governments in North America, Asia and Europe in 2019 — and the first programs at municipal level were launched last year.

Advertisement. Scroll to continue reading.

“Hackers are a global force for good, working together to secure our interconnected society,” said Luke Tucker, senior director of community at HackerOne. “The community welcomes all who enjoy the intellectual challenge to creatively overcome limitations. Their reasons for hacking may vary, but the results are consistently impressing the growing ranks of organizations embracing hackers through crowdsourced security — leaving us all a lot safer than before.”

Related: Two White Hats Earn Over $1 Million via Bug Bounty Programs

Related: Hacker Accessed Private Reports on HackerOne

Related: HackerOne Raises $36.4 Million in Series D Funding Round

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

SecurityWeek’s Threat Detection and Incident Response Summit brings together security practitioners from around the world to share war stories on breaches, APT attacks and threat intelligence.


Securityweek’s CISO Forum will address issues and challenges that are top of mind for today’s security leaders and what the future looks like as chief defenders of the enterprise.


Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.


Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Management & Strategy

SecurityWeek examines how a layoff-induced influx of experienced professionals into the job seeker market is affecting or might affect, the skills gap and recruitment...


The latest Chrome update brings patches for eight vulnerabilities, including seven reported by external researchers.

CISO Conversations

In this issue of CISO Conversations we talk to two CISOs about solving the CISO/CIO conflict by combining the roles under one person.