Bug Bounty
In short
A bug bounty is a program in which an organization rewards outside security researchers for finding and responsibly reporting vulnerabilities in its systems.
What is a bug bounty?
In a bug bounty program, an organization publishes rules inviting security researchers, either anyone or an invited group, to look for vulnerabilities in its websites, apps or products, and pays a reward, the bounty, for each valid report it hasn't received before. Rewards grow with severity, from small amounts for minor issues to very large sums for critical flaws in major platforms. Netscape ran one of the first programs in 1995, and today companies such as Google, Microsoft and Apple, as well as many governments, run them, often through platforms such as HackerOne, Bugcrowd and Intigriti.
The program's policy defines the scope, meaning which domains and apps may be tested, and forbids harmful techniques such as denial-of-service attacks, social engineering or reading other users' data beyond what proves the bug. It also explains how to report and includes a safe harbor statement promising not to take legal action against researchers who follow the rules. The security team then triages each report: it reproduces the issue, rates its severity, often with the CVSS scoring system, fixes it and pays the reward, usually only to the first person who reported that bug.
It is like a bank offering a reward to anyone who finds a weak spot in its vault and tells the bank instead of robbing it. Without payments, the same idea is a vulnerability disclosure policy (VDP): a public promise about how to report safely, often advertised in a security.txt file as defined by RFC 9116. Many organizations start with a VDP and add bounties once they can handle the volume of reports.
A bug bounty is often confused with penetration testing. A penetration test is a contract with a chosen team for a fixed scope and time, paid for the work, with a full report even if little is found; a bug bounty is open-ended and continuous, draws on many testers with different skills and pays only for valid findings. Bounties can also bring floods of duplicate or low-quality reports and don't guarantee that anything was tested thoroughly, so organizations use both, alongside secure development.
Key takeaways
- A bug bounty pays outside researchers for valid vulnerability reports.
- The policy sets the scope, forbidden techniques, rewards and safe harbor.
- Platforms such as HackerOne and Bugcrowd host programs and help triage reports.
- A vulnerability disclosure policy offers a safe reporting channel without payments.
- It complements penetration testing rather than replacing it.
Example
# Served at https://example.com/.well-known/security.txt (RFC 9116)
Contact: mailto:security@example.com
Contact: https://example.com/security/report
Expires: 2027-04-01T00:00:00.000Z
Policy: https://example.com/security/policy
Acknowledgments: https://example.com/security/thanks
Preferred-Languages: en, trReaders ask
What is the difference between a bug bounty and penetration testing?
A penetration test hires a team to test a fixed scope for a fixed time and is paid regardless of the results. A bug bounty is ongoing, open to many researchers and pays only for valid, new vulnerabilities.
Is bug bounty hunting legal?
Within an official program's scope and rules, yes, and safe harbor terms promise no legal action. Testing systems without permission, or outside the published scope, can break computer crime laws even when the intent is good.
How do you start bug bounty hunting?
Learn how common web vulnerabilities work, for example from the OWASP Top 10, practice on deliberately vulnerable labs and capture-the-flag challenges, and read publicly disclosed reports. Then choose a program with a broad scope and follow its rules exactly.
See also
- Penetration TestingSecurity, p. 32Penetration testing is an authorized, simulated attack on a system that helps an organization find and fix security weaknesses before real attackers do.
- CVESecurity, p. 12A CVE is a unique public identifier, such as CVE-2021-44228, given to one known security vulnerability so everyone can refer to the same flaw by one name.
- Zero-DaySecurity, p. 57A zero-day is a software vulnerability that the vendor doesn't know about or hasn't fixed yet, so attackers can exploit it before any patch exists.
- OWASP Top 10Security, p. 30The OWASP Top 10 is a widely used list of the ten most critical security risks to web applications, published by the nonprofit OWASP and updated regularly.
- Fuzz TestingTesting & Quality, p. 11Fuzz testing is an automated technique that feeds a program huge numbers of unexpected or malformed inputs to find crashes, hangs, and security vulnerabilities.
Sources
Spotted a mistake or something missing on this page?Suggest an edit