Skip to main content

Bug Bounty

Updated 3 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/bug-bounty

In short

A bug bounty is a program in which an organization rewards outside security researchers for finding and responsibly reporting vulnerabilities in its systems.

What is a bug bounty?

In a bug bounty program, an organization publishes rules inviting security researchers, either anyone or an invited group, to look for vulnerabilities in its websites, apps or products, and pays a reward, the bounty, for each valid report it hasn't received before. Rewards grow with severity, from small amounts for minor issues to very large sums for critical flaws in major platforms. Netscape ran one of the first programs in 1995, and today companies such as Google, Microsoft and Apple, as well as many governments, run them, often through platforms such as HackerOne, Bugcrowd and Intigriti.

The program's policy defines the scope, meaning which domains and apps may be tested, and forbids harmful techniques such as denial-of-service attacks, social engineering or reading other users' data beyond what proves the bug. It also explains how to report and includes a safe harbor statement promising not to take legal action against researchers who follow the rules. The security team then triages each report: it reproduces the issue, rates its severity, often with the CVSS scoring system, fixes it and pays the reward, usually only to the first person who reported that bug.

It is like a bank offering a reward to anyone who finds a weak spot in its vault and tells the bank instead of robbing it. Without payments, the same idea is a vulnerability disclosure policy (VDP): a public promise about how to report safely, often advertised in a security.txt file as defined by RFC 9116. Many organizations start with a VDP and add bounties once they can handle the volume of reports.

A bug bounty is often confused with penetration testing. A penetration test is a contract with a chosen team for a fixed scope and time, paid for the work, with a full report even if little is found; a bug bounty is open-ended and continuous, draws on many testers with different skills and pays only for valid findings. Bounties can also bring floods of duplicate or low-quality reports and don't guarantee that anything was tested thoroughly, so organizations use both, alongside secure development.

Key takeaways

  • A bug bounty pays outside researchers for valid vulnerability reports.
  • The policy sets the scope, forbidden techniques, rewards and safe harbor.
  • Platforms such as HackerOne and Bugcrowd host programs and help triage reports.
  • A vulnerability disclosure policy offers a safe reporting channel without payments.
  • It complements penetration testing rather than replacing it.

Example

A security.txt file that tells researchers where to reporttext
# Served at https://example.com/.well-known/security.txt (RFC 9116)
Contact: mailto:security@example.com
Contact: https://example.com/security/report
Expires: 2027-04-01T00:00:00.000Z
Policy: https://example.com/security/policy
Acknowledgments: https://example.com/security/thanks
Preferred-Languages: en, tr

Readers ask

What is the difference between a bug bounty and penetration testing?

A penetration test hires a team to test a fixed scope for a fixed time and is paid regardless of the results. A bug bounty is ongoing, open to many researchers and pays only for valid, new vulnerabilities.

Is bug bounty hunting legal?

Within an official program's scope and rules, yes, and safe harbor terms promise no legal action. Testing systems without permission, or outside the published scope, can break computer crime laws even when the intent is good.

How do you start bug bounty hunting?

Learn how common web vulnerabilities work, for example from the OWASP Top 10, practice on deliberately vulnerable labs and capture-the-flag challenges, and read publicly disclosed reports. Then choose a program with a broad scope and follow its rules exactly.

See also

Sources

Spotted a mistake or something missing on this page?Suggest an edit

More

Settings