Bug Bounty

Bug Bounty

A bug bounty is a reward that a company pays when someone from outside finds a security flaw in its software and reports it confidentially. Instead of hiding errors, companies like Google, Apple, or OpenAI pay outsiders to attack their systems and uncover vulnerabilities.

Every major piece of software contains errors. Some of them are harmless, others allow outsiders to access passwords or customer data. Such dangerous errors are called security vulnerabilities. A bug bounty is a public promise made by a company: whoever finds such a vulnerability and reports it to us confidentially will be paid for it. The word is made up of “bug” for a programming error and “bounty” for a reward. The amount ranges, depending on severity, from around 100 euros up to several hundred thousand.

Why companies pay outsiders to attack them

A company can never fully test its own software by itself. Its own developers know their product too well and look where they expect problems to be. Outsiders try things that no one internally has thought of. A bug bounty therefore buys the company exactly this outside perspective.

The second reason is economic. A discovered vulnerability also has a price on the black market: criminals and state actors pay for access to other people’s systems. If a company pays nothing, the illegal sale is the only way for the finder to make money. A bounty makes the legal route more attractive. For the company, this is cheap: a reward of 50,000 euros is less than a data breach affecting millions of customers.

There is also a legal side to this. Without a program, someone testing other people’s systems moves in a gray area and risks being reported to the authorities. A bug bounty program specifies in writing what is allowed. For many finders, this protection is more important than the money.

From discovery to payout

Every program has rules, the so-called scope. It states which websites, apps, or servers may be tested and which may not. Almost always forbidden is anything that disrupts real users: overloading servers, spying on other people’s accounts, deleting data. Anyone who moves outside these rules loses legal protection.

If someone finds a vulnerability, they write a report. In it, they must not merely claim that an error exists, but demonstrate it in a comprehensible way. The company reviews the report, assesses its severity, and determines the reward accordingly. An error that exposes an entire database brings in a multiple of one that only displays the wrong icon.

Confidentiality applies until the issue is fixed. Usually both sides agree that the finder may only speak publicly about it after around 90 days. This is often mediated through platforms such as HackerOne or Bugcrowd, which collect and sort reports and handle payment. It is important to distinguish this from a penetration test: there, a company hires an agency for a fixed period and pays by the hour. With a bug bounty, anyone may search at any time, but money is only paid for an actual find.

From Apple rewards to jailbreaks in AI models

Almost all major technology companies run such programs. Apple pays up into the millions for particularly severe vulnerabilities in iPhones, because precisely this kind of access is extremely valuable to state buyers. Over the years, Google has paid out well over 50 million dollars to finders. Banks, car manufacturers, and government agencies now also use bug bounties.

In the AI industry, a new variant has emerged. There, it is not just about classic programming errors, but about inputs that trick a language model into giving forbidden answers. Such workarounds are called jailbreaks. Anthropic and OpenAI have set up programs that pay rewards for exactly this.

In the news, bug bounties usually come up after an incident. Then it is said that a vulnerability was “reported as part of a bug bounty program.” For the company, that is the favorable version of the story. The expensive version is the one in which criminals found the vulnerability first.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.