Bug Bounty Program

A bug bounty program is a public offer made by a company: whoever finds a security vulnerability in its software and reports it confidentially receives money for it. In this way, the company deliberately seeks help from outside instead of relying solely on its own experts.

Every larger computer program contains bugs. Some of them are dangerous: they allow outsiders to access data or take over a system. Such dangerous bugs are called security vulnerabilities. In a bug bounty program, a company publicly announces that it will pay for tips about such vulnerabilities. Whoever finds one and reports it confidentially to the company, instead of exploiting or publishing it, receives a reward. The amount depends on how severe the damage would be. Small findings bring in a few hundred euros, very severe vulnerabilities can also bring six-figure sums.

Why this matters

A company can never fully review its own software by itself. The developers know their system too well and therefore overlook exactly the paths that no one thought of. In addition, a security department with thirty people worldwide faces thousands of curious experts.

Bug bounties exploit this difference in scale. They make wanting to report the more attractive option. Whoever finds a vulnerability has two options: sell it to criminals or intelligence agencies, or report it legally. The better the rewards and the fairer the treatment, the more often the decision falls in favor of the legal path.

For the company, the math usually works out favorably. A reward of 50,000 euros is cheaper than a data leak that costs millions in fines and lost trust.

How it works

At the beginning there is a set of rules, the so-called scope. It states which systems may be examined and which may not. Prohibited methods are also defined, such as attacks that would take down a service. Whoever adheres to these rules will not be sued. Whoever breaks them loses this protection.

Whoever discovers a vulnerability writes a report with instructions for reproducing it. The company checks whether the bug is real and new. It is then classified and assessed, and afterwards fixed. Only once the fix has been shipped may the finding usually be described publicly. This period is called the disclosure period and is often set at 90 days.

Many companies do not organize this themselves but instead go through platforms such as HackerOne or Bugcrowd. These intermediaries provide the reporting form, pre-screen reports, and pay out the rewards. A comparison: the platform functions like a tendering office that collects and sorts offers before they reach the client.

Where you encounter the term

Almost every major technology company has such a program: Google, Apple, Microsoft, Meta. Apple pays up into the millions for particularly severe iPhone vulnerabilities. Banks, government agencies, and even the German armed forces now also run their own programs.

In the news, bug bounties often turn up after a security incident. The report will then state whether the vulnerability was reported through a bounty program or was only noticed as a result of an attack. Among AI providers there is a new variant: rewards not only for technical bugs but also for ways to bypass a chatbot's safety rules.

For individuals, this has become a real source of side income. Some people live exclusively off bug bounties. Most programs have no upper or lower age limit, but for minors they require parental consent for the payout.

Related Products

Latest News

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.