~kris/dots

srice

ref: e9b48d06a8541f3eda5c4db90382ab3c77183afb srice/doc/income/bug-bounty.md -rw-r--r-- 29.4 KiB
e9b48d06 — Kris Yotam xprofile: systemd-aware pipewire start + blueman-applet; sb-internet: tolerate missing /proc/net/wireless 2 months ago

#title: "Bug Bounty as an Income Stream" subtitle: "Platforms, programs, specializations, and what hunters actually earn" audience: "Kris Yotam (Linux/C/Python/Rust, OSCP track, math background, AI-security interest)" related: "./pentest.md (cert + career-path side)" last_updated: 2026-05-20

#Bug Bounty as an Income Stream

This is the platforms-and-programs side. The cert track, formal pentesting employment, OSCP/OSWE/OSEP planning, and Synack Red Team vetting live in ./pentest.md. Read that first if you want the career-path angle; this document assumes you already know what XSS and a reverse shell are.

#1. Major BB Platforms — Head-to-Head

Platform Founded Model Median public bounty Top single payout (public) Notes
HackerOne 2012 Public + private + managed ~$500 (web), ~$2.5k (high) $1M+ (Google/Apple chains via H1-managed) Biggest brand. Live Hacking Events (LHEs). Best AI/LLM crossover.
Bugcrowd 2012 Public + private + managed (VRT-graded) ~$400 ~$200k (Tesla/automotive) Hosts OpenAI, Tesla, Atlassian. CrowdMatch invites.
Intigriti 2016 Public + private €500 median €100k+ (EU OSS bounties) EU-headquartered (Belgium). Hosts EU-funded OSS programs. Triage reputation is the strongest of the big-four.
YesWeHack 2015 Public + private €300-€500 €50k+ EU/Asia/MEA. Strong in finance + telco in France, Singapore, Germany.
Synack Red Team 2013 Vetted private only hourly + bounty hybrid n/a public Application + skills test + background check. See pentest.md SRT section.
Immunefi 2020 Web3 / smart contracts $1k-$10k typical $10M (Wormhole, capped) Highest absolute payouts in the industry. ~90% of top web3 bounties live here.
Cantina 2023 Web3 audits + competitive contests varies $500k+ contest pots Spearbit's competitive arm. Solo bounties + crowd audits.
Code4rena 2021 Web3 competitive audit contests n/a (contest pots) $1M+ pots Contest-style; you compete with other auditors, payouts split by severity weighting.
Sherlock 2022 Web3 contests + coverage n/a (contest pots) $1M+ pots Insurance-backed audit contests; Watson rank system.
HackenProof 2017 Public + web3 $500-$5k ~$1M Eastern-European origin, growing web3 share.
Federacy 2016 Public/private Low Low Small program list; mostly startups. Worth a skim, not a primary platform.
Open Bug Bounty 2014 Non-paid coordinated disclosure $0 $0 Reputation-only. Useful for first-time CVE-ish writeups, not income.

Ranking for a serious researcher in 2026:

  1. HackerOne broadest program list. OpenAI is not here but Anthropic, GitHub, PayPal, Shopify, DoD, GitLab are. Best LHE pipeline.
  2. Immunefi if you can do Solidity audits at all, the expected hourly here beats every other platform combined. The catch is the skill ramp.
  3. Bugcrowd for OpenAI, Tesla, Atlassian, and roughly half the Fortune 500 private programs.
  4. Intigriti fastest-growing, best triage, and EU public-sector programs you cannot get elsewhere.
  5. Code4rena / Sherlock / Cantina pick one as a "compete on weekends" platform once you have Foundry skills.
  6. YesWeHack fine as a secondary, especially if you want Asian/EU enterprise scope.
  7. Synack covered in pentest.md; it is hybrid contractor/bounty work, not pure BB.

#2. Top-Paying Public Programs (2025-2026 Snapshot)

Program Platform / URL Scope highlights Typical range Top tier Notes
Apple Security Bounty security.apple.com/bounty iOS/macOS/iCloud/Secure Enclave $5k-$250k $2M for full zero-click iOS chain with persistence Slow triage, world-class engineers reviewing.
Google VRP bughunters.google.com All Google products $100-$31,337 $605k+ paid for Android chains Fast-ish triage; very clear severity guide.
Chrome VRP g.co/chrome/vrp Chromium renderer/sandbox/IPC $500-$250k $250k for sandbox escape full chain Memory-safety bug heaven; Rust folks have an edge.
Android Security Rewards bughunters.google.com AOSP, Pixel, Tensor $500-$1M $1M Pixel TEE Hardware + kernel skills required for top tier.
Microsoft Bug Bounty microsoft.com/msrc/bounty Azure, M365, Identity, Copilot, Windows insider $500-$250k $250k Hyper-V Different sub-programs per product; read each carefully.
Meta Bug Bounty bugbounty.meta.com FB / IG / WhatsApp / Quest / Llama $500-$300k $300k+ chains Source-code-aided research for invited researchers.
Amazon VRP hackerone.com/amazonvrp AWS, retail, devices, Alexa $100-$25k varies AWS-side has its own program at aws.amazon.com/security/vulnerability-reporting.
OpenAI bugcrowd.com/openai API, ChatGPT, plugins, infra $200-$6.5k typical $20k+ for critical infra See section 3. Model jailbreaks are OUT of scope.
Anthropic hackerone.com/anthropic plus separate model-safety program Claude API, claude.ai, infra $1k-$15k $30k+ via separate model-safety program Two-program structure: classical AppSec on H1, model-safety/universal-jailbreak elsewhere (see section 3).
GitHub hackerone.com/github github.com, Actions, Codespaces $617-$30k+ $30k+ Long-running, top-tier reputation.
GitLab hackerone.com/gitlab gitlab.com + self-managed $1k-$35k $35k+ Generous on auth/RCE.
PayPal hackerone.com/paypal Payments, Braintree, Venmo $50-$30k $30k+ Fast triage, picky on impact.
Stripe bugcrowd.com/stripe All Stripe surface $500-$30k $30k+ Tight scope, high quality bar.
Square / Block hackerone.com/block Cash App, Square, Tidal $100-$25k $25k+
Uber hackerone.com/uber rider, driver, eats, freight, infra $500-$50k $50k+ Mature program; lots of duplicate noise.
Shopify hackerone.com/shopify shop.app, admin, apps $500-$50k $50k+ Famous LHE host. Strong reputation rewards.
Cloudflare hackerone.com/cloudflare edge, Workers, Zero Trust $250-$10k+ varies Workers/Pages bugs pay well.
Tesla bugcrowd.com/tesla Vehicles, app, energy, infra $100-$200k $200k+ for vehicle CAN/infotainment Pwn2Own automotive parity.
US DoD (Hack the Pentagon) hackerone.com/deptofdefense .mil + DoD vendors (varies by event) $0-$25k $25k for select events Most engagements pay; the public VDP does not. Prestige + clearance signal.
EU OSS (intigriti-hosted) intigriti.com/programs Drupal, Mastodon, FileZilla, etc. €500-€10k €25k+ EU Commission funds bounties on critical OSS.
Wormhole (Immunefi) immunefi.com/bug-bounty/wormhole Cross-chain bridge $50k-$2.5M $10M cap One of the largest live bounties on earth.
Aave (Immunefi) immunefi.com/bug-bounty/aave DeFi lending $10k-$1M $1M+
MakerDAO / Sky (Immunefi) immunefi.com/bug-bounty/makerdao DAI/USDS stablecoin $10k-$10M $10M cap
Optimism (Immunefi) immunefi.com/bug-bounty/optimism L2 rollup $50k-$2M+ $2M+
Arbitrum (Immunefi) immunefi.com/bug-bounty/arbitrum L2 rollup $10k-$2M $2M+
Polygon (Immunefi) immunefi.com/bug-bounty/polygontechnology PoS, zkEVM $10k-$2M $2M+

Time-to-pay reputation (broadly): GitHub, Shopify, Stripe, GitLab fast. Apple, Google, Microsoft slow but reliable. Tesla, Uber variable. Immunefi top programs pay within 2-8 weeks of fix deploy; KYC required above roughly $10k.

#3. AI / LLM-Specific Bug Bounties

This is your declared niche, so it gets a real treatment. The most important framing: classical AppSec bugs in AI products pay far better than novel alignment attacks. A prompt injection that exfiltrates another user's chat history via the plugin sandbox is an IDOR + SSRF story dressed in LLM clothing, and it pays IDOR + SSRF money, not "interesting paper" money.

#Programs

Program URL What pays What does not
OpenAI bugcrowd.com/openai API auth/authz, infra RCE/SSRF, plugin/connector escapes, sandbox bypasses, account takeover, IDOR on chat/file resources, privilege escalation in Operator/Codex/Atlas, billing tampering Model jailbreaks, prompt injections producing disallowed content, hallucinations, factual errors, model-safety / alignment issues explicitly out of scope of the paid program. OpenAI routes those through a separate (mostly non-monetary) model-vulnerability reporting form. Typical critical payouts: $6.5k-$20k.
Anthropic classical hackerone.com/anthropic API/web/infra bugs in claude.ai, console, integrations Same exclusions as above (jailbreaks, refusal-evasion).
Anthropic model safety Separate invite/contest programs (e.g. universal-jailbreak prizes, constitutional-classifier challenges) Universal jailbreaks of specific safeguards, with reproduction recipe One-off contests; not a steady income.
Google (Bard/Gemini under VRP + AI VRP) bughunters.google.com (see AI rules) Account takeover, data exfiltration via Workspace/Drive Gemini integration, prompt-injection-led data leaks, model theft, training data leakage Pure refusal-evasion ("I made it curse").
Microsoft Copilot microsoft.com/msrc/bounty-microsoft-ai Copilot for M365/Edge/Windows, including indirect prompt injection that leads to data exfiltration. Critical: $20k-$30k+ Hallucinations, "uncomfortable" content, low-impact prompt injection.
xAI / Grok hackerone.com/x covers X + Grok Account takeover via Grok integrations, training-data leakage, RCE Jailbreaks.
Hugging Face huggingface.co/security (private, request invite) Account takeover, model-card XSS, Spaces sandbox escape, dataset poisoning vectors Public AI-hub triage is faster than the giants.
Meta / Llama bugbounty.meta.com All FB/IG/Llama infra; Llama Guard bypasses with impact Pure jailbreaks.
Replicate, Together.ai, Fireworks, Perplexity, Mistral Bug-bounty pages on company sites or security.txt of each RCE in inference sandbox, billing/abuse, account takeover Smaller payouts ($500-$5k typical), faster triage.

#Status paths (non-monetary but career-forming)

  • HackAPrompt (2023, recurring) Learn Prompting + AI Village competition. Established the prompt-injection field; winners get hired.
  • AI Village at DEF CON generative red-team competitions (the 2023 White House GRT, the 2024 follow-ups). Speaking here is a credential.
  • OWASP LLM Top 10 the canonical taxonomy. LLM01 prompt injection through LLM10 supply chain. Use the IDs in your reports; triagers know them.
  • MITRE ATLAS adversarial ML taxonomy. Useful for framing model-extraction / data-poisoning reports.

#Where the easy wins are in AI products (in 2026)

  1. Indirect prompt injection that lands a real impact agentic systems (Operator, Atlas, Gemini-in-Workspace, Copilot Studio) that read attacker-controlled content and then act with the user's privileges. This is the single hottest 2026 category.
  2. RAG data leaks system prompts, embedding-DB content, other users' chunks. Treat the vector DB as a data store and look for IDOR / auth.
  3. Plugin / tool / MCP server escapes SSRF and RCE through a function-calling tool that takes URLs or shell args. Classic AppSec, AI surface.
  4. Auth and sharing bugs in chat/file resources IDOR on share links, conversation IDs, file IDs, project IDs.
  5. Sandboxing escapes code interpreter / "Advanced Data Analysis"-style containers.
  6. Billing / abuse free-tier bypass, refund logic, account spam, model-cost evasion.

Your math + Python + Rust profile is unusually well suited to the agent / tool-use surface. That is the lane.

#4. Specializations and Their Economics

Specialization Bug payout range Realistic hourly when productive Supply / demand Ramp
Web app (classical OWASP) $100-$5k $50-$200/hr Heavily saturated 1-3 months from PortSwigger to first paid bug
Mobile (Android) $500-$30k $100-$300/hr Moderate 2-4 months: Frida, jadx, objection, Burp
Mobile (iOS) $500-$50k+ $150-$400/hr Low supply 4-8 months; needs jailbroken device or Corellium
API security $250-$10k $80-$250/hr Growing Easiest fast-win lane for newcomers
IDOR / access control $250-$15k $100-$300/hr Always wanted 1-2 months; mostly methodology
Subdomain takeover / cloud misconfig $100-$5k wildly variable Saturated by automation Days; automate or skip
SSRF / cloud metadata $500-$25k+ $150-$400/hr Perennial 1-3 months
OAuth / SSO / SAML $1k-$50k $200-$500/hr when found Specialist Steep; needs careful spec reading
Source-aided / invited audits $1k-$50k+ $200-$500/hr Invite-only Earn it on public programs first
Web3 / smart contracts $1k-$10M $200-$1000/hr top tier Strong demand, top auditors scarce 6-12 months serious study: Solidity, EVM, Foundry, Slither
Browser exploits $30k-$250k+ n/a — long projects Tiny supply Years; sandbox + v8/SpiderMonkey internals
Mobile OS exploits $200k-$2M n/a — long projects Tiny supply Years; only worth it for full chains
Hardware / firmware $5k-$200k $100-$500/hr Niche Months; needs hardware + JTAG + glitching
AI/LLM (applied AppSec angle) $500-$30k $100-$300/hr Booming, undersupplied 2-4 months on top of a solid web-app base

The AI/LLM line above is the income-realistic take. The "win the universal-jailbreak prize" line is closer to a contest payout than a steady stream.

#5. Realistic Income Data

Public sources: HackerOne's Hacker-Powered Security Report (7th edition, 2023-2024 data), Bugcrowd's Inside the Mind of a Hacker reports, and Immunefi's annual web3 bug bounty stats.

Cohort Annual gross
Casual hunter (10 hours/week or less) $0-$5k most never get a valid first bug
Active hunter (10-20 hours/week, year one) $3k-$15k
Year-two specialist $20k-$60k
Top 1% on a platform $150k-$500k
Top 10 globally across all platforms (roughly 50 people total) $500k-$3M+
Top web3 auditors (handful) $1M-$10M+ in a single payout year

Median for active hunters is widely cited as roughly $0. Most reports submitted are duplicates, informational, or N/A. Among hunters who get even one bug paid in a year, the median is closer to $1k-$3k. The mean is dragged up by a tiny number of full-timers.

Going full-time before you have roughly $80k in trailing-12-month earnings is a budget-killer. The income variance is the real story: 6-month droughts between $40k criticals are routine.

Public earners worth following (their writeups, not their dollar figures, are what matters):

#6. Workflow and Tools

Brief, since you live in Linux. Treat the BlackArch laptop as the bounty rig; keep BB recon out of ~/dev/ and into a separate ~/recon/ or ~/ops/<program>/ tree with strict per-program directories so scope mistakes cannot happen.

#Recon stack

#Proxies

  • Burp Suite Professional $475/yr, still the industry standard. Required for any program that uses session replay.
  • Caido fast-growing Rust-based competitor with much nicer UX; free tier covers most work. Pair with Burp; do not replace yet.

#Smart contracts

#Mobile

#Cloud

#AI-product testing

#Pipelines

  • Axiom distribute recon to spot VMs
  • Trickest visual recon workflows, generous free tier

#7. Reporting and Comms

Quality dominates quantity. A high-signal hunter sends fewer than five reports a week; a low-signal hunter sends fifty. Triagers remember both.

A great report has:

  1. One-line summary (severity + asset + bug class)
  2. CVSS v3.1 vector (or the platform's own VRT / severity mapping)
  3. Steps to reproduce minimal, copy-pasteable, no marketing
  4. Proof of concept curl-able, or a short video; strip credentials
  5. Impact what an attacker actually achieves, with realistic preconditions
  6. Recommended fix short, does not say "use a WAF"
  7. References OWASP, CWE, your own prior writeups

Severity disputes: programs use CVSS but most weight business impact. Lead with impact and the score follows. Bugcrowd uses its VRT; learn the categories before submitting.

Triage SLAs (approx):

  • HackerOne managed: 1-3 business days first response
  • Bugcrowd managed: 1-5 business days
  • Intigriti: 1-2 days
  • Immunefi: 1-7 days (a Slack/Discord war room appears for criticals)
  • Self-managed programs: anywhere from hours to weeks

Duplicates are the dominant negative outcome for new hunters. Two mitigations: pick low-traffic asset classes, and report fast (within hours of discovery).

Disclosure-agreement risk is real: some programs change scope or rewards retroactively. Screenshot the policy on submission and save the rules / scope page.

#8. Reputation and Status Building

  • Leaderboards hackerone.com/leaderboard, Bugcrowd's MVP rankings, Immunefi's Hall of Fame. Top-100 is realistic in 2-3 years for a strong hunter. Top-10 is a full-time job.
  • Live Hacking Events (LHEs) H1's flagship invite-only on-site events (often in Las Vegas, Amsterdam, Tokyo) with six-figure event purses, two-day hack windows, plus the only place you will meet the other hunters. Bugcrowd runs equivalents. Earning an LHE invite is the first major status step.
  • Public disclosure every report H1/Bugcrowd resolves can be requested for public disclosure. A polished writeup on your own site (krisyotam.com slot looks ideal) becomes recruiting bait.
  • Twitter/X + Bluesky + Mastodon the BB community is still mostly on X. Following and posting concise findings is how new programs notice you.
  • Speaking DEF CON AI Village, BSides anywhere, LASCON, Hexacon, Insomni'hack, OffensiveCon. Talks get you onto private programs.

#9. Tax and Business Setup (US)

Cross-link: see ./pentest.md business-entity section for the longer treatment shared with consulting income.

  • BB income is 1099-NEC (or 1099-MISC for older platforms). PayPal/Coinbase payouts still generate 1099-Ks at $600+.
  • Self-employment tax = 15.3% on top of income tax (Social Security 12.4% to the cap + Medicare 2.9%).
  • LLC pass-through is fine until roughly $60-100k of profit; at that point an S-corp election (form 2553) lets you split into reasonable salary + distributions and save roughly 7-8% in SE tax. Get a CPA; the worst-case downside is IRS reclassification.
  • Quarterly estimated taxes due Apr 15, Jun 15, Sep 15, Jan 15. Use IRS Direct Pay.
  • Payment methods by platform: HackerOne (PayPal, Coinbase, Hyperwallet bank, Payoneer), Bugcrowd (PayPal, Payoneer, US bank), Intigriti (SEPA, Wise), YesWeHack (SEPA, bank wire), Immunefi (USDC on-chain or bank, KYC above thresholds), Synack (1099 + bank). Crypto payouts have their own basis-tracking burden; log every payout date and USD value at receipt.
  • DOJ 2022 policy update on CFAA press release good-faith research is no longer prosecuted under CFAA. This is a policy, not law; state laws still apply.
  • Always verify scope on the day you test. Programs edit scope quietly.
  • DMCA section 1201 still bites on circumvention of access controls in research that is not covered by the security-research exemption (renewed every three years). Mobile / firmware reverse-engineering lives here; check the current exemption text.
  • Out-of-scope discoveries if you find something on a target's infra that is not covered, the right play is coordinated disclosure through their security.txt or the CISA CVD process, not a bounty submission and not a tweet.
  • Never test production without explicit authorization. A security.txt pointing to HackerOne is not authorization for adjacent infra. Read every program's "Targets in Scope" list and stop at the boundary.
  • Safe Harbor language in program rules: read it. Real safe harbor names CFAA + DMCA + state computer-crime statutes. Vague "we will not sue" language is worth less.
  • VPN + dedicated machine. The BlackArch laptop already does the second; pin a paid VPN (Mullvad / IVPN) for the first. Some programs require US-only or geo-restricted source IPs; respect them or your reports get tossed.

#11. Concrete 12-Month Plan

A specific schedule that fits an OSCP-track schedule in parallel (see pentest.md for the cert side).

#Months 1-3 — Foundation

  • Finish PortSwigger Web Security Academy start to finish (the apprentice + practitioner labs). It is free and it is the canonical curriculum.
  • Set up the BlackArch laptop's recon stack (section 6) in ~/ops/. Write a small shell wrapper that takes a program slug and scaffolds ~/ops/<program>/{scope,recon,notes,reports}.
  • Pick two public programs on Bugcrowd / HackerOne with broad scope and high signal-to-noise, usually big SaaS vendors with subdomain wildcards. Submit ten reports. Expect 6-8 dupes and 1-2 paid lows. This is normal.
  • Read The Web Application Hacker's Handbook 2e chapters 4, 7, 9, 12, 13 in parallel with the labs.

#Months 4-6 — Specialize

You have two strong lanes given your background.

  1. AI/LLM applied AppSec OpenAI (Bugcrowd), Anthropic (H1), Microsoft Copilot, Google AI VRP. Read OWASP LLM Top 10 + ATLAS, then hunt the AppSec surface (auth, IDOR, SSRF in tools, RAG leakage) on these targets. This compounds with your math/Python.
  2. Smart-contract auditing on Immunefi + Sherlock work through Cyfrin Updraft and Secureum bootcamp materials. Do one Code4rena or Sherlock contest a month even if you score zero, the post-mortem reading is the real curriculum. This is the higher-payout lane.

Pick one. Doing both halfway is worse than doing one fully.

#Months 7-9 — Depth + relationships

  • Target one program deeply. Build a recon-and-monitoring pipeline for it: weekly subdomain diff, JS-file diff, new-route diff. The 80/20 of finding criticals is being on the new attack surface first.
  • Publish two writeups on krisyotam.com (cross-link from this doc). One technical, one methodology.
  • Get on the program's Discord / Slack if they have one. Talk to triagers, humanise yourself. This becomes invite paths.
  • Submit to the DEF CON AI Village CFP or a BSides talk. Even a rejected CFP gets read.

#Months 10-12 — Scale or invite

  • If AI/LLM lane: aim for an Anthropic or Microsoft Copilot invite-only / private scope. Anthropic in particular has invited steady reporters into expanded scope.
  • If smart-contracts lane: aim for a top-3 finish in one Sherlock or Code4rena contest, or land a Cantina solo audit invite.
  • Either way: apply to a Live Hacking Event. HackerOne LHE applications happen rolling.
  • Honest 12-month income target for a half-time hunter on this plan: $15k-$50k all-in. Hitting top-1% in year one is a fantasy; year three is realistic.

#References