This is the platforms-and-programs side. The cert track, formal pentesting employment, OSCP/OSWE/OSEP planning, and Synack Red Team vetting live in ./pentest.md. Read that first if you want the career-path angle; this document assumes you already know what XSS and a reverse shell are.
| Platform | Founded | Model | Median public bounty | Top single payout (public) | Notes |
|---|---|---|---|---|---|
| HackerOne | 2012 | Public + private + managed | ~$500 (web), ~$2.5k (high) | $1M+ (Google/Apple chains via H1-managed) | Biggest brand. Live Hacking Events (LHEs). Best AI/LLM crossover. |
| Bugcrowd | 2012 | Public + private + managed (VRT-graded) | ~$400 | ~$200k (Tesla/automotive) | Hosts OpenAI, Tesla, Atlassian. CrowdMatch invites. |
| Intigriti | 2016 | Public + private | €500 median | €100k+ (EU OSS bounties) | EU-headquartered (Belgium). Hosts EU-funded OSS programs. Triage reputation is the strongest of the big-four. |
| YesWeHack | 2015 | Public + private | €300-€500 | €50k+ | EU/Asia/MEA. Strong in finance + telco in France, Singapore, Germany. |
| Synack Red Team | 2013 | Vetted private only | hourly + bounty hybrid | n/a public | Application + skills test + background check. See pentest.md SRT section. |
| Immunefi | 2020 | Web3 / smart contracts | $1k-$10k typical | $10M (Wormhole, capped) | Highest absolute payouts in the industry. ~90% of top web3 bounties live here. |
| Cantina | 2023 | Web3 audits + competitive contests | varies | $500k+ contest pots | Spearbit's competitive arm. Solo bounties + crowd audits. |
| Code4rena | 2021 | Web3 competitive audit contests | n/a (contest pots) | $1M+ pots | Contest-style; you compete with other auditors, payouts split by severity weighting. |
| Sherlock | 2022 | Web3 contests + coverage | n/a (contest pots) | $1M+ pots | Insurance-backed audit contests; Watson rank system. |
| HackenProof | 2017 | Public + web3 | $500-$5k | ~$1M | Eastern-European origin, growing web3 share. |
| Federacy | 2016 | Public/private | Low | Low | Small program list; mostly startups. Worth a skim, not a primary platform. |
| Open Bug Bounty | 2014 | Non-paid coordinated disclosure | $0 | $0 | Reputation-only. Useful for first-time CVE-ish writeups, not income. |
Ranking for a serious researcher in 2026:
| Program | Platform / URL | Scope highlights | Typical range | Top tier | Notes |
|---|---|---|---|---|---|
| Apple Security Bounty | security.apple.com/bounty | iOS/macOS/iCloud/Secure Enclave | $5k-$250k | $2M for full zero-click iOS chain with persistence | Slow triage, world-class engineers reviewing. |
| Google VRP | bughunters.google.com | All Google products | $100-$31,337 | $605k+ paid for Android chains | Fast-ish triage; very clear severity guide. |
| Chrome VRP | g.co/chrome/vrp | Chromium renderer/sandbox/IPC | $500-$250k | $250k for sandbox escape full chain | Memory-safety bug heaven; Rust folks have an edge. |
| Android Security Rewards | bughunters.google.com | AOSP, Pixel, Tensor | $500-$1M | $1M Pixel TEE | Hardware + kernel skills required for top tier. |
| Microsoft Bug Bounty | microsoft.com/msrc/bounty | Azure, M365, Identity, Copilot, Windows insider | $500-$250k | $250k Hyper-V | Different sub-programs per product; read each carefully. |
| Meta Bug Bounty | bugbounty.meta.com | FB / IG / WhatsApp / Quest / Llama | $500-$300k | $300k+ chains | Source-code-aided research for invited researchers. |
| Amazon VRP | hackerone.com/amazonvrp | AWS, retail, devices, Alexa | $100-$25k | varies | AWS-side has its own program at aws.amazon.com/security/vulnerability-reporting. |
| OpenAI | bugcrowd.com/openai | API, ChatGPT, plugins, infra | $200-$6.5k typical | $20k+ for critical infra | See section 3. Model jailbreaks are OUT of scope. |
| Anthropic | hackerone.com/anthropic plus separate model-safety program | Claude API, claude.ai, infra | $1k-$15k | $30k+ via separate model-safety program | Two-program structure: classical AppSec on H1, model-safety/universal-jailbreak elsewhere (see section 3). |
| GitHub | hackerone.com/github | github.com, Actions, Codespaces | $617-$30k+ | $30k+ | Long-running, top-tier reputation. |
| GitLab | hackerone.com/gitlab | gitlab.com + self-managed | $1k-$35k | $35k+ | Generous on auth/RCE. |
| PayPal | hackerone.com/paypal | Payments, Braintree, Venmo | $50-$30k | $30k+ | Fast triage, picky on impact. |
| Stripe | bugcrowd.com/stripe | All Stripe surface | $500-$30k | $30k+ | Tight scope, high quality bar. |
| Square / Block | hackerone.com/block | Cash App, Square, Tidal | $100-$25k | $25k+ | |
| Uber | hackerone.com/uber | rider, driver, eats, freight, infra | $500-$50k | $50k+ | Mature program; lots of duplicate noise. |
| Shopify | hackerone.com/shopify | shop.app, admin, apps | $500-$50k | $50k+ | Famous LHE host. Strong reputation rewards. |
| Cloudflare | hackerone.com/cloudflare | edge, Workers, Zero Trust | $250-$10k+ | varies | Workers/Pages bugs pay well. |
| Tesla | bugcrowd.com/tesla | Vehicles, app, energy, infra | $100-$200k | $200k+ for vehicle CAN/infotainment | Pwn2Own automotive parity. |
| US DoD (Hack the Pentagon) | hackerone.com/deptofdefense | .mil + DoD vendors (varies by event) | $0-$25k | $25k for select events | Most engagements pay; the public VDP does not. Prestige + clearance signal. |
| EU OSS (intigriti-hosted) | intigriti.com/programs | Drupal, Mastodon, FileZilla, etc. | €500-€10k | €25k+ | EU Commission funds bounties on critical OSS. |
| Wormhole (Immunefi) | immunefi.com/bug-bounty/wormhole | Cross-chain bridge | $50k-$2.5M | $10M cap | One of the largest live bounties on earth. |
| Aave (Immunefi) | immunefi.com/bug-bounty/aave | DeFi lending | $10k-$1M | $1M+ | |
| MakerDAO / Sky (Immunefi) | immunefi.com/bug-bounty/makerdao | DAI/USDS stablecoin | $10k-$10M | $10M cap | |
| Optimism (Immunefi) | immunefi.com/bug-bounty/optimism | L2 rollup | $50k-$2M+ | $2M+ | |
| Arbitrum (Immunefi) | immunefi.com/bug-bounty/arbitrum | L2 rollup | $10k-$2M | $2M+ | |
| Polygon (Immunefi) | immunefi.com/bug-bounty/polygontechnology | PoS, zkEVM | $10k-$2M | $2M+ |
Time-to-pay reputation (broadly): GitHub, Shopify, Stripe, GitLab fast. Apple, Google, Microsoft slow but reliable. Tesla, Uber variable. Immunefi top programs pay within 2-8 weeks of fix deploy; KYC required above roughly $10k.
This is your declared niche, so it gets a real treatment. The most important framing: classical AppSec bugs in AI products pay far better than novel alignment attacks. A prompt injection that exfiltrates another user's chat history via the plugin sandbox is an IDOR + SSRF story dressed in LLM clothing, and it pays IDOR + SSRF money, not "interesting paper" money.
| Program | URL | What pays | What does not |
|---|---|---|---|
| OpenAI | bugcrowd.com/openai | API auth/authz, infra RCE/SSRF, plugin/connector escapes, sandbox bypasses, account takeover, IDOR on chat/file resources, privilege escalation in Operator/Codex/Atlas, billing tampering | Model jailbreaks, prompt injections producing disallowed content, hallucinations, factual errors, model-safety / alignment issues explicitly out of scope of the paid program. OpenAI routes those through a separate (mostly non-monetary) model-vulnerability reporting form. Typical critical payouts: $6.5k-$20k. |
| Anthropic classical | hackerone.com/anthropic | API/web/infra bugs in claude.ai, console, integrations | Same exclusions as above (jailbreaks, refusal-evasion). |
| Anthropic model safety | Separate invite/contest programs (e.g. universal-jailbreak prizes, constitutional-classifier challenges) | Universal jailbreaks of specific safeguards, with reproduction recipe | One-off contests; not a steady income. |
| Google (Bard/Gemini under VRP + AI VRP) | bughunters.google.com (see AI rules) | Account takeover, data exfiltration via Workspace/Drive Gemini integration, prompt-injection-led data leaks, model theft, training data leakage | Pure refusal-evasion ("I made it curse"). |
| Microsoft Copilot | microsoft.com/msrc/bounty-microsoft-ai | Copilot for M365/Edge/Windows, including indirect prompt injection that leads to data exfiltration. Critical: $20k-$30k+ | Hallucinations, "uncomfortable" content, low-impact prompt injection. |
| xAI / Grok | hackerone.com/x covers X + Grok | Account takeover via Grok integrations, training-data leakage, RCE | Jailbreaks. |
| Hugging Face | huggingface.co/security (private, request invite) | Account takeover, model-card XSS, Spaces sandbox escape, dataset poisoning vectors | Public AI-hub triage is faster than the giants. |
| Meta / Llama | bugbounty.meta.com | All FB/IG/Llama infra; Llama Guard bypasses with impact | Pure jailbreaks. |
| Replicate, Together.ai, Fireworks, Perplexity, Mistral | Bug-bounty pages on company sites or security.txt of each | RCE in inference sandbox, billing/abuse, account takeover | Smaller payouts ($500-$5k typical), faster triage. |
Your math + Python + Rust profile is unusually well suited to the agent / tool-use surface. That is the lane.
| Specialization | Bug payout range | Realistic hourly when productive | Supply / demand | Ramp |
|---|---|---|---|---|
| Web app (classical OWASP) | $100-$5k | $50-$200/hr | Heavily saturated | 1-3 months from PortSwigger to first paid bug |
| Mobile (Android) | $500-$30k | $100-$300/hr | Moderate | 2-4 months: Frida, jadx, objection, Burp |
| Mobile (iOS) | $500-$50k+ | $150-$400/hr | Low supply | 4-8 months; needs jailbroken device or Corellium |
| API security | $250-$10k | $80-$250/hr | Growing | Easiest fast-win lane for newcomers |
| IDOR / access control | $250-$15k | $100-$300/hr | Always wanted | 1-2 months; mostly methodology |
| Subdomain takeover / cloud misconfig | $100-$5k | wildly variable | Saturated by automation | Days; automate or skip |
| SSRF / cloud metadata | $500-$25k+ | $150-$400/hr | Perennial | 1-3 months |
| OAuth / SSO / SAML | $1k-$50k | $200-$500/hr when found | Specialist | Steep; needs careful spec reading |
| Source-aided / invited audits | $1k-$50k+ | $200-$500/hr | Invite-only | Earn it on public programs first |
| Web3 / smart contracts | $1k-$10M | $200-$1000/hr top tier | Strong demand, top auditors scarce | 6-12 months serious study: Solidity, EVM, Foundry, Slither |
| Browser exploits | $30k-$250k+ | n/a — long projects | Tiny supply | Years; sandbox + v8/SpiderMonkey internals |
| Mobile OS exploits | $200k-$2M | n/a — long projects | Tiny supply | Years; only worth it for full chains |
| Hardware / firmware | $5k-$200k | $100-$500/hr | Niche | Months; needs hardware + JTAG + glitching |
| AI/LLM (applied AppSec angle) | $500-$30k | $100-$300/hr | Booming, undersupplied | 2-4 months on top of a solid web-app base |
The AI/LLM line above is the income-realistic take. The "win the universal-jailbreak prize" line is closer to a contest payout than a steady stream.
Public sources: HackerOne's Hacker-Powered Security Report (7th edition, 2023-2024 data), Bugcrowd's Inside the Mind of a Hacker reports, and Immunefi's annual web3 bug bounty stats.
| Cohort | Annual gross |
|---|---|
| Casual hunter (10 hours/week or less) | $0-$5k most never get a valid first bug |
| Active hunter (10-20 hours/week, year one) | $3k-$15k |
| Year-two specialist | $20k-$60k |
| Top 1% on a platform | $150k-$500k |
| Top 10 globally across all platforms (roughly 50 people total) | $500k-$3M+ |
| Top web3 auditors (handful) | $1M-$10M+ in a single payout year |
Median for active hunters is widely cited as roughly $0. Most reports submitted are duplicates, informational, or N/A. Among hunters who get even one bug paid in a year, the median is closer to $1k-$3k. The mean is dragged up by a tiny number of full-timers.
Going full-time before you have roughly $80k in trailing-12-month earnings is a budget-killer. The income variance is the real story: 6-month droughts between $40k criticals are routine.
Public earners worth following (their writeups, not their dollar figures, are what matters):
Brief, since you live in Linux. Treat the BlackArch laptop as the bounty rig; keep BB recon out of ~/dev/ and into a separate ~/recon/ or ~/ops/<program>/ tree with strict per-program directories so scope mistakes cannot happen.
Quality dominates quantity. A high-signal hunter sends fewer than five reports a week; a low-signal hunter sends fifty. Triagers remember both.
A great report has:
Severity disputes: programs use CVSS but most weight business impact. Lead with impact and the score follows. Bugcrowd uses its VRT; learn the categories before submitting.
Triage SLAs (approx):
Duplicates are the dominant negative outcome for new hunters. Two mitigations: pick low-traffic asset classes, and report fast (within hours of discovery).
Disclosure-agreement risk is real: some programs change scope or rewards retroactively. Screenshot the policy on submission and save the rules / scope page.
Cross-link: see ./pentest.md business-entity section for the longer treatment shared with consulting income.
security.txt or the CISA CVD process, not a bounty submission and not a tweet.security.txt pointing to HackerOne is not authorization for adjacent infra. Read every program's "Targets in Scope" list and stop at the boundary.A specific schedule that fits an OSCP-track schedule in parallel (see pentest.md for the cert side).
~/ops/. Write a small shell wrapper that takes a program slug and scaffolds ~/ops/<program>/{scope,recon,notes,reports}.You have two strong lanes given your background.
Pick one. Doing both halfway is worse than doing one fully.