Facing an embarrassing situation, HackerOne, which is a bug bounty platform that boasts clients including Starbucks, Instagram, Goldman Sachs, Twitter , and Zomato, paid $20,000 to a user who exposed a vulnerability in its platform.
“A hacker briefly had access to information about other programs running on the HackerOne platform.

“Less than 5% of HackerOne programs were affected, and those programs were contacted within 24 hours of receiving the report,” HackerOne said in a statement this week. The hacker and HackerOne community member posted a report on the Bug Bounty platform: “I can read all @security reports and more programs.”
HackerOne responded: “We did not consider it necessary for you to have opened all the reports and pages to confirm that you had access to the account. Would you mind explaining why you did this to us?”
Haxta4ok00 said: “I did it to show the impact, I didn’t mean to cause any harm, I reported it to you right away and I wasn’t sure that after replacing the token I would have all the rights. I apologize if I did something wrong, but it was just a white hack.”
In August this year, HackerOne revealed that hackers earned $ in just one year by reporting vulnerabilities through various bug bounty opportunities, as government efforts to fix malware increased by 214% globally. Food delivery platform Zomato has paid more than $100,000 to 435 hackers to date for finding and fixing bugs in its platform.
With the help of HackerOne's bug bounty program since July 2017, Zomato has successfully resolved 775 vulnerability. Hacker-powered security is a technique that uses collaboration with the hacker community to identify unknown security and reduce risk . Popular examples include programs and vulnerability disclosure policies.
