
Have you ever wondered how much money hackers and security by reporting security holes and software bugs? For some, detecting vulnerabilities in websites and applications is a challenge , while for others it is a significant source of income. In recent years, more and more companies have been paying hackers to search for security holes in software and services. This process is known as “bug bounty programs.”
Companies announce their programs and ask hackers to try to find bugs, in exchange for large sums of money (usually determined by the severity of the bug). In this way, organizations strengthen their security.
HackerOne , which runs bug bounty programs for organizations such as the U.S. Department of Defense and Google , has released new data on the number of vulnerabilities found by hackers (who have signed up for its projects) and the amount of money they have received. According to HackerOne, more than 181,000 vulnerabilities and more than $100 million has been given out. have been reported
The company said that last year it gave away more than $44.75 million to hackers around the world who participated in bug bounty programs. That was an 86% increase from the previous year . Most of the money went to bug bounty programs run by U.S. organizations .
Some bugs can bring big rewards to hackers
According to HackerOne, the average amount paid for detecting critical vulnerabilities has reached $3,650, while the average amount paid per vulnerability is $979. Critical vulnerabilities make up about 8% of total reports, while reports for serious vulnerabilities account for 21%.
“Hacking . remains a steady source of income for some hackers,” the platform says. Nearly nine in ten are under 35, and one in five say hacking activities are their sole source of income

Millionaires from… bug bounty programs
Over the past 10 years, nine hackers have raised over $1 million through their participation in HackerOne’s bug bounty programs. This shows that finding and reporting vulnerabilities can be very profitable. Also, over 200 hackers have earned more than $100,000, and 9,000 hackers have earned “at least something.” Finally, half of the hackers who have found at least one vulnerabilityhave earned $1,000 or more.
As we said above, for many hackers, finding bugs is a challenge. They are not so interested in the money. The skills they learn can benefit their careers. Four out of five said they want to use the knowledge they gain for a job.
According to ZDNet, COVID-19 has led to an increase in attacks on organizations and companies. However, there has also been an increase in hackers wanting to help by identifying and fixing bugs that could be exploited by cybercriminals . During this time, registrations by hackers in bug bounty programs have increased by 59% and vulnerability reports have increased by 28%.
