Bug Bounty Program

Bug Bounty Program

A bug bounty program is a public offer made by a company: whoever finds a flaw in its software and reports it confidentially gets paid for it. This way, the company deliberately seeks outside help instead of waiting for criminals to discover the vulnerability first.

Every major piece of software contains bugs. Some of these bugs are dangerous because strangers can use them to get hold of passwords or account data. A bug bounty program is a company’s public promise to pay money for reported flaws of this kind. “Bug” is the English word for a defect and is the common term in computing for a programming error. “Bounty” means a reward or prize. So whoever finds a flaw must not exploit it or make it public, but instead reports it to the manufacturer and collects a payment for it.

Why companies invite strangers to attack their systems

A company can never fully test its own software by itself. The developers know their program too well and therefore think along the same lines as when they built it. Outsiders, on the other hand, try exactly the odd approaches that nobody inside thought of. A bounty program multiplies the number of eyes on the problem without having to hire a thousand people.

Behind this lies a simple calculation as well. A reward often costs a few thousand euros. A data leak involving millions of customer records costs fines, lawyers, and trust, and quickly runs into the millions. As long as the reward is clearly cheaper than the damage, the program is worthwhile.

The second reason is a race. For serious security vulnerabilities there is also a black market where criminals and intelligence agencies pay. Whoever offers nothing themselves automatically leaves finders to that side. An official program gives them a legal and more convenient path.

From report to payout

At the start there is a clear set of rules, called the scope. It states which websites, apps, and servers may be tested and which attacks remain forbidden. A test that takes down the company’s servers, for example, is almost always prohibited. Whoever sticks to the rules will not be reported. Whoever steps outside them makes themselves liable to prosecution.

If someone finds a flaw, they send in a report with instructions for reproducing it. A security team checks whether the bug is real and how severe it is. The reward is set accordingly. A cosmetic issue might bring in 100 euros, while a flaw granting full access to other people’s accounts could bring in several tens of thousands. Google and Apple have in individual cases paid six-figure sums.

The flaw is only disclosed once it has been fixed. This sequence is called responsible disclosure. It distinguishes a bug bounty program from a penetration test, where a company pays a security firm for a fixed period of time. With a bounty, you don’t pay for time worked, only for results.

Bounties in the news and online

Nearly all major technology companies run such programs, including Google, Microsoft, Apple, and Meta. They are often brokered through platforms like HackerOne or Bugcrowd, which collect reports and handle payments. Leaderboards have formed there, and some individual finders earn their living from it.

In the crypto world the sums involved are especially high. There, programs directly manage money, and a single flaw can immediately cost millions. Rewards of a million dollars or more have already occurred there.

New in this area is artificial intelligence. Chatbot providers now also pay for people finding ways to bypass the models' safety rules. In the news, bounties are usually reported in hindsight: a company states that a flaw was reported by an external researcher and has already been fixed. This is generally a good sign, since the alternative would have been an attacker finding it first.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.