🐛 Bug Bounty Programs

Security researchers get paid for finding vulnerabilities in software, websites, and apps. Browse 460 active opportunities below.

✦ Get AI-Matched
Bug bounty programs pay security researchers — from beginners to elite hackers — to find and responsibly disclose security vulnerabilities before malicious actors can exploit them. Companies like Google, Apple, Meta, Microsoft, and hundreds of startups and government agencies run public programs that accept submissions from anyone, with rewards ranging from $100 for low-severity issues to $1,000,000+ for critical vulnerabilities. Unlike traditional employment, bug bounty hunting lets you work independently on your own schedule, choosing programs that match your skills and interests.
Bug Bounty Programs (460 active — showing top 30 of 460)
Apple Security Bounty — Up to $2,000,000 ($5M+ with bonuses) $2,000,000

Apple doubled its top reward to $2 million for zero-click exploit chains capable of achieving goals similar to sophisticated mercenary spyware. Bonus categories…

Bug Bounty Online
Google Android & Devices VRP — Up to $1,500,000 $1,500,000

Google's Android and Devices Vulnerability Reward Program pays up to $1.5 million for zero-click exploit chains targeting the Titan M security chip on Pixel dev…

Bug Bounty Online
Samsung Mobile Security Rewards $1,000,000

Rewards for critical vulnerabilities in Samsung Galaxy devices and services.

Bug Bounty Online
Microsoft Bug Bounty — Up to $250,000 $250,000

Microsoft's Security Response Center runs bounty programs across Azure, Microsoft 365, Hyper-V, Windows, and Dynamics, with top awards around $250,000 for criti…

Bug Bounty Online
Google Cloud VRP — Up to $101,010 $101,010

Google's Cloud Vulnerability Reward Program offers a top award of $101,010 for the highest-impact vulnerabilities in Google Cloud products. The program covers a…

Bug Bounty Online
Intel Bug Bounty $100,000

Bounties for hardware, firmware, and software vulnerabilities in Intel products.

Bug Bounty Online
Sony PlayStation Bug Bounty $50,000

Sony's PlayStation bug bounty (via HackerOne) rewards researchers for vulnerabilities in PlayStation systems, with top rewards exceeding $50,000.

Bug Bounty National
PayPal Bug Bounty $30,000

PayPal's bug bounty (via HackerOne) rewards researchers for security vulnerabilities across its payment platforms.

Bug Bounty National
GitHub Security Bug Bounty $30,000

Bounties for vulnerabilities in GitHub products and infrastructure.

Bug Bounty Online
GitLab Bug Bounty $20,000

GitLab runs a public bug bounty (via HackerOne) rewarding researchers for vulnerabilities in GitLab products.

Bug Bounty National
Mozilla Security Bug Bounty $20,000

Mozilla pays bounties for security vulnerabilities in Firefox and its services, with high-impact bugs earning the top rewards.

Bug Bounty National
Tesla Bug Bounty $15,000

Tesla's bug bounty (via Bugcrowd) rewards researchers for vulnerabilities in its vehicles, apps, and infrastructure.

Bug Bounty National
redstorm.io — Security Bug Bounty Cash bounty — amount varies by severity

redstorm.io runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash rewar…

Bug Bounty Online
intl.nothing.tech — Security Bug Bounty Cash bounty — amount varies by severity

intl.nothing.tech runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash…

Bug Bounty Online
Latent Patterns — Security Bug Bounty Cash bounty — amount varies by severity

Latent Patterns runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash r…

Bug Bounty Online
Rujira Security Audit $40,000 USDC prize pool (USDC = USD 1:1). Pool is split among auditors who find valid vulnerabilities.

Code4rena competitive security audit: Rujira Security Audit. $40,000 USDC prize pool (USDC = USD 1:1). Pool is split among auditors who find valid vulnerabiliti…

Bug Bounty National
K2 Security Audit $135,000 USDC prize pool (USDC = USD 1:1). Pool is split among auditors who find valid vulnerabilities.

Code4rena competitive security audit: K2 Security Audit. $135,000 USDC prize pool (USDC = USD 1:1). Pool is split among auditors who find valid vulnerabilities.…

Bug Bounty National
Code4rena — Smart Contract Security Audit Competitions Prize pools $4,000–$300,000+ USDC per audit. Pool divided among auditors with valid findings. Top wardens earn $50K–$200K+ per year.

Code4rena hosts competitive smart contract security audits where independent security researchers ('wardens') compete to find vulnerabilities in Web3 protocols.…

Bug Bounty National
Halodoc — Security Bug Bounty Cash bounty — amount varies by severity

Halodoc runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; p…

Bug Bounty Online
zkSync — Security Bug Bounty Cash bounty — amount varies by severity

zkSync runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; pa…

Bug Bounty Online
web3 foundation — Security Bug Bounty Cash bounty — amount varies by severity

web3 foundation runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash r…

Bug Bounty Online
szns — Security Bug Bounty Cash bounty — amount varies by severity

szns runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; payo…

Bug Bounty Online
rockset — Security Bug Bounty Cash bounty — amount varies by severity

rockset runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; p…

Bug Bounty Online
reportgarden — Security Bug Bounty Cash bounty — amount varies by severity

reportgarden runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash rewa…

Bug Bounty Online
ownCloud — Security Bug Bounty Cash bounty — amount varies by severity

ownCloud runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward;

Bug Bounty Online
inDrive — Security Bug Bounty Cash bounty — amount varies by severity

inDrive runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; p…

Bug Bounty Online
iRobot — Security Bug Bounty Cash bounty — amount varies by severity

iRobot runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; pa…

Bug Bounty Online
dropbox — Security Bug Bounty Cash bounty — amount varies by severity

dropbox runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; p…

Bug Bounty Online
dfuse Platform — Security Bug Bounty Cash bounty — amount varies by severity

dfuse Platform runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash re…

Bug Bounty Online
cPanel — Security Bug Bounty Cash bounty — amount varies by severity

cPanel runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; pa…

Bug Bounty Online
How to earn a bug bounty reward
  1. Choose a program that matches your security specialization — web application vulnerabilities, mobile apps, APIs, cryptography, or hardware. Review the scope carefully to understand what is in and out of bounds.
  2. Set up a safe testing environment. Never test directly on production systems without explicit authorization. Use the program's sandbox or staging environments when available.
  3. Find a qualifying vulnerability through ethical testing. Common findings include SQL injection, cross-site scripting (XSS), authentication bypass, insecure direct object references (IDOR), and remote code execution (RCE).
  4. Write a clear, detailed proof-of-concept report. Include steps to reproduce, the potential impact, affected endpoints, and any screenshots or video demonstrations. Quality reports get triaged and paid faster.
  5. Submit through the platform (HackerOne, Bugcrowd, Intigriti, Immunefi, etc.) and wait for triage — typically 1–14 days. Respond promptly to any questions from the security team.
  6. Receive your payment once the vulnerability is confirmed and patched, typically within 30–90 days. Many platforms offer immediate partial payment after triage.
Frequently Asked Questions
Do I need to be a professional hacker to earn bug bounties?+
No. Many bug bounty hunters are self-taught security enthusiasts, developers, or students. Platforms like HackerOne and Bugcrowd have beginner-friendly programs. Start with programs that have broad web application scope, practice on platforms like HackTheBox or TryHackMe, and work your way up to higher-value targets.
How much can I earn from bug bounty programs?+
Earnings vary widely. Beginner researchers commonly earn $500–$5,000/month from part-time hunting. Full-time top earners make $200,000–$500,000/year. Critical vulnerabilities in major programs like Google or Apple can pay $100,000–$1,000,000 per report. The Immunefi platform lists crypto programs with bug bounties up to $15 million.
Are bug bounty earnings taxable?+
Yes. In the United States, bug bounty payments are generally treated as self-employment income and are subject to federal income tax and self-employment tax. Platforms will often issue a 1099 form if you earn over $600 in a year. Keep records of all submissions and payments.
What is the difference between private and public bug bounty programs?+
Public programs are open to all researchers and are listed publicly. Private programs are invitation-only, typically reserved for researchers with proven track records. Most platforms let top performers graduate from public to private programs, which often have higher payouts and less competition.
Which bug bounty platforms pay the most?+
Immunefi (crypto/Web3 programs, up to $15M per bug), HackerOne (Google, Apple, DoD programs), Intigriti (European programs including Intel $100K, AMD $30K), Bugcrowd, and YesWeHack are the leading platforms. Government programs via the DoD Vulnerability Disclosure Program also pay competitively.

Want personalized matches?

Our AI ranks all 460 bug bounty programs — plus every other category — by how well each fits your profile, location, and background.

Get My Match Report