🐛 Bug Bounty Programs
Security researchers get paid for finding vulnerabilities in software, websites, and apps. Browse 460 active opportunities below.
✦ Get AI-MatchedApple doubled its top reward to $2 million for zero-click exploit chains capable of achieving goals similar to sophisticated mercenary spyware. Bonus categories…
Google's Android and Devices Vulnerability Reward Program pays up to $1.5 million for zero-click exploit chains targeting the Titan M security chip on Pixel dev…
Rewards for critical vulnerabilities in Samsung Galaxy devices and services.
Microsoft's Security Response Center runs bounty programs across Azure, Microsoft 365, Hyper-V, Windows, and Dynamics, with top awards around $250,000 for criti…
Google's Cloud Vulnerability Reward Program offers a top award of $101,010 for the highest-impact vulnerabilities in Google Cloud products. The program covers a…
Bounties for hardware, firmware, and software vulnerabilities in Intel products.
Sony's PlayStation bug bounty (via HackerOne) rewards researchers for vulnerabilities in PlayStation systems, with top rewards exceeding $50,000.
PayPal's bug bounty (via HackerOne) rewards researchers for security vulnerabilities across its payment platforms.
Bounties for vulnerabilities in GitHub products and infrastructure.
GitLab runs a public bug bounty (via HackerOne) rewarding researchers for vulnerabilities in GitLab products.
Mozilla pays bounties for security vulnerabilities in Firefox and its services, with high-impact bugs earning the top rewards.
Tesla's bug bounty (via Bugcrowd) rewards researchers for vulnerabilities in its vehicles, apps, and infrastructure.
redstorm.io runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash rewar…
intl.nothing.tech runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash…
Latent Patterns runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash r…
Code4rena competitive security audit: Rujira Security Audit. $40,000 USDC prize pool (USDC = USD 1:1). Pool is split among auditors who find valid vulnerabiliti…
Code4rena competitive security audit: K2 Security Audit. $135,000 USDC prize pool (USDC = USD 1:1). Pool is split among auditors who find valid vulnerabilities.…
Code4rena hosts competitive smart contract security audits where independent security researchers ('wardens') compete to find vulnerabilities in Web3 protocols.…
Halodoc runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; p…
zkSync runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; pa…
web3 foundation runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash r…
szns runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; payo…
rockset runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; p…
reportgarden runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash rewa…
ownCloud runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward;
inDrive runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; p…
iRobot runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; pa…
dropbox runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; p…
dfuse Platform runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash re…
cPanel runs a public bug bounty program. Report qualifying security vulnerabilities through their published security policy or contact to earn a cash reward; pa…
- Choose a program that matches your security specialization — web application vulnerabilities, mobile apps, APIs, cryptography, or hardware. Review the scope carefully to understand what is in and out of bounds.
- Set up a safe testing environment. Never test directly on production systems without explicit authorization. Use the program's sandbox or staging environments when available.
- Find a qualifying vulnerability through ethical testing. Common findings include SQL injection, cross-site scripting (XSS), authentication bypass, insecure direct object references (IDOR), and remote code execution (RCE).
- Write a clear, detailed proof-of-concept report. Include steps to reproduce, the potential impact, affected endpoints, and any screenshots or video demonstrations. Quality reports get triaged and paid faster.
- Submit through the platform (HackerOne, Bugcrowd, Intigriti, Immunefi, etc.) and wait for triage — typically 1–14 days. Respond promptly to any questions from the security team.
- Receive your payment once the vulnerability is confirmed and patched, typically within 30–90 days. Many platforms offer immediate partial payment after triage.
Want personalized matches?
Our AI ranks all 460 bug bounty programs — plus every other category — by how well each fits your profile, location, and background.
Get My Match Report