Skip to content
Tech News
← Back to articles

What Happened to HackerOne?

read original more articles
Why This Matters

The article highlights concerns about HackerOne's current state, reflecting on its origins as a secure platform that fostered ethical hacking and bug bounty programs. Its evolution and potential issues are significant for both the tech industry and consumers, as they impact cybersecurity practices and the integrity of vulnerability disclosure. Understanding these changes is crucial for stakeholders relying on bug bounty platforms for security assurance.

Key Takeaways

So…what’s going on at HackerOne lately? It might be time for a wellness check.

If you are new to the bug bounty space (1-3 years), you might not have any idea what I’m talking about.

But as a properly washed-up bug bounty hunter who lived through the golden era of HackerOne, I think it’s time to address the elephant in the room.

For some context, I started as a hacker on HackerOne in 2017. When I began working in tech, that hands-on experience was extremely useful for managing a bug bounty program, since I knew what researchers wanted, and how to interact with them.

As a result, I have managed multiple large bug bounty programs on HackerOne across various companies from 2018 to 2025 and I’ve been on both sides of the equation.

What I’m about to talk about comes from first-hand experience, both as a researcher and as a bug bounty program manager, and many, many years of direct conversations with HackerOne, both publicly and privately.

To start, I think it’s important to realize what HackerOne was originally designed to be.

In 2011, two ethical hackers, Jobert Abma and Michiel Prins, set out to find security vulnerabilities in 100 of the largest tech companies. They succeeded and found bugs in Google, Facebook, Apple, Microsoft, Twitter, and many others. At this point in time, the landscape for ethical security research was risky, legally dubious, and very scary for security researchers.

Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this. Much of this was due to specific arbitrary lines drawn in the sand which, if crossed, made you a bad actor, but if not crossed, made you a potentially bad actor but technically not one.

Bug Bounty Platforms like HackerOne were designed to directly address this issue. It created a safe mutual space for companies and hackers to connect, and it paved the way for ethical hackers to submit security vulnerabilities to companies, with full consent, and get paid for that work. This was a huge milestone. You no longer had to worry about getting dragged to court (or jail) for finding an IDOR that leaked customer data. Instead, you got a “thank you” and a cash payout for making everyone a little safer.

... continue reading