Bug Bounty Platforms
Where to actually hunt: 35 curated platforms - crowdsourced, web3, private/vetted, pentest-as-a-service, disclosure and first-party vendor programs.
Bug Bounty Platforms index
- HackerOne - The largest program catalog - web, mobile, API, and increasingly AI/LLM scope. The default first stop for most hunters.
- Bugcrowd - Broad crowdsourced platform with a well-defined severity taxonomy and researcher-matching to private programs.
- Intigriti - Fast-growing European platform with strong enterprise and EU-government scope and an active researcher community.
- YesWeHack - European (EU-hosted, GDPR-aligned) platform with strong public programs and a built-in training ground.
- Immunefi - The dominant web3 bug bounty platform - DeFi, smart contracts, bridges, and protocols, with the largest single payouts in the industry.
- HackenProof - Web3-focused platform (part of Hacken) covering exchanges, chains, and dApps, plus some traditional web scope.
- Synack Red Team - Invite-only, vetted researcher network (SRT) running continuous testing on enterprise and government targets.
- Cobalt - Paid, time-boxed pentest engagements delivered by the vetted 'Cobalt Core' - closer to consulting than open bounty.
- Open Bug Bounty - Free, non-profit coordinated-disclosure platform for a narrow set of externally verifiable issues (XSS, etc.) on any website.
- Google Bug Hunters - Google's own VRP covering Google-owned web/apps, Chrome, Android, and open-source (OSS VRP). High payouts, deep single-target work.
- Microsoft MSRC - Microsoft's bounty programs - Azure, Windows, Microsoft 365, Dynamics, and dedicated AI/Copilot bounties.
- Apple Security Bounty - Apple's bounty across iOS/macOS and services, with very high payouts for high-impact chains and a research-device program.
- Meta Bug Bounty - Meta's program across Facebook, Instagram, WhatsApp, and their platforms/SDKs, including account-security and GraphQL-heavy surfaces.
- Yogosha - Invite-heavy European platform with private programs and pentest-style engagements. Less noisy than the big two.
- Huntr - Bounties on open-source repositories (now under Protect AI). Supply chain, RCE in libraries, ML/AI repos.
- GitHub Bug Bounty - github.com, GitHub Enterprise, Actions, Packages, auth. Excellent docs and a high bar.
- GitLab HackerOne - GitLab.com and CE/EE. Issue trackers, CI, auth, GraphQL. Famous for well-written scope and HackerOne reports.
- Shopify Open Source / HackerOne - Shopify admin, storefront, apps, Hydrogen, plus a well-known open-source bounty streak.
- Cloudflare VRP - Dashboard, Workers, Access, DNS, CDN bypasses. High bar, high quality, lots of 'this is intended edge behaviour'.
- AWS Vulnerability Reporting - AWS services and consoles. Customer-account issues are usually the customer's problem, not AWS's, unless you found a service-side cross-tenant bug.
- Tesla Bug Bounty - Vehicle, energy, web, apps. Famous scope, famous swag, famous 'do not brick a car' rules.
- Mozilla Hall of Fame / Bug Bounty - Firefox, mozilla.org, Firefox Accounts, VPN, Pocket-era properties. Oldest continuous web bounty worth knowing.
- Atlassian Bug Bounty - Jira, Confluence, Bitbucket, Trello, Atlas, admin.atlassian.com. Cloud vs DC/Server are different scopes.
- Detectify Crowdsource - You write a module that Detectify runs across their customer base. Paid per accepted module plus a bounty stream, not per-target hunting.
- NVIDIA Public Bug Bounty - GPU software, NGC, networking, AI stacks, and web properties. NVIDIA's current public program is hosted on Intigriti, with PSIRT as the official reporting path.
- CISA Vulnerability Disclosure - Coordinated disclosure into CISA for federal civilian and designated critical-infrastructure systems. Not a cash bounty board.
- PayPal Bug Bounty - PayPal, Venmo, Braintree, Honey. Auth, payments, and account linking. High bar, high duplicates.
- Okta Bug Bounty - Identity-platform bug bounty hosted on Bugcrowd, limited to the tenants and products named in the current brief.
- TikTok Bug Bounty - Public bug bounty on HackerOne for the TikTok properties listed in the current program brief.
- WordPress Bug Bounty - Bug bounty for WordPress core and the open-source projects and sites listed on the HackerOne program.
- Kubernetes Bug Bounty - CNCF-funded bug bounty for Kubernetes components and the related assets listed on HackerOne.
- Node.js HackerOne - Security reports for the Node.js runtime go through the HackerOne program.
- IBM Vulnerability Disclosure - Vulnerability disclosure program for IBM products, offerings, services, and sites, handled by IBM PSIRT.
- curl Vulnerability Disclosure - Coordinated disclosure for curl and libcurl. The project states that it does not pay rewards.
- PlayStation Bug Bounty - Sony Interactive Entertainment bug bounty on HackerOne for the PlayStation assets listed in the current scope.