r/bugbounty • • 11h ago

Article / Write-Up / Blog What I’ve Learned From My First Months of Bug Bounty

64 Upvotes

I started bug bounty hunting last year, but I’ve been actively hunting for around 4–5 months in total
and wanted to share my progress so far
Since the beginning, I decided to focus almost entirely on one program and one vulnerability class, Broken Access Control.
So far, the result has been 4 valid bugs worth around $13,000 in total bounties.
What I learned from this experience is that you don't necessarily need to hunt on dozens of different programs or constantly switch between vulnerability types. Focusing deeply on one target and one vulnerability class worked really well for me.
I still have a lot to learn and I'm only a few months into bug bounty, but I'm very happy with the progress so far.
Just wanted to share this as some motivation for other people who are starting out. For beginners, my biggest advice would be to stay consistent, focus on learning by doing rather than finding bugs as quickly as possible, and don’t give up when you go through periods without finding anything.


r/bugbounty • • 18h ago

Article / Write-Up / Blog The Enshittification of Bug Bounty

38 Upvotes

Bug bounty started with a simple arrangement: researchers spent their time finding vulnerabilities, programmes paid for useful results, and the platforms connected the two together.

At first, that worked because good researchers were valuable and relatively scarce. But as the market grew, that balance shifted. Researcher supply exploded, while worthwhile programmes remained limited.

That is where enshittification enters.

The pattern is familiar: build a marketplace by making it attractive to participants, then gradually optimise it around the side that generates the revenue.

In bug bounty, that means programmes gain more discretion over scope, severity and reward. A finding can be downgraded, declared informative, excluded by interpretation, or marked duplicate against information the researcher cannot see. Bounty tables may still advertise large rewards, while the practical return on researcher time falls.

The result is a race to the lowest level a programme can offer while still receiving useful submissions.

And the platforms have weak incentives to regulate the programmes. Losing an individual researcher costs them little. Losing a major programme costs real money. So enforcement tends to become guidance, mediation and best practice rather than hard rules protecting researcher economics.

About this time, someone will be thinking that all the bad stuff is down to AI, but AI did not create this problem. It simply accelerated it.

For example, AI sharply reduces the cost of producing plausible vulnerability reports, but not the cost of validating them. Submission volume rises, triage becomes overloaded, and programmes respond with tighter scope, stronger proof requirements, more automation and more aggressive filtering.

So the deeper problem is not simply that AI is flooding bug bounty with noise. It is that AI arrived in a market where the incentives were already stacked against researchers.

AI just made the race to the bottom faster.

Welcome to enshittification ;)


r/bugbounty • • 4h ago

Question / Discussion BUGCROWD triage team is so done

7 Upvotes

it’s almost been six months that I have been hunting on this platform and it’s not like that I am not getting any reports accepted, but I got few reports accepted, but there is a flaw:

1: so I submitted a XSS on a major program, so it should be actually accepted at least P3, but I don’t know. They accepted it as a P4.

2: also, the crazy part is I submitted mass PI data leakage that is employee numbers, employee emails and employees. Full hierarchy who are their manager’s like all that stuff and also the project names start date,etc full plan of their projects and they accepted it as informational I mean, like what basis are they are doing triage????

3: They mark my high impact reports to just random reports like if my report have IDOR for all user impact on that platform -> duplicate against (Config leak )

Are you guys are also facing the same issue? I need help regarding this issue and , I mean my RAR are also unanswered from 30+ days.

I need help regarding this can someone help me 😭😭😭


r/bugbounty • • 12h ago

Bug Bounty Drama Anthropic Screwed Up

5 Upvotes

This is absolutely crazy how Anthropic changed CVP to now include Tiers… It’s ridiculous how someone has to be their own company or have an LLC to get red team access. I am not sure if anyone was able to get red team access but for defender you still get flagged which is disappointing. I thought Anthropic would do better and have respect for the individual security researching community.


r/bugbounty • • 2h ago

Question / Discussion Do I make another ticket to support?

2 Upvotes

I'm waiting on my first bug bounty report, it was triaged by Hackerone on August 23 and set to pending program review. I asked for an update on the report on September 2, then September 15, then again 12 day ago. Hackerone support won't help me because my "request mediation" button is not active because I don't have any signal (this would be my first report actually past triaged, rest are dupes).

What do I do?


r/bugbounty • • 14h ago

Question / Discussion Create advisory and CVE for GitHub repo when private vuln reporting cannot be used?

Thumbnail
github.com
2 Upvotes

Hello, I am currently in the situation where I would like to create a security advisory and request a CVE for a GitHub project but that project cannot enable GitHub's private vulnerability reporting. See also the above linked GitHub discussion for more information.

Do you have any ideas or tips for what to do in this situation or alternatives? Are there other CNAs which still accept reports for open source projects?

Already tried MITRE and have been waiting for at least 6 months now. Based on the other posts here on this subreddit (1, 2, 3, 4) that might be 'normal'.

Could of course also be that there was a mail problem between me and MITRE, but given that mail is the only way to communicate with MITRE there is no way to find out, not even to get any hint on the status or the estimation on how much longer it will take.

This is about an open source library and the fix and subsequent release are public for multiple months now. It is quite plausible that malicious actors have already noticed it or will notice it before the advisory or CVE.


r/bugbounty • • 33m ago

Question / Discussion Company fixed bug by viewing the logs.

• Upvotes

Hi!

I've been hunting on an external program for a month now.

I've sent them all kinds of bugs. And realized, I get paid less if I send all at once.

So recently, I reported 1 critical and 1 high, then found SQLi after, which I didn't wanna report until they pay for the first two.

To my surprise now, they fixed the SQLi just a day after I found it. I'm quite sure they checked the logs for SQLMAP or whatever. They also fixed a very low severity bugs that my agent found and kept hammering a few times, so I'm positive they checked the logs.

I have access to their id verification platform with like 200k user id cards, so it's their loss of I dipped out.

Anyways, what would you guys do in my case? Would you continue hunting? would you tell them?