World
Hackerone's Evolution: a Veteran's Perspective on the Platform's Shift

HackerOne, once the gold standard for bug bounty programs, has changed significantly since its founding in 2011, and a long-time researcher and program manager reflects on what that means for the industry.
So…what's going on at HackerOne lately? It might be time for a wellness check. If you are new to the bug bounty space (1-3 years), you might not have any idea what I'm talking about.
But as a properly washed-up bug bounty hunter who lived through the golden era of HackerOne, I think it's time to address the elephant in the room. For some context, I started as a hacker on HackerOne in 2017. When I began working in tech, that hands-on experience was extremely useful for managing a bug bounty program, since I knew what researchers wanted, and how to interact with them. As a result, I have managed multiple large bug bounty programs on HackerOne across various companies from 2018 to 2025 and I've been on both sides of the equation.
What I'm about to talk about comes from first-hand experience, both as a researcher and as a bug bounty program manager, and many, many years of direct conversations with HackerOne, both publicly and privately. To start, I think it's important to realize what HackerOne was originally designed to be. In 2011, two ethical hackers, Jobert Abma and Michiel Prins, set out to find security vulnerabilities in 100 of the largest tech companies.
Source: Hacker News
Most read in this category
Loading article…