Skip to content

Bug Bounty 🐛💰

Term: Bug Bounty

Definition: A bug bounty program is a reward system where organizations pay security researchers rewards (bounties) to find and report vulnerabilities in their systems. The “Gig Economy” of cybersecurity.

How it works:

  1. Company launches a bug bounty program.
  2. Researchers find and report bugs.
  3. Researched writes a report explaining the bug and how to reproduce it.
  4. Company validates the bug and pays a “bounty” (monetary reward) based on severity. Major Platforms: HackerOne, Bugcrowd, Intigriti, Defend Iceland.

Related Concepts: Responsible disclosure, Vulnerability research, security bounty programs.