HackerOne bug bounty payouts reach $81 million in 2024-2025
Summary
Hide ▲
Show ▼
HackerOne reported paying $81 million in bug bounties over the past year, marking a 13% year-over-year increase. The platform manages over 1,950 bug bounty programs for high-profile clients, including major corporations and government agencies. The average annual payout across all active programs is approximately $42,000, with the top 100 programs paying out $51 million in the last year. The top 10 programs alone accounted for $21.6 million in rewards. The number of AI vulnerabilities has surged by over 200%, with prompt injection vulnerabilities increasing by 540%. Meanwhile, traditional vulnerabilities like XSS and SQLi are declining, while authorization flaws are on the rise.
Timeline
-
02.10.2025 18:35 1 articles · 10h ago
HackerOne reports $81 million in bug bounty payouts for 2024-2025
HackerOne has paid $81 million in bug bounties over the past 12 months, a 13% increase year-over-year. The top 100 programs paid out $51 million, with the top 10 programs accounting for $21.6 million. AI vulnerabilities surged by over 200%, with prompt injection vulnerabilities increasing by 540%. Traditional vulnerabilities like XSS and SQLi are declining, while authorization flaws are on the rise. The number of bug bounty programs including AI in scope increased by 270% year-over-year, and 70% of researchers surveyed used AI tools in their workflow.
Show sources
- HackerOne paid $81 million in bug bounties over the past year — www.bleepingcomputer.com — 02.10.2025 18:35
Information Snippets
-
HackerOne paid $81 million in bug bounties over the past 12 months.
First reported: 02.10.2025 18:351 source, 1 articleShow sources
- HackerOne paid $81 million in bug bounties over the past year — www.bleepingcomputer.com — 02.10.2025 18:35
-
The platform manages over 1,950 bug bounty programs.
First reported: 02.10.2025 18:351 source, 1 articleShow sources
- HackerOne paid $81 million in bug bounties over the past year — www.bleepingcomputer.com — 02.10.2025 18:35
-
The average yearly payout across all active programs is approximately $42,000.
First reported: 02.10.2025 18:351 source, 1 articleShow sources
- HackerOne paid $81 million in bug bounties over the past year — www.bleepingcomputer.com — 02.10.2025 18:35
-
The top 100 bug bounty programs paid out $51 million between July 1, 2024, and June 30, 2025.
First reported: 02.10.2025 18:351 source, 1 articleShow sources
- HackerOne paid $81 million in bug bounties over the past year — www.bleepingcomputer.com — 02.10.2025 18:35
-
The top 10 programs alone accounted for $21.6 million in rewards.
First reported: 02.10.2025 18:351 source, 1 articleShow sources
- HackerOne paid $81 million in bug bounties over the past year — www.bleepingcomputer.com — 02.10.2025 18:35
-
The top 100 all-time earners took a total of $31.8 million, with individual researchers surpassing six-figure annual earnings.
First reported: 02.10.2025 18:351 source, 1 articleShow sources
- HackerOne paid $81 million in bug bounties over the past year — www.bleepingcomputer.com — 02.10.2025 18:35
-
AI vulnerabilities increased by more than 200%, with prompt injection vulnerabilities surging by 540%.
First reported: 02.10.2025 18:351 source, 1 articleShow sources
- HackerOne paid $81 million in bug bounties over the past year — www.bleepingcomputer.com — 02.10.2025 18:35
-
XSS and SQLi vulnerabilities are in decline, while authorization flaws are increasing.
First reported: 02.10.2025 18:351 source, 1 articleShow sources
- HackerOne paid $81 million in bug bounties over the past year — www.bleepingcomputer.com — 02.10.2025 18:35
-
1,121 bug bounty programs included AI in scope in 2025, a 270% increase year-over-year.
First reported: 02.10.2025 18:351 source, 1 articleShow sources
- HackerOne paid $81 million in bug bounties over the past year — www.bleepingcomputer.com — 02.10.2025 18:35
-
70% of over 1,820 researchers surveyed used AI tools in their workflow.
First reported: 02.10.2025 18:351 source, 1 articleShow sources
- HackerOne paid $81 million in bug bounties over the past year — www.bleepingcomputer.com — 02.10.2025 18:35