What Happened to HackerOne? · Curiosity With a Side of Chaos
↓<br>Skip to main content
Curiosity With a Side of Chaos
Table of Contents
Table of Contents
So…what’s going on at HackerOne lately? It might be time for a wellness check.
If you are new to the bug bounty space (1-3 years), you might not have any idea what I’m talking about.
But as a properly washed-up bug bounty hunter who lived through the golden era of HackerOne, I think it’s time to address the elephant in the room.
For some context, I started as a hacker on HackerOne in 2017. When I began working in tech, that hands-on experience was extremely useful for managing a bug bounty program, since I knew what researchers wanted, and how to interact with them.
As a result, I have managed multiple large bug bounty programs on HackerOne across various companies from 2018 to 2025 and I’ve been on both sides of the equation.
What I’m about to talk about comes from first-hand experience, both as a researcher and as a bug bounty program manager, and many, many years of direct conversations with HackerOne, both publicly and privately.
Background
To start, I think it’s important to realize what HackerOne was originally designed to be.
In 2011, two ethical hackers, Jobert Abma and Michiel Prins, set out to find security vulnerabilities in 100 of the largest tech companies. They succeeded and found bugs in Google, Facebook, Apple, Microsoft, Twitter, and many others. At this point in time, the landscape for ethical security research was risky, legally dubious, and very scary for security researchers.
Not only was there significant personal liability, but there had been multiple instances of hackers being criminally charged and sentenced to jail time for finding and reporting security vulnerabilities prior to this. Much of this was due to specific arbitrary lines drawn in the sand which, if crossed, made you a bad actor, but if not crossed, made you a potentially bad actor but technically not one.
Bug Bounty Platforms like HackerOne were designed to directly address this issue. It created a safe mutual space for companies and hackers to connect, and it paved the way for ethical hackers to submit security vulnerabilities to companies, with full consent, and get paid for that work. This was a huge milestone. You no longer had to worry about getting dragged to court (or jail) for finding an IDOR that leaked customer data. Instead, you got a “thank you” and a cash payout for making everyone a little safer.
This operating model was the foundation for bug bounty and remained that way for the next 5+ years.
The Golden Age of HackerOne and Live Hacking Events
During this period, there was a very strong and explicit focus for the business: how do we make this the best possible product for hackers?
The people running the business day-to-day were hackers, hacker-adjacent, and most (if not all) were face-to-face with hackers on a regular basis.
From 2017 to 2020, HackerOne was doing Live Hacking Events (LHEs) every few months. These were exclusive events where the top bug bounty researchers around the world would fly into a location, be given a target, and go absolutely ham finding critical vulnerabilities. LHEs were a huge value prop for programs. During a 1-3 day period, you would get more high and critical security reports than you would have received for the whole year otherwise.
Every event had a 1-of-1 custom designed poster with graphics, hacker usernames, stickers and challenge coins. It’s hard to overstate what an incredible and productive period this was for HackerOne and their top programs.
These events were exclusive and highly coveted; invites and +1s were practically their own currency. And the environment at these events was surreal. You would be given free flights and hotels around the world, and spend a few days surrounded by the best and most skilled bug bounty hunters in the world. These researchers would regularly find some of the most impactful bugs using their own novel techniques, and all while sharing tips and tricks in one-off conversations that could not be replicated anywhere else.
Prior to the advent of live hacking events, most security researcher circles were small, isolated, and sharing information publicly was practically unheard of. LHEs created a way for security researchers to connect with each other, and essentially created a whole new community within infosec. Most of my closest friends nowadays are people who I met through the live hacking scene, and I am extremely grateful to HackerOne for that.
LHEs were not the only area where HackerOne was building and establish a community for security researchers. They created a HackerOne Community space to organize meetups, online events, workshops, and CTFs. They created regional clubs, and appointed hackers who lived there as ambassadors to help foster and grow local researcher communities all around the...