DEV Community

Charles
Charles

Posted on

What Happened to HackerOne? The Rise and Fall of the Bug Bounty Giant

The rise and fall of HackerOne is a cautionary tale for every platform that depends on a two-sided marketplace. What started as a revolutionary way to connect ethical hackers with companies has, according to a detailed post by a veteran bug bounty hunter, become a shadow of its former self.

The story begins in 2011, when two ethical hackers, Jobert Abma and Michiel Prins, set out to find security vulnerabilities in 100 of the largest tech companies. They succeeded, finding bugs in Google, Facebook, Apple, and Microsoft. But the legal landscape was hostile — hackers faced personal liability and even criminal charges for reporting vulnerabilities. HackerOne was created to solve this: a safe, mutual space where companies and hackers could connect.

The Golden Age

From 2015 to 2020, HackerOne was the center of the security research world. Live hacking events drew the top researchers together in person. Companies paid real money — sometimes six figures for a single critical vulnerability. The platform fostered a genuine community: researchers shared techniques, competed on leaderboards, and built careers.

The stats were impressive. HackerOne facilitated over $100 million in bounties paid. Tens of thousands of researchers participated. Major companies — from Uber to Goldman Sachs — ran programs. The live hacking events became legendary, with teams of researchers flown to cities around the world to hack in person, competing for bounties and bragging rights.

The Enshittification

Then things started to change. The term "enshittification" — coined by Cory Doctorow to describe the lifecycle of platforms — fits perfectly here.

First, HackerOne began prioritizing enterprise customers over individual researchers. The platform features that researchers loved — public leaderboards, transparency about bounty amounts, community discussion — were deprioritized in favor of enterprise dashboards and private program management.

Second, the quality of programs declined. Many companies set absurdly low bounty amounts — $50 for a critical SQL injection vulnerability, for example. Some programs took months to respond to reports. Others simply closed reports without explanation.

Third, HackerOne changed its policies around report ownership. Originally, HackerOne promised that reports belonged to the researchers who filed them. But as the platform pivoted toward enterprise customers, researchers reported finding their reports locked, their ability to disclose limited, and their relationship with the platform increasingly one-sided.

"Your Reports Are Yours, We Promise"

One of the most contentious changes was around report disclosure. HackerOne's original promise was simple: your reports are yours. You can disclose them after a reasonable period, even if the company doesn't fix the vulnerability.

But researchers reported that in practice, disclosure became increasingly difficult. Programs could indefinitely delay disclosure. HackerOne's mediation process was opaque. Some researchers waited years to disclose vulnerabilities they had reported, with no recourse.

This matters because disclosure is the currency of the bug bounty world. Researchers build their reputations through public disclosures. Without the ability to show their work, researchers are essentially doing unpaid labor with no recognition.

The Broader Pattern

What happened to HackerOne follows a pattern we've seen across tech platforms:

  1. Build a community: Create a space that attracts passionate users (researchers) and paying customers (companies).
  2. Grow the user base: Subsidize one side to attract the other. HackerOne subsidized researchers with good bounties and community features.
  3. Capture value: Once the network effect is strong, shift focus to the paying side (enterprises). Reduce features that benefit the non-paying side (researchers).
  4. Extract: Lock in both sides. Companies get locked in because switching platforms means losing their vulnerability history. Researchers get locked in because their reputation is tied to the platform.

The result is a platform that serves neither side well but profits from both being trapped.

What This Means for Security

The decline of HackerOne isn't just a business story — it has real security implications:

  • Fewer researchers participating: Top researchers are leaving for direct relationships with companies or competing platforms.
  • Lower quality reports: Researchers who remain face longer response times and lower bounties, reducing motivation.
  • Delayed vulnerability disclosure: When disclosure is blocked, the public doesn't know about vulnerabilities that affect them.
  • Market fragmentation: The bug bounty market is splintering across HackerOne, Bugcrowd, Intigriti, and direct programs, making it harder for researchers to find good programs and for companies to reach researchers.

Lessons for Platform Builders

The HackerOne story offers several lessons for anyone building a two-sided marketplace:

Don't bite the hand that feeds you. The researchers are the supply side. If you make their experience worse to please enterprise customers, you'll lose your supply, and then your demand has no reason to stay either.

Transparency builds trust. The community features that HackerOne deprioritized — leaderboards, public bounty amounts, discussion forums — were exactly what built trust in the early days. Removing them eroded that trust faster than any competitor could.

Promises matter. "Your reports are yours" was a promise that attracted researchers. Breaking it, even slowly, destroys credibility that took years to build.

Network effects work both ways. The same network effect that makes a platform valuable can make it a ghost town when one side leaves. HackerOne's dominance looked unassailable until researchers started leaving — and then it looked fragile.

The Future of Bug Bounties

The bug bounty model isn't dead — it's evolving. Direct vulnerability disclosure programs (VDPs) are growing. Companies are hiring researchers directly. New platforms are emerging with different models: some offering equity, some focusing on specific technologies, some emphasizing transparency.

The question is whether any platform can avoid the same lifecycle. The temptation to prioritize the paying side over the community side is structural. Every platform that succeeds at scale faces it.

HackerOne's story is a reminder that platforms aren't just technology — they're communities. And communities, it turns out, have limits on how much exploitation they'll tolerate before they walk away.


Based on a detailed analysis by a veteran bug bounty hunter and program manager who has worked with HackerOne since 2017, both as a researcher and as an enterprise customer.

Top comments (0)