Quick answer
The 4 big bug bounty platforms (HackerOne, Bugcrowd, YesWeHack, Intigriti) are not interchangeable. HackerOne has the largest programs (Shopify, Uber, GitHub) but slow triage. Bugcrowd pays fast but triage is aggressive with dupes. Intigriti is EU-first, clean payout. YesWeHack has French/European infrastructure and excellent human triage. If you live in Europe: start with Intigriti + YesWeHack (simple EU taxes), jump to HackerOne once you have a track record.
Comparison table
| Platform | HQ | Public programs | Reputation | Payout speed | Triage quality | EU friendly |
|---|---|---|---|---|---|---|
| HackerOne | US | ~600+ | Reputation + Signal/Impact | 1-3 weeks | Variable (depends on program) | OK (PayPal, USD) |
| Bugcrowd | US | ~400+ | Kudos + VRT priority | 1-2 weeks | Aggressive with dupes | OK (PayPal, USD) |
| Intigriti | Belgium | ~250+ | Points + streak | 3-7 days | Human, technical | Excellent (SEPA, EUR) |
| YesWeHack | France | ~150+ | Reputation + ranking | 5-10 days | Human, technical | Excellent (SEPA, EUR) |
HackerOne — the big one, but slow
Pros:
- Programs from Shopify, Uber, GitHub, GitLab, Coinbase, US DoD.
- Massive volume of public scope.
- Signal/Impact system that rewards consistent hunters with private invites.
- Live hacking events (LHE) with €1M+ pots.
Cons:
- Triage outsourced to the HackerOne triage team — inconsistent quality, plenty of unfair N/As in small programs.
- Payout speed depends on the program (some pay in 24h, others take 6 weeks).
- Tax treatment: they issue a 1099 (US) — in the EU you declare it as business income, standard income tax.
When to pick HackerOne:
- You want top-tier targets (Shopify, Uber).
- You care about LHEs.
- You already have a track record or level up via private invites.
Bugcrowd — fast payout but aggressive triage
Pros:
- Fast payout: PayPal within 1-2 weeks after accept.
- Bug Bounty Hunter levels (BBH I → II → III → IV) — clear progression system.
- Public VRT (Vulnerability Rating Taxonomy) — you know the exact severity/payout before reporting.
- Private programs accessible relatively early.
Cons:
- Triage marks dupes with broad criteria — you've seen the same bug reported by 3 different hunters with meaningful differences and all 3 get marked dupe.
- Some programs have very creative "Out of Scope" rules (e.g. clickjacking always N/A even with impact).
- Communication with triage is less direct than YesWeHack/Intigriti.
When to pick Bugcrowd:
- You need fast cashflow.
- Starting out — the level system gives useful feedback.
- Targets that are only here (Atlassian, some US gov).
Intigriti — the EU favorite
Pros:
- HQ Belgium → SEPA payment in EUR, 3-7 days after accept.
- Human technical triage — reasonable severity discussions, almost never an unfair N/A.
- Points + streak system that rewards consistency.
- Active Discord community, accessible (not a closed elite like H1).
- Tax benefits: simple EUR invoice for an EU freelancer.
Cons:
- Fewer programs than H1/BC (~250).
- Many programs require submitting from the EU → can be tricky if you live outside.
- Average bounties slightly lower than H1 top programs (~€500-€3000 vs ~$1000-$5000).
When to pick Intigriti:
- You live in the EU → SEPA + EUR simplifies the paperwork.
- You want human triage and real technical conversations.
- Starting out — the learning curve is gentler.
YesWeHack — French, technical, underrated
Pros:
- HQ France → SEPA, EUR, EU-compliant.
- Extremely high-quality technical triage — they discuss root cause with you.
- Unique European targets (OVH, Doctolib, Qonto, French government).
- Free "Dojo" with free labs to build reputation.
- Good public ranking system.
Cons:
- Private programs take longer to open up — you need a solid track record.
- Less polished UI than Intigriti.
- Smaller community, fewer guides.
When to pick YesWeHack:
- You want targets that aren't on other platforms (French banking, EU government).
- You like deep technical triage.
- You live in the EU and want to keep everything on SEPA.
My real journey (3 years of data)
I started on HackerOne because of the hype — 6 months of N/As, slow triage, frustration. I migrated to Intigriti + YesWeHack and the difference was brutal: first accept in 3 weeks, SEPA payout in 5 days, triage that responded with technical arguments. I went back to H1 once I had high signal and the private invites came on their own. My recommendation if you start in the EU:
- Month 0-3: Intigriti — low barrier, small public programs, patient triage for beginners.
- Month 3-6: Add YesWeHack for unique EU targets.
- Month 6+: Bugcrowd for fast cashflow, HackerOne for top-tier targets.
[!tip] Don't spread yourself thin The most expensive mistake is jumping between 4 platforms without focus. Master a methodology on one platform, build reputation, then expand. Top hunters have 70% of income on 1-2 platforms, not 4.
Tax considerations — EU
Bug bounty income in most EU countries = business income. Once you pass ~€1000/year, you generally have to:
- Register as self-employed with your tax authority under the relevant IT/technical services activity code.
- Social security (autónomo/self-employed regime): if you'll foreseeably earn >€10000/year or recurringly → registration is typically mandatory.
- VAT: services to EU businesses without a permanent establishment → intra-community reverse charge. Platforms like Intigriti/YesWeHack issue a VAT-free invoice with your intra-community VAT number.
- Quarterly advance payments: a percentage of your profit, depending on your jurisdiction.
- Annual income tax: declaration with the income under business activity.
US platforms (H1, BC): treated as an export of services outside the EU → VAT-free invoice, income tax only.
[!warning] This is not tax advice Talk to an advisor before you start invoicing seriously. The difference between full self-employment and declaring it as occasional income changes the tax treatment drastically once you start earning €1000+/month.
How to level up
HackerOne
- High Signal (>5.0) → private invites arrive on their own.
- High Impact (>10) → entry to top-tier programs (Shopify Plus, GitHub Sec, AWS).
- LHE participation → networking + premium invites.
Bugcrowd
- BBH I → II: 5 VHigh/Critical reports accepted.
- BBH II → III: 15 reports + acceptance ratio >70%.
- BBH III → IV: top 1% — access to Elite Programs.
Intigriti
- Streak of consecutive valid reports → points boost.
- Top 100 in the ranking → private invites.
YesWeHack
- Reputation > 1000 → most privates accessible.
- Top 50 in the public ranking → invitations to European Live Hacking Events.
Quick comparison — where the money is
| Metric | Winner |
|---|---|
| Highest average bounties | HackerOne (top programs) |
| Fastest payout | Bugcrowd / Intigriti |
| Best technical triage | YesWeHack / Intigriti |
| Most public programs | HackerOne |
| Best for EU | Intigriti / YesWeHack |
| Best progression system | Bugcrowd (BBH levels) |
| Fewest unfair dupes/N/As | Intigriti |
| Most LHE / events | HackerOne |
Hunting checklist when choosing a platform
- Where do I live? If EU → start with Intigriti/YesWeHack
- Does fast cashflow matter? → Bugcrowd
- Top-tier or exotic targets? → HackerOne (Shopify, Uber) or YesWeHack (EU banking)
- Just starting? → Intigriti has the gentlest curve
- Full-time work? → focus on 1-2 platforms max
- Taxes? → SEPA/EUR is 10× simpler than USD/PayPal
- Does LHE motivate me? → HackerOne has the biggest pots
- Active Discord? → Intigriti > the rest
Related labs
If you don't yet have a solid methodology before choosing a platform, start with the complete bug bounty guide and practice with public labs.
Practice this in a lab
Que Es Bug Bounty Guia Completa
Keep learning · free account
Save your progress, unlock advanced payloads and rank your flags.
There's an extra payload at the end
Which platform pays fastest and triages best in 2026 according to my internal data from 200+ reports over 3 years.
€7.99/mo · cancel anytime
Related articles
How to write a bug bounty report that gets accepted — structure and common mistakes
The ideal structure of a bug bounty report: title, summary, impact, steps to reproduce, PoC, remediation. The 10 mistakes that get your report rejected.
What is bug bounty? A complete guide to understanding how it works
Bug bounty explained: programs, platforms, types of vulnerabilities, how you get paid, duplicate ratios and why some hunters make a living from it.
Burp Suite — setup from scratch for bug bounty (Community + Professional)
Installation, proxy + CA cert setup, target scope, essential extensions and workflow to start hunting with Burp Suite today.