Bug Bounty
InformationalBug Bounty
Definition
Bug Bounty is a security model where organizations offer financial rewards to security researchers (ethical hackers) who discover and report vulnerabilities in their systems. Programs define a scope, participation rules and reward tables based on severity. It is a form of security crowdsourcing that complements internal teams and traditional audits.
Impact
Examples
Typical rewards by severity
Rewards vary enormously depending on the company and severity: Critical (RCE, SQLi with exfiltration): €5,000 - €100,000+. High (internal SSRF, mass IDOR, Account Takeover): €2,000 - €20,000. Medium (stored XSS, impactful CSRF): €500 - €5,000. Low (Open Redirect, Information Disclosure): €100 - €1,000. Companies like Google, Apple or Microsoft pay the highest rewards.