Bug Bounty

Informational

Bug Bounty

Definition

Bug Bounty is a security model where organizations offer financial rewards to security researchers (ethical hackers) who discover and report vulnerabilities in their systems. Programs define a scope, participation rules and reward tables based on severity. It is a form of security crowdsourcing that complements internal teams and traditional audits.

Impact

Significant income for security researchers (from hundreds to millions of euros)Continuous improvement of organizations' securityAccess to global security talent without hiring employeesDetecting vulnerabilities before attackers exploit themA professionalized ecosystem with platforms, events and communities

Examples

Typical rewards by severity

Rewards vary enormously depending on the company and severity: Critical (RCE, SQLi with exfiltration): €5,000 - €100,000+. High (internal SSRF, mass IDOR, Account Takeover): €2,000 - €20,000. Medium (stored XSS, impactful CSRF): €500 - €5,000. Low (Open Redirect, Information Disclosure): €100 - €1,000. Companies like Google, Apple or Microsoft pay the highest rewards.

Practice Bug Bounty with real labs

Apply what you've learned in safe environments based on real bug bounty reports.

See practice labs
hunters training
712

hunters training

labs from real reports
55

labs from real reports

completions
1,206

completions

in bounties practiced
$213,970

in bounties practiced

46 flags captured this week·Real reports from HackerOne · Bugcrowd · Intigriti·No commitment·Free Academy
BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real reports that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime