
A growing chorus from the bug bounty community is pushing back against low compensation for valid bug reports, revealing vast discrepancies in expected rewards. Many feel burnt out as they gauge the tough triage processes impacting their earnings.
Frustrations reached a boiling point, with one tester detailing that out of potential bounties exceeding $100,000, they only earned $1,700 this year. Their 42 submissions, spanning multiple programs, fell mostly on deaf ears as numerous vulnerabilities were downplayed or dismissed entirely.
"I submitted real issues and got little to show for it," said one frustrated tester.
Payment Disappointments
A prevailing sentiment among testers points to shocking payout gaps. Many get zero or meager rewards for their valid reports, even amidst expectations of substantial compensation.
Triage Protocol Criticism
Testers are increasingly unhappy with triage teams, claiming many reports are shut down inaccurately or lack proper attention. Commenters noted instances where reports were simply not read thoroughly.
Quality of Bug Programs
The community is increasingly questioning the integrity of various bug bounty programs. Several users have stated they are pulling back from reporting altogether or only submitting to programs they trust.
Interestingly, as one person noted, "Iβm just going to stop reporting anything at all (to all but a handful of good programs), as it is a waste of my time to write it all up, just to have someone take my work for free."
The feedback from the community reflects a mosaic of discontentment about vulnerability assessments:
"I logged multiple reports with Intigriti, and two were closed as N/A because the triage staff just didnβt read them properly."
"Despite my detailed reports, I keep hearing excuses and see little follow-through. It feels more like volunteer work."
Some testers have turned to independent validation of vulnerabilities instead of collaborating with programs, citing long wait times for them to even acknowledge submissions.
Comments reveal a deepening frustration over the reliability of reported payouts. One tester pointed to a particularly problematic program, emphasizing, "They rolled out excuse after excuse for why it didnβt qualify, and in the end, paid out as a p3."
Experts warn that without addressing these issues, we could see nearly 40% of bug hunters reconsider remaining in the field. This shift may force programs to rethink their structures or risk losing valuable contributors.
β οΈ Only 7 bounties deemed eligible out of 42 reports logged.
π 18 reports received no response at all, alarming many testers.
πΈ $1,700 was the payout this year, when it could have been $100k+.
Rising discontent may just be the tip of the iceberg. If the systems in place donβt change, the number of those willing to contribute may dwindle, putting pressure on programs to improve transparency and payment structures.