Skip to main content
  1. Home
  2. Computing
  3. News

Some ethical hackers are making huge amounts of cash

Add as a preferred source on Google

Broadly speaking, hackers come in two flavors. Those who are out to exploit a computer system and cause havoc for its operator and people who use it, and those who search for vulnerabilities in a system and then inform the operator in exchange for a cash reward.

The latter can make some serious dough from their work, too, with the top ones able to earn millions of dollars in the space of a single year.

Recommended Videos

HackerOne is a Silicon Valley-based company that partners with the global hacker community to track down security issues for its clients — via so-called “bug bounty programs” — before the vulnerabilities can be exploited by criminals.

A growing number of companies big and small are working with HackerOne to launch bug bounty programs so that flaws can be identified and fixed, thereby removing them as a potential threat to their business.

In its latest annual Hacker Report, HackerOne reveals just how well some ethical hackers have been doing.

In the last year alone, ethical hackers earned a staggering $40 million through the reporting of vulnerabilities to programs run by HackerOne, a huge increase from the $19 million earned in 2019. Nine hackers have earned over $1 million dollars on the platform since 2019, and one hacker passed the $2 million mark in 2020.

More and more ethical hackers from all over the world are signing up to bug bounty programs, with HackerOne having seen a 63% increase in the number of hackers reporting flaws in the last year alone. The company now has more than a million investigators on its books.

In May 2020, HackerOne reached the milestone of $100 million paid to hackers for vulnerability reports, of which 50,000 were made in the last year, with the company forecasting that hackers will earn a total of $1 billion in bug bounties within five years.

Payments for reported vulnerabilities can vary hugely as they depend largely on how dangerous the bug could be to a firm’s computer systems and overall operations if it were to be exploited by hackers with nefarious intentions.

For an example of how payment systems function with bug bounty programs, we can look at one operated by Sony that invites ethical hackers to search for vulnerabilities on its PlayStation platform.

According to data from 2020, payouts start at $100 for a low-rated vulnerability discovered on Sony’s gaming platform, with more valuable tiers offering minimum payments of $400, $1,000, and $3,000.

Discover a low-rated vulnerability on the PlayStation 4, for example, and you should receive a minimum of $500, with higher rewards worth a minimum of $2,500 and $10,000. The most critical vulnerabilities, meanwhile, will result in a payment of at least $50,000.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Substack now lets you check if a post was written by AI
A new Pangram-powered scanner lets you check posts, notes, and replies for signs of AI writing.
Video playing on Substack.

Substack is giving readers a way to check whether the post they're reading was written by a human or by a chatbot. The company has partnered with AI-detection firm Pangram to introduce new tools that will let users scan posts, notes, and replies for AI-generated text. CEO Chris Best introduced the features in a post titled "Against Claudefishing," his term for content that leans on AI while presenting itself as human work.

How the scanning tool works

Read more
China’s AI talent shortage has tech giants recruiting teenagers
Forget campus recruiting, china's biggest tech firms are betting on teenage coders.
Artificial Intelligence

A 13-year-old boy in Hangzhou has already won national AI competitions and built a following of more than 136,000 people online, all while his dad tries to figure out how to guide him through a field that barely existed when he himself was growing up. That family's situation, first reported by Rest of World, says a lot about where China's tech industry is heading right now.

Companies used to wait for graduates to walk through the door. Now they're reaching further back, first to undergrads, and increasingly to teenagers, hoping to spot rare talent before anyone else gets to them.

Read more
OpenAI says AI models autonomously pulled off a major hack, but only a Chinese AI helped recovery
OpenAI

OpenAI’s latest cybersecurity test produced a result that sounds like a cautionary sci-fi script. Its AI models managed to escape their sandbox and reached the open internet. This is where things took a scary turn as it began hacking Hugging Face to steal the answers to the test they were taking.

The company says GPT-5.6 Sol and a more capable unreleased model autonomously chained together vulnerabilities across OpenAI’s research systems and Hugging Face’s production infrastructure. OpenAI has described the event as an unprecedented cyber incident.

Read more