HackerOne lets white hat hackers report security flaws to companies, gets 20% bounty commission
HackerOne Connects Hackers With Companies, and Hopes for a Win-Win — SAN FRANCISCO — In 2011, two Dutch hackers in their early 20s made a target list of 100 high-tech companies they would try to hack. Thanks: @peter_farago
Context & Ripple Effects
This story is the founding move of the intermediated bug-bounty market: two Dutch hackers build a platform where white hats disclose flaws to companies and HackerOne takes a 20% commission on every bounty. The model's arc since is visible in the coverage — by 2023 the platform had awarded over $300M to researchers, and last year payouts hit a record $81M as buyers like Netflix and Anthropic paid researchers up to $25K per flaw.
The same corpus also shows the risks of standing between hackers and their customers: in 2022 HackerOne disclosed that an employee stole vulnerability reports and sold them to seven companies — a failure mode unique to the middleman position this article introduces.
First-order effects
- Companies on the target list gain a sanctioned intake channel for outside security research, replacing ad-hoc disclosure with a paid, brokered process.
- White hat hackers get a monetizable path for their findings, with HackerOne's 20% take establishing the intermediary fee structure for the whole market.
Second-order effects
- The brokerage model scales into a lucrative profession — interviews with researchers show individuals crossing $1M+ in earnings — which pushes buyers toward programmatic spending on external hunters rather than purely in-house testing.
- Concentrating vulnerability reports inside one trusted intermediary creates new attack surface itself: once HackerOne became the vault, insiders could profitably steal and resell disclosures, forcing the platform to police its own employees like any other custodian of sensitive data.
Third-order effects
- If the pattern holds, outsourced vulnerability discovery becomes standard procurement for companies of every kind — the coverage shows even dark net markets like Hansa running bug bounty programs, evidence the practice has normalized far past its Silicon Valley origin.
- Trust in the intermediary becomes a competitive asset: platforms will be judged not just on bounty volume but on custody of the reports they hold, shaping consolidation around brokers with credible handling guarantees.
The trend: Security flaw discovery is shifting from informal researcher-to-vendor contact to commissioned marketplaces that take a percentage of every bounty, turning ethical hacking into an industry with its own economics and custody risks.