Tor Project launching a bug bounty program with HackerOne, sponsored by Open Technology Fund
Major changes are underway in the Tor Project …
Context & Ripple Effects
Tor spent late 2015 trying to shrink its dependence on US government money: its first-ever crowdfunding campaign was framed explicitly as a push for funding independence, and it delivered with over $200,000 raised by January 2016. The new bug bounty complicates that arc — instead of self-funding security research from donations, Tor is outsourcing both the platform and the bill to HackerOne and the Open Technology Fund, the funder built in 2012 to help over 24 million people under repressive regimes reach the internet.
First-order effects
- Security researchers get a paid, structured channel for reporting Tor vulnerabilities through HackerOne, with the Open Technology Fund sponsoring the payouts rather than the Tor Project drawing on its freshly crowdfunded budget.
- HackerOne adds a high-profile anonymity-infrastructure client at a moment when it says it paid a record $81 million in rewards over the past year, up 13% year-over-year.
Second-order effects
- The template proves exportable: three years later OnePlus runs its own bug bounty with $50–$7,000 rewards and a HackerOne partnership for select researchers, showing consumer hardware makers adopting the same intermediary model Tor normalized for nonprofits.
- Sponsor-funded bounties let cash-strained mission-driven projects buy security expertise they could not staff internally, shifting the cost of vulnerability discovery onto funders like the Open Technology Fund whose mandate already covers censorship circumvention.
Third-order effects
- Bug bounties harden into default procurement for critical internet infrastructure, with platforms like HackerOne — which says it has awarded over $300M since inception — becoming gatekeepers between sponsors and researchers.
- The open-to-any-researcher intake model strains as submissions scale: GitHub's plan for a two-tier bounty that cuts public rewards while boosting invite-only payouts amid AI-generated report floods suggests the industry may retreat toward gated researcher pools, reversing part of what early programs like Tor's set up.
The trend: Bug bounties are evolving from corporate goodwill gestures into the primary funding mechanism for securing critical internet infrastructure, with specialist intermediaries and government-adjacent sponsors setting the terms.