Tor Project launching a bug bounty program with HackerOne, sponsored by Open Technology Fund
Context & Ripple Effects
When HackerOne opened its marketplace to white hat hackers in 2015, taking a 20% commission on every bounty, its clients were companies protecting commercial products. The Tor Project signing on changes that template: this is a nonprofit whose software exists to serve users under repressive regimes, with the bill paid by the Open Technology Fund — the funder launched in 2012 to help over 24 million people in censored countries reach the open internet.
The sponsorship structure matters because it decouples who pays from who profits: OTF is effectively buying vulnerability discovery for anti-censorship infrastructure through a commercial intermediary.
First-order effects
- Security researchers gain a paid, structured channel for reporting Tor flaws instead of unpaid disclosure, with HackerOne handling triage and taking its standard commission.
- The Open Technology Fund's spend shifts from building circumvention tooling toward hardening it, treating undiscovered vulnerabilities in Tor as a fundable gap.
Second-order effects
- Other privacy and anti-censorship nonprofits now have a proven playbook — donor or grant money routed through a bounty platform — putting pressure on them to offer researchers compensation rather than goodwill alone.
- HackerOne gains a marquee non-corporate reference case that broadens its addressable base beyond product companies, a path consumer hardware makers like OnePlus later followed with its own HackerOne-partnered program.
Third-order effects
- If grant-sponsored bounties become routine, publicly funded security work converges with the commercial vulnerability market — the same platform serving both — raising questions about oversight when state-adjacent funders pay for flaws in tools used by dissidents.
- HackerOne's growth curve, which by 2023 had reached over $300M in cumulative rewards across its programs, suggests bounty platforms are consolidating into default disclosure infrastructure regardless of who the sponsor is.
The trend: Bug bounty platforms are becoming the default mechanism for coordinated vulnerability disclosure, expanding from corporate products to publicly funded civic infrastructure.