HackerOne raises $40M Series C led by led by Dragoneer Investment Group
Matt Weinberger / Business Insider :
Context & Ripple Effects
HackerOne's business is a two-sided marketplace: ethical hackers report security flaws to companies and the platform keeps a 20% commission on each bounty, per its 2015 launch-era coverage. The $40M Series C led by Dragoneer Investment Group is the capital to scale that take-rate model after it says it paid out over $300M in cumulative rewards.
The round lands in a category that has since proven durable: rival Bugcrowd raised a $30M Series D three years later, and HackerOne itself expanded beyond private bounties into public disclosure programs with General Motors in Detroit.
First-order effects
- Dragoneer's $40M gives HackerOne runway to grow its researcher network and enterprise customer base while defending its 20% bounty commission as the core revenue engine.
- The raise puts fresh pressure on Bugcrowd, the other major bug-bounty intermediary, which must match HackerOne's funding scale to compete for the same corporate programs.
Second-order effects
- As funded platforms court enterprises, vulnerability disclosure shifts from ad-hoc email reports to contracted programs — the model General Motors adopted when it opened Detroit's first public disclosure program with HackerOne.
- Growth forces both marketplaces to invest in trust infrastructure: HackerOne's own incidents — an employee stealing researchers' vulnerability reports and the expulsion of Voatz for hostile treatment of hackers — show governance becoming a competitive differentiator.
Third-order effects
- If the pattern holds, crowdsourced security consolidates into a few well-capitalized intermediaries that set the norms for how companies pay independent researchers — with platform governance, not just payout volume, determining who wins enterprise trust.
- The same funding logic that carried HackerOne and Bugcrowd extends to adjacent security niches, as seen when industrial-security firm Dragos raised a $110M Series C for critical-infrastructure defense.
The trend: Corporate security testing is moving from closed internal teams to managed crowdsourced marketplaces, where venture-backed intermediaries set the economics and governance for paying independent researchers.