Facebook launches a bug bounty “loyalty program” called Hacker Plus, which will give bug hunters extra bonuses and special perks based on past performance
Context & Ripple Effects
Facebook's bug bounty program has been expanding steadily for a decade — from paying 321 researchers $1.3M in 2014 and adding Oculus and Moves to scope, to covering third-party apps that expose user access tokens in 2018, and launching a separate Data Abuse Bounty that same year. By late 2020 the program was on track to pay out $1.98M on over 1,000 submissions in its tenth year.
Hacker Plus changes the incentive model rather than the scope: instead of paying per report alone, Facebook now layers bonuses and perks on top of a researcher's track record. It's a retention play aimed at the small pool of high-performing hunters who account for a disproportionate share of valid submissions — and it follows the broader pattern, set when Yelp launched its HackerOne-coordinated program in 2016, of consumer platforms competing for the same limited researcher talent.
First-order effects
- Facebook's most productive bug hunters now earn escalating rewards for continued loyalty, shifting their calculus from shopping each finding to the highest bidder toward consolidating their output with Facebook.
- Researchers who split their time across multiple company programs face an implicit trade-off, since Hacker Plus status accrues from sustained past performance with Facebook specifically.
Second-order effects
- Rival bounty hosts and platforms — from Yelp-style corporate programs to intermediaries like HackerOne — come under pressure to add their own tiered or loyalty-style rewards, or watch top talent concentrate on Facebook's program.
- Facebook's per-finding payout economics shift: the $1.98M annual outlay grows as bonuses stack on top of base bounties, a cost Facebook accepts to keep vulnerability volume high ahead of public exposure.
Third-order effects
- Bug bounty hunting moves further from ad hoc side income toward a career ladder with rank, status, and recurring benefits — pushing platforms to treat researcher relations as a competitive function, the way they treat creators or advertisers.
- If loyalty mechanics prove effective, bounty programs consolidate around the biggest spenders, leaving smaller companies to compete through intermediaries or higher per-report premiums for scarcer researcher attention.
The trend: Bug bounty programs are evolving from per-report payment schemes into tiered talent-retention systems, as major platforms compete for a limited pool of elite security researchers.