HackerOne

the world's largest bug bounty and vulnerability disclosure platform, where security researchers earn bounties — commonly $50 to $10,000+ per accepted vulnerability, with $380M+ rewarded to date — for

Websites, Games & App Testing Verified Sep 2026PayPal

Quick facts

HackerOne quick facts
FactDetail
CategoryWebsites, Games & App Testing
Platform typeBug bounty platform
Websitehackerone.com
Pay unitPer task, Hourly or project rate
Payout methodsPayPal, Bank transfer, SEPA, SWIFT international bank transfer, Cryptocurrency payout
Payout cadenceDaily, Monthly, Threshold-based
Minimum ageUNVERIFIED — no minimum age found in the official docs reviewed
Countries15 tracked — Global researcher community; individual programs set their own eligibility (most are open to all researchers); some programs exclude US-sanctioned countries.
Languagesen
EquipmentComputer, Stable internet
Experience neededExpert
Identity verificationPseudonymous accounts allowed at signup, but bounty payouts require (in order): identity verification via Veriff (valid 12 months), at least one valid payout method, and an approved tax form; bank accounts must be in your own/registered-business name matching the tax form; third-party accounts prohibited.
Last verified2026-09-07

In one paragraph

HackerOne pays for bug bounty hunting — billed per task, paid via PayPal and Bank transfer. Available: widely available. Minimum age UNVERIFIED — no minimum age found in the official docs reviewed.

Visit HackerOne

Pros & cons — facts only

Pros

  • Pays via PayPal.
  • Payout cadence: Daily.
  • Instant signup — no approval wait.
  • Available in 15 tracked countries.

Cons

  • Minimum payout not published — verify before your first cash-out.
  • Entry gated by qualification/identity checks.

How to join HackerOne

  1. Create a free account at hackerone.com/users/sign_up (name, username, valid email; pseudonym OK; 12+ char password); verify email; optionally set 2FA and skills; browse the program directory, read each program's policy/scope; submit vulnerability reports; complete Veriff ID verification + tax form + payout setup to receive bounties. Private programs are invite-based (reputation-driven).

Signup involves: Instant signup · Sign up · Identity verification · Project matching

Pay & payouts

  • Billed per: Per task, Hourly or project rate
  • Payout methods: PayPal, Bank transfer, SEPA, SWIFT international bank transfer, Cryptocurrency payout
  • Payout cadence: Daily, Monthly, Threshold-based
  • Minimum payout: Not published

Requirements

Minimum age
UNVERIFIED — no minimum age found in the official docs reviewed
Languages
English
Identity verification
Pseudonymous accounts allowed at signup, but bounty payouts require (in order): identity verification via Veriff (valid 12 months), at least one valid payout method, and an approved tax form; bank accounts must be in your own/registered-business name matching the tax form; third-party accounts prohibited.
Skills
Specialized: web/mobile security research, vulnerability discovery, and detailed technical report writing (reproducible steps or working proof-of-concept). Hacker101 CTF and free educational materials support learning, but meaningful bounty income requires demonstrated skill.
Equipment
Own computer and internet connection for security research; testing tools range from free to paid (HackerOne publishes a list of 100 tools); no specific hardware mandated by the platform.

Where it's available

Global researcher community; individual programs set their own eligibility (most are open to all researchers); some programs exclude US-sanctioned countries.

Restrictions: Program-level exclusions exist (e.g., Epic Games excludes residents of Cuba, Iran, North Korea, Sudan, Syria); bank transfers cannot go to OFAC-sanctioned banks (e.g., VTB, Sberbank); INR local payouts capped (HDFC suspended).

  • Australia
  • Brazil
  • Canada
  • Germany
  • Egypt
  • France
  • United Kingdom
  • India
  • Mexico
  • New Zealand
  • Philippines
  • Pakistan
  • United States
  • Vietnam
  • South Africa

What kind of work

  • Bug bounty hunting
  • Vulnerability disclosure
  • Penetration testing

Testing prerequisites

  • Bug reporting

HackerOne FAQ

Is HackerOne legit?

Yes — HackerOne is a real, operating platform. We verified its signup, payout, and policy pages directly on 2026-09-07 using 6 sources.

How does HackerOne pay out?

Via PayPal, Bank transfer, SEPA, SWIFT international bank transfer, Cryptocurrency payout. Payout cadence: Daily / Monthly / Threshold-based.

Who can join HackerOne?

Minimum age UNVERIFIED — no minimum age found in the official docs reviewed. Global researcher community; individual programs set their own eligibility (most are open to all researchers); some programs exclude US-sanctioned countries. Pseudonymous accounts allowed at signup, but bounty payouts require (in order): identity verification via Veriff (valid 12 months), at least one valid payout method, and an approved tax form; bank accounts must be in your own/registered-business name matching the tax form; third-party accounts prohibited.

How do I sign up for HackerOne?

Create a free account at hackerone.com/users/sign_up (name, username, valid email; pseudonym OK; 12+ char password); verify email; optionally set 2FA and skills; browse the program directory, read each program's policy/scope; submit vulnerability reports; complete Veriff ID verification + tax form + payout setup to receive bounties. Private programs are invite-based (reputation-driven).

What skills does HackerOne require?

Specialized: web/mobile security research, vulnerability discovery, and detailed technical report writing (reproducible steps or working proof-of-concept). Hacker101 CTF and free educational materials support learning, but meaningful bounty income requires demonstrated skill.

Sources & verification

Facts on this page were verified against 6 sources. Last full check: .

Explore related collections

Visit HackerOne