Micro-TasksSELF-REPORTEDCROWDED

Bug Bounty Hunting

Find and responsibly disclose security vulnerabilities for cash rewards on HackerOne/Bugcrowd.

Fully remoteNeeds an existing skillNo upfront cash

The Money Label

Cash score49
Startup cost$$$$$£0
Ready in1–3 mo
Hours a week10–30 hrs/wk
Skill floorExisting skill
RiskMEDIUM
Effort10–30 HRS/WK
Ceiling£0–4.7k/MO
SaturationCrowded
EvidenceSELF-REPORTED
Available inUS · GB · CA · AU · IN · DE

Why that grade Payout distribution and elite-hunter figures are widely cited platform and community statistics; median individual payouts specifically are drawn from general community consensus rather than one audited source. Course-seller index 3/10.

Figures are researched estimates, not guarantees. Check local rules before you trade.

Why anybody pays for this

Companies would rather pay a hacker to find and responsibly report a flaw than have it exploited or discovered by a regulator, so they fund ongoing bounty programs — real, well-paid work for genuinely skilled security researchers.

Extremely top-heavy distribution: median individual payouts are small (many hunters earn $0-$500/year total); mid-tier skilled hunters can make $20,000-$80,000/year; a small elite (top ~100 hackers) earn six figures, with several individuals crossing $1M+ lifetime and critical/RCE bugs at some programs paying $10,000-$50,000+ per report.

Good fit if

Someone with genuine, developed technical skill in web/app security, willing to spend months building that skill before landing a first valid paid report.

Skip it if

Anyone treating this as a beginner-accessible side hustle — it is not, and the field is now flooded with AI-assisted low-quality report spam that has eroded triage patience for everyone, beginners included.

What actually goes wrong

Testing anything outside a program's declared scope can constitute unauthorized computer access — a real crime, not just a rules violation — so the legal safety of this work depends entirely on your own discipline about staying inside bounds, not the platform's.

The playbook

5 steps to your first paying customer

What the steps cost
£0
estimate £0

Set up

01

Learn web/app security fundamentals

£0 · 8 hrs

OWASP Top 10 and hands-on practice with Burp Suite are the standard starting point.

Done when You've worked through the OWASP Top 10 hands-on in Burp Suite and can independently find at least one vulnerability class (e.g. XSS, IDOR) in a deliberately vulnerable practice app.

Burp SuiteOWASP ZAP

First customers

02

Start on public programs with generous scope

£0 · 6 hrs

HackerOne, Bugcrowd and Intigriti all list public programs — pick ones with broad, clearly defined scope to start.

Done when You're actively testing on at least two public HackerOne, Bugcrowd or Intigriti programs with broad, clearly defined scope.

3 more steps in this playbook

The rest of the playbook: what to charge, what you need in place before you take money, where the first customers come from, and what each step costs.

Free forever · no card · 30 seconds

Building a moat

N/A — individual skilled gig work.

01

Deep specialization in one vulnerability class or tech stack

02

A strong reputation score that unlocks invite-only, higher-paying private programs

Exit options

A strong track record can lead to full-time security research roles or independent pentest consulting.

Similar, but different