Back
What happened to HackerOne: bug bounties, AI triage and a shaken community
SiTech Team3 წთ. საკითხავი

What happened to HackerOne: bug bounties, AI triage and a shaken community

A former bug bounty hunter and program manager traces how HackerOne shifted from hacker-first culture to sales-driven contracts, and why its AI triage and data policies sparked a controversy.

A platform built for a different era

HackerOne was founded by two ethical hackers, Jobert Abma and Michiel Prins, who in 2011 set out to find vulnerabilities in 100 of the largest technology companies. They succeeded: bugs turned up at Google, Facebook, Apple, Microsoft and Twitter, among others. The platform, launched in 2012, offered consent, a safe space and paid bounties, and became the reference model for bug bounty programs.

From live hacking events to annual contracts

Between 2017 and 2020 the company ran Live Hacking Events every few months, flying the world's top researchers to a target for one to three days. Programs would collect more high and critical reports in that window than in the rest of the year. HackerOne also built community infrastructure — meetups, workshops, CTFs and regional clubs with local ambassadors. According to the author, that momentum later faded.

The business changed shape too. Between 2014 and 2022 HackerOne raised $160M. In late 2024 Marten Mickos, CEO for almost a decade, was replaced by Kara Sprague, formerly Chief Product Officer at F5. Revenue shifted from a share of bounties towards capacity-based fees and multi-year contracts, with renewal discounts used to keep customers locked in.

The AI controversy

In February 2026 the researcher zseano noticed a wave of departures at HackerOne and asked why employees were leaving. The discussion surfaced updates to the platform's terms of service that allowed reports submitted on HackerOne to be used to train AI models. Co-founder and CTO Alex Rice responded that the company does "not train, fine-tune, or otherwise improve GenAI or large language models on researcher data", and CEO Kara Sprague published a similar statement.

About two months later researchers noticed comments from an account called hackerone-agent on their reports. A HackerOne product manager explained it was a preliminary AI review: the system analyses all reports and decides which can go straight to the validation team, and rejection reasons are stored so the agent's reasoning improves over time. As the author argues, that distinction makes little practical difference to researchers whose submissions now influence future automated behaviour.

In June the same pattern appeared around the new HackerOne Continuous Testing product: a page saying testing is "sharpened using context from HackerOne's 12+ years of real-world vulnerability data" was edited after researchers raised it.

Why it matters

The author's conclusion is that the platform has lost the identity it started with in 2012. His closing advice to researchers is that platforms cannot exist without hackers; for customers, he argues that building an in-house program now costs less than a single year on a commercial platform.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.