HackerOne shifted from hackers to sales, a longtime bug hunter writes

In 2011, two ethical hackers, Jobert Abma and Michiel Prins, set out to find security vulnerabilities in 100 of the largest tech companies and succeeded, turning up bugs at Google, Facebook, Apple, Microsoft and Twitter, among others. At the time, reporting a vulnerability could expose a researcher to criminal charges; HackerOne built a legal, paid channel between hackers and companies, and that model held for the platform's first five-plus years.
The author, who started as a hacker on HackerOne in 2017 and managed large bug bounty programs on the platform for various companies from 2018 to 2025, describes 2017 to 2020 as a golden era built around Live Hacking Events (LHEs): in-person events held every few months where top researchers were flown in, given a target, and competed to find critical bugs over one to three days, often surfacing more high and critical reports than a program would receive in a full year otherwise. Each event had a custom-designed poster, stickers and challenge coins, and invitations were highly coveted. HackerOne also ran a Community program with meetups, workshops, CTFs and regional hacker ambassadors. According to the author, this began to fade: community programs lost momentum, LHE posters went from custom silkscreen prints to cheap laser prints, and the staff who ran these programs were laid off or left.
The author dates the turning point to around 2020 or 2021, when HackerOne had to answer how it would make money. Between 2014 and 2022 the company raised a total of $160 million across seed rounds roughly every two years, funding that, per the author, gave VCs board seats and other leverage over the business. The founding CEO was replaced by a corporate CEO, and HackerOne moved away from taking a 20 percent cut of bounties paid toward capacity-based fees and multi-year annual contracts; customers renewing a multi-year deal were offered discounts of 30 to 60 percent to stay locked in. The author writes that account managers pushed customers to raise bounty amounts to stay competitive, telling them, in the author's account, "Hackers want to spend time focused on the highest-paying programs." As the sales-first approach took hold, the author says triage staff, many of them former hackers, burned out and left over low pay and heavy workload; hackers were flooded with more low-quality programs and a worse triage experience; and customers saw report quality fall and costs rise. Because bug bounty is, in the author's telling, an oligopoly of three companies that control almost the entire market (none of these companies are named), HackerOne did not lose customers to competition despite this decline.
HackerOne later introduced the Hacker Success Program (HSP), pairing top hackers with a dedicated Hacker Success Manager who could help resolve disputes over communication, program quality or bounty payouts, and who offered extra opportunities such as H1 challenges. The author calls this useful in practice for the hackers who have it, but says it also created an uneven playing field: newer hackers have little way to escalate problems and get support, while top hackers, already advantaged, receive direct help. The author adds that HSP could not do the one thing many hackers wanted, which was to drive real changes and new features on the platform itself; a dedicated feedback channel was created but, in the author's account, produced no visible action on the large number of suggestions posted there.
On the arrival of large language models around 2021, the author argues HackerOne had a ten-year backlog of feature requests and access to powerful new development tools, but instead of using them to close that backlog, built its own AI assistant, called Hai. The author describes Hai as little more than a wrapper on top of OpenAI's technology, with few real capabilities beyond what hackers and programs had already been asking HackerOne to add to the core platform. The author also writes that Abma and Prins, the hackers who founded and built the company, are still listed on HackerOne's website as part of the executive team but have, in the author's words, been sidelined within the business they built. The available text of the post breaks off mid-sentence at the start of a section titled "The Enshittifica," apparently the beginning of a section on platform enshittification; the remainder of the article, including that section, is not part of the text retold here.
Key facts
- HackerOne raised a total of $160 million in VC funding through seed rounds roughly every two years between 2014 and 2022.
- HackerOne moved from a 20 percent cut of paid bounties to capacity-based fees and multi-year annual contracts, offering renewing customers discounts of 30 to 60 percent to stay locked in.
- From 2017 to 2020, HackerOne ran Live Hacking Events every few months, flying in top researchers for one to three day events that the author says often produced more critical reports than a full year of ordinary program activity.
- The author, a bug bounty hacker since 2017 who managed HackerOne programs from 2018 to 2025, says the company's AI assistant Hai is just a wrapper on top of OpenAI with few unique capabilities.
- The author describes bug bounty as an oligopoly of three unnamed companies controlling almost the entire market, which the author says let HackerOne keep customers despite declining service quality.
Why it matters
HackerOne was one of the platforms that turned ethical hacking from a legally risky activity into a paid, sanctioned line of work, and its Live Hacking Events helped build the modern bug bounty community. A firsthand account of that platform trading its hacker-first culture for a sales-driven, VC-funded business model is a signal about where incentive structures push a marketplace business once outside investment enters the picture, not just a complaint about one company's product decisions.
Who it affects
Independent security researchers who rely on HackerOne and similar platforms for legal, paid vulnerability disclosure; the companies that run bug bounty programs on HackerOne and negotiate its contracts; triage staff employed to review submitted reports; and HackerOne's own founders and staff, who the author says have been pushed to the margins of the company they built.
How to use it
The account is most useful to anyone weighing whether to run a program on HackerOne or a competing bug bounty platform: it flags that HackerOne's pricing has moved from a percentage-of-bounty model to capacity-based annual contracts, and that multi-year renewals come with steep discounts of 30 to 60 percent aimed at keeping customers locked in, details worth checking against current HackerOne contract terms before signing.
How solid is it
This is a first-person opinion piece by someone who says they were a hacker on HackerOne from 2017 and ran bug bounty programs on the platform from 2018 to 2025, giving direct experience on both the researcher and program-manager sides. The concrete figures cited, the $160 million raised between 2014 and 2022 and the shift away from a 20 percent bounty cut, are stated plainly, but most of the account, the decline in triage quality, report quality and community engagement, rests on the author's own observation rather than published data, and there is no response from HackerOne in the retold text.
Risks and caveats
The piece is a single insider's critique, not a company statement or an independent investigation, and several specifics are left unnamed: the corporate CEO who replaced HackerOne's founding CEO, and the three companies the author says form the bug bounty oligopoly. No date is given for when Hai launched, and changes in bounty payouts, report quality and triage pay are described only in general terms rather than with figures. The version of the article retold here also cuts off mid-sentence at the start of a section on platform enshittification, so whatever follows in the original is not reflected.
“Hackers want to spend time focused on the highest-paying programs”
— HackerOne account managers, as quoted by the author