Paid to Break Things
Security is one of the few fields where a solo developer still competes directly with billion-dollar companies — and gets paid market rate for winning. No resume screen, no eight-round interview loop, no "we went with an internal candidate." You find a real vulnerability in a published scope, you write it up, you get paid per finding.
If you've read our survival guide for unemployed programmers, bug bounties were on the income map with a note: fatter tail, thinner base. This post is the deep dive — every major platform, who each one fits, and how to avoid wasting three months on the wrong one.
One framing first, because it decides which platform you pick: paid security work comes in two very different shapes.
Bug Bounties vs. Audit Contests — Pick Your Game
Bug bounties are open hunting. A company publishes a scope (their app, a subdomain list, an API), you find a valid vulnerability whenever you find it, and the platform pays you per severity. Income is lumpy and unpredictable — you might earn nothing for six weeks, then $5,000 in an afternoon.
Audit contests are time-boxed competitions. A protocol (usually DeFi) puts up a prize pool — say $100,000 — and for a fixed window of days, auditors race to find issues in one codebase. The pool is split by placement, so every top-finishing auditor gets paid on every contest. Less windfall, more paycheck.
Rule of thumb
Start with bounty hunting to build a finding history and learn triage. Graduate to audit contestswhen your hit rate is consistent — that's where $/hour stabilizes. Both reward exactly the same skill, so nothing you learn is wasted.
The Platforms at a Glance
Nine serious options, ordered roughly from "default starting point" to "specialist territory." Details below the table.
| Platform | Focus | Typical payouts | Best if you… |
|---|---|---|---|
| HackerOne | Web & enterprise | $100–$10k+ per report | First platform; largest program selection |
| Bugcrowd | Enterprise web & mobile | $100–$10k+ per report | Enterprise scopes, managed programs |
| Intigriti | Web (EU-based) | $50–$5k+ | European researchers, community events |
| YesWeHack | Web (EU-based) | $50–$5k+ | Beginners — free Dojo training ground |
| Synack | Invite-only missions | Retainer + per find | Consistent income for vetted researchers |
| Immunefi | Web3 / smart contracts | $1k–$10M+ (record payout) | Crypto natives who know Solidity |
| Cantina | Audit contests (web3) | $200k–$2M+ pools; $46M+ paid out | Senior auditors; the biggest contests |
| CodeHawks (Cyfrin) | Audit contests (web3) | Shares of contest pools | Beginners learning smart-contract auditing |
| Sherlock | DeFi audit contests | Escalated pools + per find | DeFi specialists |
| Google / Microsoft / Meta VRPs | Vendor direct | $500–$250k+; millions paid yearly | No middleman, top-of-resume signal |
The Web Platforms
HackerOneis the default first platform: over a million registered hackers, the largest catalog of public programs, and hundreds of millions in lifetime payouts. Its transparency is the point — scopes, triage decisions, and payout history are public, which matters when you're building a reputation from zero. The honest caveat: flagship targets are heavily hunted. Fresh and niche programs pay far better per hour than "find a bug in Google on HackerOne."
Bugcrowd runs parallel to HackerOne with a more enterprise flavor: many Fortune 500 programs, priority-based payouts, and historically strong triage. Plenty of researchers run both platforms and double-dip on scopes.
Intigriti and YesWeHackare the European ecosystem. Both have friendly communities and responsive teams; YesWeHack's Dojo is a free training ground with real-world-style challenges, making it one of the best on-ramps for total beginners.
Synack is the outlier worth understanding: invite-only, vetted researchers, and work arrives as missions — scoped, recurring engagements that pay a monthly retainer plus per-find bonuses. Invited researchers describe it as the closest thing to a security salary in the bounty world. You get in with a proven finding history elsewhere.
Vendor programs— Google's VRP, Microsoft's MSRC, Meta Whitehat — cut out the middleman entirely. No platform fees, direct relationships with security teams, and payouts that collectively run into the tens of millions per year across the three. They also sit at the top of any security resume. The trade-off is process: strict scopes, stricter disclosure rules, and slower first responses on some programs.
Skip Open Bug Bounty.It lists uncoordinated disclosure "programs" from sites that never agreed to participate — publishing bugs against unwilling targets burns your reputation before you have one.
The Web3 & Audit Contest Platforms
Immunefiis where the biggest single payouts in bug bounty history live — including the record $10 million paid for one critical smart-contract finding. It's the default platform for web3: hundreds of protocols publish scopes there, and payouts run from $1,000 for a medium to seven figures for a protocol-breaking critical. Two conditions apply. You need real Solidity and DeFi knowledge — web techniques won't get you paid. And stick to programs listed on the platform itself; the crypto space is full of scammers impersonating bounty programs.
The audit contest model has one recent plot twist worth knowing: Code4rena — the platform that invented the format — shut down in May 2026. Its programs and wardens were absorbed by Immunefi, which now runs audit competitions of its own. The model survives, just under new roofs:
Sherlock runs insurance-backed contests: a protocol that passes a Sherlock audit can buy on-chain coverage, and typical pools run $50,000–$300,000.Cantina(Spearbit's marketplace) hosts the largest contests anywhere — $200,000 to $2M+ pools, over $46 million paid out — and a private-contest invitation there is the senior signal of web3 security. CodeHawks (Cyfrin) runs beginner-friendly contests where newer auditors build a first finding history.
Each contest is a fixed window (days to a few weeks), a fixed pool, and a public leaderboard that splits the pool by placement. The economics matter for an unemployed programmer: a top-10 finish usually pays four figures even when you don't win, so a skilled auditor earns on every contest rather than hoping for one windfall.
The contest meta-skill is different from bounty hunting: everyone is reading the same fresh codebase, so the money goes to unique, defensible findings with clean write-ups — not to racing the obvious issues first.
How to Choose — Three Paths
- You have web security skills. Start with HackerOne public programs plus one vendor program (Google or Microsoft), hunting scopes built on the stack you know best. After 10+ valid reports, apply to Synack and private program invitations.
- You know smart contracts (or are committed to learning).Immunefi for open-ended hunting and its audit competitions, Sherlock and Cantina for contests — start on CodeHawks if you're new to Solidity. This path has the highest payout ceiling per finding anywhere.
- You're starting from zero.Don't register anywhere yet. Spend 4–6 weeks on free training — PortSwigger Web Security Academy and YesWeHack Dojo — then hunt no-pay vulnerability disclosure programs (VDPs) for your first reputation, then paid scopes. Registering early and flailing costs you nothing but three months; training first costs you nothing at all.
The Honest Numbers
The "made $100k in a weekend" stories are real. They are also the top of an extremely skewed distribution. Most first payouts arrive after 1–3 months of consistent effort, and most reports pay in the hundreds of dollars. A handful of researchers earn the majority of all payouts, year after year.
So budget accordingly. Treat your first 90 days as paid training with lottery upside — the real compounding asset is the finding history you're building, which opens private programs, Synack, audit contests, and eventually salaried security roles.
Compared to the other fast stream on our income map: cash prize hackathons pay faster and more predictably — a weekend of work, prizes within weeks — while bounties pay slower at the base and far more at the tail. Many people run both, using hackathon money to bridge the ramp-up. If that sounds like you, start with the ranked feed on hackradar.win and hunt scopes in the evenings.
Your First 30 Days — A Checklist
- Pick one platform and one vendor program. Depth beats breadth.
- Choose 2–3 programs built on the stack you know best. Node backends? Mobile APIs? Go there.
- Read each program's scope and policy carefully — out-of-scope findings don't pay and can get you kicked.
- Reproduce every finding before reporting, and write the report like you're teaching: impact, steps, PoC.
- Keep a public page of your valid reports and hall-of-fame entries — it is your resume.
- After 10 valid reports: apply for private programs, Synack, or your first audit contest.
Pair It with the Fast Stream
Security work compounds — every valid report makes the next one easier to land. But the ramp is real, and rent isn't. The fastest way to put money in your account while your finding history builds is a weekend hackathon in your stack: open hackradar.win, pick your skills, and the feed ranks 400+ upcoming cash prize hackathons by expected return per day. Hunt bugs in the evenings, ship demos on the weekends — both pay in the same currency: shipped skill.