HackerOne has announced a significant increase in maximum bug bounty payouts across its platform, with top-tier critical vulnerabilities now eligible for rewards up to $250,000 — a 67% increase from the previous $150,000 cap.
The move comes as organizations increasingly recognize the value of external security researchers in identifying critical vulnerabilities before malicious actors. Key changes include:
- Critical RCE/Auth Bypass — Up to $250,000 (was $150,000)
- SSRF with Cloud Metadata Access — Up to $75,000 (was $50,000)
- Stored XSS with Session Theft — Up to $25,000 (was $15,000)
- IDOR with PII Exposure — Up to $50,000 (was $30,000)
The platform also introduced a new “Rapid Response” bonus of 25% for researchers who report critical vulnerabilities within 72 hours of a new program launch.