
Table of contents
18
By Salman Khan, OSCP+, Founder of XHack, SRT (Synack Red Team member)
Read this in 30 seconds: Bug bounty vs freelance pentesting isn’t a pay comparison between two jobs. It’s a comparison between two ways of being paid: per finding, or per day.
- Freelance pentesting has a floor, bug bounty doesn’t. UK contractor vacancies show a median day rate of £675 across 40 postings in the six months to October 7, 2026. In a 2019 survey, about 29% of bounty hunters earned under $1,000 a year.
- Bug bounty has a tail, freelancing mostly doesn’t. About 10% of that survey earned $75,000 or more. Freelance income is capped by the days you can sell.
- The two have different gates. Bounty needs only a laptop and a scope page. Freelancing needs a buyer, a contract, insurance and a report a client will accept.
- Per hour worked, freelancing usually pays better for people who can find clients. That’s our reading of the data, not a measured result.
- The most practical answer is sequencing, not choosing. Use bounty to build proof, platform or direct freelancing to get paid days.
People ask which pays better as if both pay for the same thing, and that’s the mistake that makes most answers useless.
Bug bounty vs freelance pentesting comes up whenever someone with offensive skills asks how to turn them into income. A bounty program pays when you find a valid, unique, in-scope bug. A client pays a freelancer for time or a fixed scope, whether or not the test finds anything critical. Those are different bets with different risks.
This article puts the best public bug bounty vs freelance numbers next to each other, labels what each number does and doesn’t measure, and ends with a test you can run on yourself.

Start with what each side pays for, because everything else follows from it.
| Bug bounty | Freelance pentesting | |
|---|---|---|
| Paid for | A valid, in-scope, non-duplicate finding | Days of work or a fixed-scope project |
| Income floor | Zero | Day rate times days sold |
| Who pays | The program, after triage | The client, by contract and invoice |
| First dollar needs | One accepted finding | One client who trusts you |
| Deliverable | A report on one bug | A report on the whole engagement |
| Legal cover | The program’s safe-harbor terms | A signed authorization and scope |
| Admin load | Low | Invoicing, tax, insurance, scoping |
A bounty hunter can do excellent work for a month and be paid nothing, because someone else reported the same bug first. A freelancer who tests carefully and finds nothing is still paid, because the client bought the effort and the assurance.
That’s why bug bounty vs freelance pentesting is really a question about risk. Who carries it: you, or the client?
There’s no single census of freelance pentester earnings, so we looked at three different kinds of number. They describe different things, and mixing them up is how people end up quoting £1,000 a day as their own take-home.
| Number | What it describes | Source type |
|---|---|---|
| £675 a day (UK contractor median) | Advertised day rate for individual contractors | Job-vacancy aggregator |
| £1,000 a day (UK rate-card median) | What clients pay a firm for a tester | Vendor blog, public rate cards |
| $1,200 to $3,000 a day (senior, boutique) | What a boutique firm quotes for a senior tester | Vendor pricing guide |
The contractor number. IT Jobs Watch, which aggregates UK contract vacancies, shows a median daily rate of £675 for penetration tester contracts across the six months to October 7, 2026, up about 23% year over year. The 25th to 75th percentile band is £638 to £712. Outside London the median is £466. It rests on only 40 postings, and these are advertised rates, not invoices paid, so treat it as a rough marker. A search-result snapshot of the same page, covering data to January 2026, listed a median of £534 on 109 postings. We didn’t verify that snapshot directly, but the gap is a reminder of how far a small sample can move.
The firm number. The vendor Stingrai compiled 30 UK public rate cards and reports a median of £1,000 a day, a central band of £800 to £1,200, and a range of £480 to £1,600. Stingrai sells pentesting, so it isn’t neutral, but it links its sources. Our inference: the gap between £1,000 and £675 is the firm’s overhead, sales and margin, which is roughly what a freelancer gives up or takes on.
The boutique number. Synack’s June 2026 pricing guide estimates senior boutique testers at $1,200 to $3,000 a day and specialist researchers at $150 to $400 an hour. These are the prices clients see, and Synack sells testing too.

There’s a middle route that sits between bug bounty vs freelance pentesting. Cobalt runs a vetted community of freelance pentesters and says it pays them for their time and effort, not per finding. Its community has more than 250 members, and, per Cobalt’s community post, joining involves a technical skills assessment, a demonstration of your report writing, an interview and a vetting process.
That gives you paid days without finding every client yourself. The trade-offs are the vetting bar, the platform setting the rate, and the fact that we couldn’t find a published pay scale.
We covered this in depth in how much bug bounty hunters make, so here are the numbers that matter for this comparison.
The best distribution we found is from Akgul et al., a USENIX Security 2023 paper. In its largest survey, of 115 hunters who reported income from surveys run in 2019:
| Yearly bounty income | Share |
|---|---|
| Under $1,000 | 28.7% |
| $1,000 to $29,999 | 49.6% |
| $30,000 to $74,999 | 11.3% |
| $75,000 or more | 10.4% |
So about 78% earned under $30,000 and about 10% earned $75,000 or more. Of the 161 who answered the hours question, about 54% spent under 10 hours a week on it. Those caveats apply: the data is from 2019, self-selected, and about 42% of respondents lived in South Asia, where a dollar goes further.
The tail is real. HackerOne said in 2023 that thirty hackers had earned more than $1M on its platform and one more than $4M. But a tail isn’t a plan. Bug bounty vs freelance income looks very different depending on whether you’re the median hunter or the 10th-percentile-from-the-top one.
The cleanest bug bounty vs freelance comparison is money per hour, with an honest note about reliability.
For the freelance side, a £675 day over a 7.5-hour working day is £90 an hour billed. The 7.5-hour day is the convention Stingrai uses, and the division is our arithmetic. That’s billed time, and you don’t bill every working hour.
For the bounty side, take the US employee benchmark as a yardstick. The Bureau of Labor Statistics reports a median wage of $129,180 for information security analysts in May 2025, which is $62.11 an hour. A hunter working 10 hours a week, 52 weeks a year, would need about $32,300 a year to match it. In the 2019 survey, only about a fifth of respondents reported $30,000 or more.
The trap on the freelance side is billable days. Here’s what a £675 day produces at different levels of work actually sold. It’s our illustration, not a survey result, and every figure is before tax, insurance and unpaid time.
| Billable days sold in a year | Gross at £675 a day |
|---|---|
| 100 | £67,500 |
| 150 | £101,250 |
| 200 | £135,000 |
There are about 260 weekdays in a year. A freelancer who sells 150 of them is doing well, and that already leaves 110 days for holidays, sales, scoping, reporting and gaps between clients. Bug bounty vs freelance on this scale: freelancing converts hours into money more reliably, and the limit is how many days you can sell.

The gross day rate is not your income. These are the costs and frictions that most bug bounty vs freelance comparisons leave out.
None of this makes freelancing a bad idea. It means the £675 is the start of the bug bounty vs freelance calculation, not the end.
In the bug bounty vs freelance cost comparison, bounty’s hidden costs mostly show up as lost time.
The upside is that none of this requires a client to trust you first, which is the biggest difference in bug bounty vs freelance risk.
Answer these four honestly. In bug bounty vs freelance decisions, they matter more than the day rate does.
| If this describes you | Lean toward |
|---|---|
| New to the field, no clients, some free time | Bug bounty, as paid learning and proof |
| Employed in security, want side income | Bug bounty on weekends, or platform freelancing |
| Have a track record and a few contacts | Direct freelancing, with bounty on the side |
| Need predictable income soon | Freelancing, or a salaried role |
For the company-side framing of the same decision, see bug bounty vs penetration testing, which is written for the buyer.

This section is our recommendation, not a measured result.
Treat bug bounty vs freelance as a sequence. Start with bounty on a few programs whose scope and rules you’ve read, and write reports as if a client would read them. Use that record, plus a certification if you choose to get one, to apply to a platform like Cobalt or to approach a first direct client. Keep a small amount of bounty time running once you’re freelancing, because it keeps your testing sharp and costs nothing to maintain.
If you want the starting steps, our guide to becoming a bug bounty hunter covers them.
Whichever way your bug bounty vs freelance decision goes, we build XHack AI for bug hunters and independent testers. We’re not neutral, so here is what it does rather than a ranking.
Two limits matter for freelancers. The agent doesn’t give you a client, a contract or the right to test a target, so work only on systems you have written authorization for. And it produces draft evidence, so you still review every finding before it reaches a client.
For what testing costs from the buyer’s side, see our AI penetration testing cost guide. Individual plans start at $20 a month, with a 7-day free trial and no credit card.
Per hour worked, freelancing usually pays better for people who can find clients, because a day rate is agreed in advance. Bug bounty pays better only in its thin tail. In a 2019 survey, about 10% of hunters earned $75,000 or more, while about 78% earned under $30,000.
Yes, once you have a contract, because you’re paid for the time even if the test finds little. The instability moves to finding the next client. Bounty has no floor at all, since a month of work can pay nothing.
There’s no census. UK contract vacancies show a median advertised day rate of £675 across 40 postings in the six months to October 7, 2026. UK vendor rate cards show a median of £1,000 a day, which is what a client pays a firm. Your take-home depends on billable days, tax and insurance.
Yes, and many people do, so bug bounty vs freelance doesn’t have to be a permanent choice. Check your client contracts and any employer policy first, since some restrict outside testing. Keep the two separate: never test a client’s systems under a bounty scope, or a bounty target under a client’s authorization.
We found no rule that requires one for freelancing in general. Some clients and platforms ask for them, and that’s an inference from how buyers vet testers, so ask your target clients. Bounty programs don’t ask for certifications.
Usually bounty first, because it has no gatekeeper and costs nothing to try. Move toward freelancing as you build a record and contacts.
Bug bounty vs freelance is a question about how you want to be paid and who should carry the risk. Freelancing carries less income risk once you have clients, and costs you the work of finding them. Bounty needs no one’s permission to start, and pays unevenly.
Use bounty to build proof, use platform or direct work to get paid for your days, and be honest about the costs on both sides.
Categories
Related articles