
Table of contents
17
By Salman Khan, OSCP+, Founder of XHack, SRT (Synack Red Team member)
Read this in 30 seconds: What bug bounty hunters make depends on which number you read, and most of the numbers online measure something other than a hunter’s income.
- The best income survey we found is old and small, but it’s real. In a peer-reviewed survey collected in 2019, 78% of respondents earned under $30,000 a year from bounties, and 29% earned under $1,000.
- Platform “averages” are often per program, not per hunter. HackerOne’s roughly $42,000 average yearly payout lines up with $81M spread across about 1,950 programs, not with what any one hunter takes home.
- Big-vendor means are dragged up by a few huge awards. Google’s $17M across 700+ researchers is under $24,300 each on paper, and the typical payout is far smaller.
- Salary sites measure job titles, not bounties. ZipRecruiter’s $43,637 is an estimate for people listed under “bug bounty,” not a record of what programs pay out.
- Our read: most new bug bounty hunters make a few hundred dollars, or nothing, in year one. The ceiling is real, with 30 HackerOne hackers past $1M lifetime, but it’s not where most people start.
Every number about what bug bounty hunters make is true about something, and almost none of them is true about you.
Search for what bug bounty hunters make and you’ll find everything from “$43,000 a year” to “$500K” screenshots to people who’ve never been paid. They aren’t contradicting each other so much as measuring different things: a salary-site estimate, a platform total divided by the wrong denominator, a vendor mean skewed by one record award, a survey of people who happened to answer.
We traced every figure about what bug bounty hunters make back to its source, labeled what each one actually measures, and did the arithmetic the headlines skip.

Here are the four figures about what bug bounty hunters make that you’ll run into most, and what each one is really counting:
Only the last one describes what individual bug bounty hunters make, and it has real limits. The rest of this article explains each, in that order of reliability.
The big programs publish totals, and the totals are impressive. HackerOne’s 2025 report cites $81M in payouts, which BleepingComputer’s coverage places in the July 2024 to June 2025 window, up 13% year over year. Google’s 2025 VRP review reports $17M to over 700 researchers, its highest ever, with a top single award of $250,000. Microsoft’s 2026 year in review reports more than $20M to 562 researchers.
Divide a total by a headcount and you get a mean. Here’s what those means are, and aren’t:
| Source | Total paid | Denominator | Arithmetic mean | What that mean actually is |
|---|---|---|---|---|
| Google VRP (2025) | $17M | 700+ researchers | under $24,300 | A mean over paid researchers, including a $250,000 top award |
| Microsoft (reported Aug 2026) | $20M+ | 562 researchers | about $35,600 or more | A mean over paid researchers, down from about $49,400 the year before |
| HackerOne (Jul 2024 to Jun 2025) | $81M | about 1,950 programs | about $41,500 | A per-program figure, not a per-hunter one |
Two things in that table deserve a closer look.
The HackerOne “average” isn’t what a hunter earns. BleepingComputer reports an “average yearly payout across all active programs” of about $42,000. HackerOne’s report page says it draws on 1,950 enterprise programs, and $81M divided by 1,950 is about $41,500. That’s close enough that we read it as a per-program average. That’s our arithmetic, since the page we could access doesn’t spell it out, but it’s the reading that fits.
More hunters means a smaller slice each. Microsoft paid more in total this year, more than $20M against $17M the year before, but recognized 562 researchers against 344. The total rose roughly 18% while the headcount rose 63%, so the mean per researcher fell about 28%, a little less if the true total is above $20M. When more people compete for a pool, what bug bounty hunters make shrinks even while the headline grows.
Every mean here also counts only researchers who were paid. Anyone who submitted and earned nothing isn’t in the denominator, so what bug bounty hunters make across everyone who tried is lower than any of these means.
At the top end, the numbers are real. HackerOne’s 2023 press release said thirty hackers had earned more than $1M on the platform, one past $4M, and BleepingComputer’s 2025 coverage says the top 100 all-time earners took $31.8M, about $318,000 each across their whole careers. Bugcrowd’s hacker page puts its average critical (P1) reward at $3,000. Those are the outcomes at the thin top, not the starting line.

The most useful income data we found comes from an academic paper, not a platform. Akgul et al., Bug Hunters’ Perspectives on the Challenges and Benefits of the Bug Bounty Ecosystem, won a Distinguished Paper Award at USENIX Security 2023. Its surveys ran from May to December 2019, and its demographics table reports yearly bounty income.
Here’s the income breakdown from its largest survey, the factor-rating study, for the 115 respondents who answered the income question:
| Yearly income from bug bounties | Respondents | Share |
|---|---|---|
| Under $1,000 | 33 | 28.7% |
| $1,000 to $29,999 | 57 | 49.6% |
| $30,000 to $74,999 | 13 | 11.3% |
| $75,000 or more | 12 | 10.4% |
The paper’s own table prints the third bracket’s lower bound as $29,999, which we read as a typo for $30,000. The smaller free-listing study shows the same shape: 10, 19, 5 and 10 respondents across the same four brackets.
Read it plainly: what bug bounty hunters make in this sample is under $30,000 a year for about 78% of respondents, and under $1,000 for roughly 29%. At the other end, about one in ten made $75,000 or more. What bug bounty hunters make isn’t a bell curve around some average. It’s a pile at the bottom and a long thin tail.
Respondents also weren’t full-timers. Of the 161 who answered the hours question, 87, about 54%, spent under 10 hours a week on bounties.
Three honest caveats come with this data.
It’s the best distribution we could find, not a census. We also couldn’t find a current per-hunter income distribution published by the platforms themselves.

Reporting on HackerOne’s survey of nearly 1,700 hackers, published in January 2018, put about 12% at $20,000 or more a year from bounties, the top 3% above $100,000, and the top 1.1% above $350,000. A quarter said bounties made up at least half their income, and 13.7% said 90 to 100%.
Those figures about what bug bounty hunters make are real, but they’re eight years old, and they come from people already active on one platform. They still get repeated without their date attached.
We also couldn’t trace the popular claim that “the top 1% earn more than the bottom 90% combined” to a primary source, so we’re not repeating it as fact.
ZipRecruiter’s bug bounty salary page lists an average of $43,637 a year, or $20.98 an hour, as of its August 8, 2026 update. It puts the middle of the range, the 25th to 75th percentile, between $36,000 and $46,000, with top earners at $50,000.
That band is the giveaway. What bug bounty hunters make doesn’t sit in a $10,000 window. In our best survey, 29% of respondents made under $1,000 and about 10% made $75,000 or more.
A salary site is estimating what people holding a “bug bounty” job title are paid. That’s a different population from independent hunters submitting to programs, and a different kind of income, a wage rather than a payout per valid finding. We couldn’t retrieve the page’s methodology note, so treat its exact figures as a rough signal at best.
A yearly figure for what bug bounty hunters make hides how much time went in. Here’s the same yearly income at three weekly hour levels. This is plain arithmetic, not survey data:
| Yearly bounty income | 5 hrs/week (260 hrs/yr) | 10 hrs/week (520 hrs/yr) | 20 hrs/week (1,040 hrs/yr) |
|---|---|---|---|
| $500 | $1.92/hr | $0.96/hr | $0.48/hr |
| $5,000 | $19.23/hr | $9.62/hr | $4.81/hr |
| $30,000 | $115.38/hr | $57.69/hr | $28.85/hr |
| $75,000 | $288.46/hr | $144.23/hr | $72.12/hr |
To match ZipRecruiter’s $20.98 an hour at 10 hours a week, a hunter needs about $10,900 a year. At 5 hours a week, about $5,500.
The honest reading: at the bottom of the distribution, bug bounty hunters make well under minimum wage per hour of work. At the top, they make far more than a salary. The middle is where most people live, and it rewards patience more than speed.
The data points to a handful of levers on what bug bounty hunters make, and most of them aren’t “be smarter.”
Bugcrowd’s Inside the Mind of a Hacker 2026 report, built on over 2,000 hackers, found 82% already use AI. That matters for what bug bounty hunters make in a specific way: if most hunters have the same assistant, AI alone isn’t an edge on the obvious bugs. It’s table stakes.
The limits are documented too. In HackerOne’s 2025 research, 58% of surveyed researchers said AI tools miss business-logic flaws and chained exploits. That’s where the larger payouts tend to live, so the stat cuts against the idea that AI automatically moves you up the income curve.
What AI does change is the cost of an attempt. In our own autonomous bug bounty agent runs, the agent solved a live CTF called “Deadbolt” fully autonomously in about three minutes. In a separate run documented in our AI VAPT services piece, pointed at a fintech bug bounty program with the instruction “recon, pick your own target, go,” it found, validated and packaged a working OAuth credential exposure in 25 minutes for about $5 in compute.
Those are our own runs, and one run isn’t an income forecast. The $5 was compute cost, not a payout. Faster recon lowers what each attempt costs you, not what bug bounty hunters make per finding, and it doesn’t protect you from a duplicate.
The cost side is worth doing the math on. XHack’s individual plans start at $20 a month, $240 a year, with a 7-day free trial and no credit card. For someone earning $999 a year, $240 is 24% of it. Our advice: use the free week to see whether the tooling produces a validated finding for you before paying for anything. We’d rather you spend $0 and learn it doesn’t fit than spend $240 hoping.
If you’re starting out, here’s how we’d use these numbers on what bug bounty hunters make. This is our judgment, built on the data above, not a forecast.
It ranges from nothing to six figures and beyond. In a peer-reviewed 2019 survey, 28.7% of respondents made under $1,000 a year, 49.6% made $1,000 to $29,999, 11.3% made $30,000 to $74,999, and 10.4% made $75,000 or more. Salary-site averages like $43,637 describe job titles, not bounty income.
We couldn’t find published income data specific to beginners. In the 2019 survey, 29% of respondents earned under $1,000 a year and about half worked under 10 hours a week. Our expectation, not a measured result, is that a first year of a few hundred dollars or less is common.
Bugcrowd’s hacker page states an average P1 (critical) reward of $3,000. We couldn’t verify a cross-platform average payout across all severities. HackerOne’s roughly $42,000 “average” appears to be per program, not per report or per hunter.
As of HackerOne’s October 2023 press release, thirty hackers had earned more than $1M on the platform, with one past $4M in total earnings. In 2025, Google’s VRP paid a single award of $250,000, its top that year.
Some bug bounty hunters make a living from it. In HackerOne’s survey reported in January 2018, 13.7% of respondents said bounties made up 90 to 100% of their annual income. But most don’t: in the 2019 survey, 78% earned under $30,000 a year.
We couldn’t find verified income data showing it does. Bugcrowd reports 82% of hackers already use AI, so it isn’t a differentiator by itself, and 58% of researchers in HackerOne’s research say AI tools miss business-logic flaws. It lowers the cost of an attempt, which is a different thing from raising what the finding pays.
What bug bounty hunters make isn’t one number. It’s a pile at the bottom, a working middle, and a thin top where the headline figures come from. The best distribution we found has 29% under $1,000 and 10% above $75,000, and the platform averages you’ll see most often measure programs, vendors and job titles instead.
Go in treating bounty hunting as skill-building that sometimes pays, track your hours so you know your real rate, and spend on tools only after you’ve proven you can land a valid finding. If you want to try AI tooling alongside that, the free week costs nothing.
Categories
Related articles