Bugcrowd Acquires Mayhem Security to Bring Human-Augmented AI Automation to Security Testing
Read More
Hacker Login
Customer Login
Contact Us
Talk to an Expert
Menu
Close menu
Hacker Login
Customer Login
Contact Us
Engagements
Talk to an Expert
Platform & Solutions
Overview
Bugcrowd Platform
Engineered Triage
CrowdMatch™
Integrations
Vulnerability Rating Taxonomy
Products
Penetration Testing
Pen Test as a Service
Continuous Attack Surface Pen Testing
AI Pen Test
Web Application Pen Test
Mobile App Pen Test
Network Pen Test
API Pen Test
IoT Pen Test
Cloud Pen Test
Social Engineering Pen Test
Red Team as a Service
AI Bias Assessment
Bug Bounty
Vulnerability Disclosure
Attack Surface Management
Solutions
AI Safety & Security
Application and Cloud Security
Vulnerability Intake and Coordination
IoT and Web3
Marketplace Apps
Mergers & Acquisitions
Social Engineering
By Industries
Financial Services
Healthcare
Retail
Automotive
Technology
Government
Security Companies
Why Bugcrowd
Why Bugcrowd
Why Crowdsourcing is Better
The Bugcrowd Difference
Our Customers
Our Customers
Resources
Resource Library
All Resources
Documentation
Blog
Case Studies
Glossary
FAQ
Code of Conduct
Platform Behavior Standards
Webinars
Events
Company
About Us
About Us
Our Customers
Leadership
Partners
Careers
Press Releases
Contact Us
In the News
Events
Blog
Diversity & Inclusion
Compliance and Security
For Hackers
Hack with us
Engagements
CrowdStream
Start Hacking
Help Wanted
FAQs
Learn with us
Hacker Docs
Bugcrowd University
Community
Leaderboard
Bugcrowd News
4 Years of Bugcrowd’s Bug Bounty: Evolution and Learnings
November 21, 2016 | By
Casey Ellis | Founder and Advisor
Back to blog
Here at Bugcrowd we take our own advice. Four years ago yesterday we launched Bugcrowd’s first bounty program to uncover vulnerabilities in our own applications and web assets.
To improve our own security, as well as make a better product for our customers, we’ve prioritized and evolved our bug bounty program over the past four years. From private to public, continuous and time-boxed, we’ve implemented many types of bug bounty programs on our own applications and web properties over the past four years and have seen amazing contributions from our bug hunting community…
First Bounties
We kicked off our first bug bounty as a time-boxed, open program with cash reward pool on a web app designed specifically for bounty testing. The second program launch was also a time-boxed, Kudos-only program.
Public Bug Bounty Program
In September 2013 we rolled out our own bug bounty on bugcrowd.com,
an ongoing public program with cash rewards
. This continuous testing offers us a breadth of testing that wouldn’t be possible with other application security testing. We’ve upped rewards since on our public program wherein our minimum reward prize has been $500 with a max of $5,000.
On-Demand Programs
We’ve run multiple private On-Demand Programs on
Crowdcontrol
, our vulnerability management platform, since the beginning of 2015. We run what are essentially 2-week crowdsourced penetration tests with focused testing for major releases and invite-only pools of researchers.
Thanks to everyone who has contributed to our bounty programs!
The volume and quality of testing that we’ve seen not only helps us keep our customer data safe but also helps us build a more powerful and intuitive product. We hope that the community continues to support our endeavor to uphold the highest standard of product security, and look forward to the future iterations of our program, and the bug bounty ecosystem in general.
Want to learn more about Bugcrowd’s bounty program? Read more here and check out all of our
public programs.
More from the blog
Cybersecurity News
CVE-2025-55182: What you need to know about React2Shell
By Michael Skelton | SVP of Operations, Dec 04, 2025
Read More
Hacker Resources
How I hacked my way to a million dollars: HX007
By Guest Post, Dec 04, 2025
Read More
Thought Leadership
Security flash: The hacklore project
By Erica Azad, Dec 02, 2025
Read More
Subscribe for updates
Close