HackerOne has reported a significant increase in bug bounty payouts, distributing $81 million to ethical hackers worldwide over the past 12 months, marking a 13% year-over-year growth. The platform, which manages over 1,950 bug bounty programs for major organizations such as Anthropic, Crypto.com, General Motors, GitHub, Goldman Sachs, Uber, and the U.S. Department of Defense, has seen its top 100 programs alone pay out $51 million between July 2024 and June 2025. The average annual payout per active program reached nearly $42,000, with the top 10 programs accounting for $21.6 million. Individual researchers are now consistently earning six-figure sums, and the top 100 all-time earners collectively received $31.8 million. A notable trend in the past year has been the dramatic rise in AI-related vulnerabilities, with prompt injection flaws increasing by 540% and overall AI security issues rising by more than 200%. This surge is attributed to both the expansion of enterprise AI security initiatives—growing at nearly three times last year's pace—and the emergence of 'bionic hackers' who leverage AI tools to enhance vulnerability discovery. In 2025, 1,121 bug bounty programs on HackerOne included AI in their scope, representing a 270% year-over-year increase, and autonomous AI-powered agents submitted over 560 valid reports. While traditional vulnerabilities such as cross-site scripting (XSS) and SQL injection (SQLi) have declined, authorization-related flaws, including insecure direct object reference (IDOR) and improper access control, are on the rise. HackerOne's CEO, Kara Sprague, highlighted the unprecedented scale at which security issues are being discovered due to the integration of AI in both offensive and defensive security practices. The company also noted that 70% of surveyed researchers have incorporated AI tools into their workflows, further accelerating the identification of vulnerabilities. The data underscores a shift in the threat landscape, with AI security becoming a primary concern for organizations participating in bug bounty programs. The increased payouts reflect both the growing complexity of vulnerabilities and the value organizations place on proactive security research. HackerOne's annual report serves as a barometer for industry trends, indicating that as AI adoption accelerates, so too does the need for robust security measures and incentives for ethical hackers. The platform's continued growth and the rising sophistication of its researcher community suggest that bug bounty programs will remain a critical component of organizational security strategies. The findings also emphasize the importance of adapting vulnerability management processes to address emerging threats, particularly those associated with AI technologies. As enterprises expand their AI initiatives, the collaboration between organizations and the ethical hacking community is proving essential in mitigating evolving risks. The report concludes that the intersection of AI and cybersecurity will continue to shape the future of vulnerability discovery and remediation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
HackerOne disclosed that it paid out $81 million in bug bounties during the preceding 12 months, marking an increase in rewards to security researchers on its platform. Multiple outlets reported the same annual payout update as a company milestone.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.