HackerOne’s “Top 10 Bug-Bounty Programs” ranking, reported by Dark Reading on June 30, 2020, put Verizon Media at No. 1 for a second consecutive year and Airbnb at No. 10. The report identifies several other programs and the factors used to judge them, but it does not reproduce an ordered list of all ten or explain a complete scoring formula. These are historical figures, not a current leaderboard.
Which bug bounty programs did the report identify?
Dark Reading named Verizon Media as the top-ranked program and Airbnb as No. 10. Between those endpoints, it also named PayPal, Uber, GitLab, and Mail.ru. Its accessible report does not establish the exact positions of those four companies or list all ten programs, so a complete ranking cannot be reconstructed from the published details.
| Program or group | What Dark Reading reported in 2020 |
|---|---|
| Verizon Media | No. 1 for the second consecutive year; more than $9.4 million paid in bounties as of April, and a top single bounty of $70,000. |
| PayPal, Uber, GitLab, and Mail.ru | Named among the programs between the first and tenth entries. The report gave a combined range of $3 million to $987,000 in total bounties, but did not assign individual totals or precise positions to these companies. |
| GitLab | One-hour average response time. |
| Eight-day average interval from bug report to bounty payment. | |
| Airbnb | No. 10, with $944,000 in total payouts and a top bounty of $15,000. |
These figures are those reported in 2020; they do not establish the programs’ present status, payout totals, response times, or rankings. The report’s $3 million-to-$987,000 range applies to the intervening named programs collectively, not to a specific company in the table.
How did HackerOne’s top bug bounty programs get ranked?
According to Dark Reading’s 2020 report, ranking factors included:
#1 Best Overall
- Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
- No Starch Press
- ABIS BOOK
- Total bounties paid
- The largest single bounty paid
- Time to respond
- Time to pay a bounty
- The number of hackers involved
The report does not state how much weight each factor carried, provide a precise calculation, or specify the ranking’s geographic scope. It therefore describes relevant measures, not a reproducible score. The published information is also too limited to compare every named program across every measure.
Why payout totals do not tell the whole story
A large cumulative payout can show that a program has paid researchers, but it does not by itself indicate how quickly reports receive attention or how effectively vulnerabilities are fixed. Response time, time to payment, and researcher participation offer additional operational signals. Even these measures need context: report volume and severity, for example, affect what a response-time average means.
Rank #2
In later program-management guidance published on November 2, 2021, HackerOne recommends measuring report volume, valid reports, severity, vulnerability categories, researcher invitations and acceptance, acknowledgment and resolution times, and bounty payment times. These metrics can help a team diagnose its process; they are not standalone proof that a system is secure.
The guidance also says recurring vulnerability categories across assets may point to underlying causes, and that frequent categories can inform developer training or code-review improvements. Allie Lugton, a HackerOne program manager, described using remediation-time and vulnerability-trend data to help development teams address recurring issues. Her comments appeared in the 2021 guidance, not in the 2020 ranking report.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
How the program ranking differs from HackerOne’s vulnerability Top 10
HackerOne published a separate Top 10 in 2019 covering vulnerability categories seen in platform data. It was not a ranking of bug-bounty programs. The category list, in order, was cross-site scripting; improper authentication; information disclosure; privilege escalation; SQL injection; code injection; server-side request forgery; insecure direct object reference; improper access control; and cross-site request forgery.
HackerOne’s 2019 article said 1,400 bug bounties had produced more than 360,000 valid vulnerabilities over seven years. It also said that its platform’s vulnerability Top 10 represented 90% of vulnerabilities captured on the platform, while only 50% of those vulnerabilities appeared on OWASP’s Top 10. Those are claims about that article’s 2019 platform dataset; they do not describe the 2020 company-program ranking or current platform data.
Quick Recap
Sources
- Dark Reading Editorial Team, “HackerOne Reveals Top 10 Bug-Bounty Programs” (June 30, 2020)
- HackerOne, “Hacker-Powered Data – Security Weaknesses and Embracing Risk with HackerOne” (August 26, 2019)
- HackerOne, “How to Use Bug Bounty Program Data to Improve Security and Development” (November 2, 2021)
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

