Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

HackerOne’s “Top 10 Bug-Bounty Programs” ranking, reported by Dark Reading on June 30, 2020, put Verizon Media at No. 1 for a second consecutive year and Airbnb at No. 10. The report identifies several other programs and the factors used to judge them, but it does not reproduce an ordered list of all ten or explain a complete scoring formula. These are historical figures, not a current leaderboard.

Which bug bounty programs did the report identify?

Dark Reading named Verizon Media as the top-ranked program and Airbnb as No. 10. Between those endpoints, it also named PayPal, Uber, GitLab, and Mail.ru. Its accessible report does not establish the exact positions of those four companies or list all ten programs, so a complete ranking cannot be reconstructed from the published details.

Program or group What Dark Reading reported in 2020
Verizon Media No. 1 for the second consecutive year; more than $9.4 million paid in bounties as of April, and a top single bounty of $70,000.
PayPal, Uber, GitLab, and Mail.ru Named among the programs between the first and tenth entries. The report gave a combined range of $3 million to $987,000 in total bounties, but did not assign individual totals or precise positions to these companies.
GitLab One-hour average response time.
Twitter Eight-day average interval from bug report to bounty payment.
Airbnb No. 10, with $944,000 in total payouts and a top bounty of $15,000.

These figures are those reported in 2020; they do not establish the programs’ present status, payout totals, response times, or rankings. The report’s $3 million-to-$987,000 range applies to the intervening named programs collectively, not to a specific company in the table.

How did HackerOne’s top bug bounty programs get ranked?

According to Dark Reading’s 2020 report, ranking factors included:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
  • Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
  • No Starch Press
  • ABIS BOOK
  • Total bounties paid
  • The largest single bounty paid
  • Time to respond
  • Time to pay a bounty
  • The number of hackers involved

The report does not state how much weight each factor carried, provide a precise calculation, or specify the ranking’s geographic scope. It therefore describes relevant measures, not a reproducible score. The published information is also too limited to compare every named program across every measure.

Why payout totals do not tell the whole story

A large cumulative payout can show that a program has paid researchers, but it does not by itself indicate how quickly reports receive attention or how effectively vulnerabilities are fixed. Response time, time to payment, and researcher participation offer additional operational signals. Even these measures need context: report volume and severity, for example, affect what a response-time average means.

In later program-management guidance published on November 2, 2021, HackerOne recommends measuring report volume, valid reports, severity, vulnerability categories, researcher invitations and acceptance, acknowledgment and resolution times, and bounty payment times. These metrics can help a team diagnose its process; they are not standalone proof that a system is secure.

The guidance also says recurring vulnerability categories across assets may point to underlying causes, and that frequent categories can inform developer training or code-review improvements. Allie Lugton, a HackerOne program manager, described using remediation-time and vulnerability-trend data to help development teams address recurring issues. Her comments appeared in the 2021 guidance, not in the 2020 ranking report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How the program ranking differs from HackerOne’s vulnerability Top 10

HackerOne published a separate Top 10 in 2019 covering vulnerability categories seen in platform data. It was not a ranking of bug-bounty programs. The category list, in order, was cross-site scripting; improper authentication; information disclosure; privilege escalation; SQL injection; code injection; server-side request forgery; insecure direct object reference; improper access control; and cross-site request forgery.

HackerOne’s 2019 article said 1,400 bug bounties had produced more than 360,000 valid vulnerabilities over seven years. It also said that its platform’s vulnerability Top 10 represented 90% of vulnerabilities captured on the platform, while only 50% of those vulnerabilities appeared on OWASP’s Top 10. Those are claims about that article’s 2019 platform dataset; they do not describe the 2020 company-program ranking or current platform data.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.