Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. Sony Interactive Entertainment opened a public PlayStation bug bounty program on HackerOne on June 24, 2020. Sony’s launch announcement named the PlayStation 4 and PlayStation Network as targets, with critical PS4 vulnerabilities eligible for bounties starting at $50,000 at launch. The current policy should be checked before testing: a later policy record lists PS5, operating systems and accessories too, but that record is a secondary mirror.

What Sony announced in 2020

Sony Interactive Entertainment opened its PlayStation Bug Bounty Program to the public on June 24, 2020, partnering with HackerOne. The program had previously been private, with selected researchers invited to participate. Geoff Norton, then Senior Director of Software Engineering at PlayStation, wrote: “We believe that through working with the security research community we can deliver a safer place to play.”

The launch announcement invited security researchers, gamers and others to test PlayStation 4 and PlayStation Network security. Sony’s launch post describes that original scope.

What systems and services are in scope?

At launch, Sony named PS4 and PlayStation Network. A later policy record lists PS4 and PS5 systems, their operating systems and accessories, and PlayStation Network; it also says submissions are accepted for current released or beta system software. That record is a secondary mirror, not the authoritative live policy. Before any testing, use the current PlayStation program page on HackerOne to confirm eligible targets, versions and rules. Scope can change, and a device or service being PlayStation-branded does not by itself mean it is eligible.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How much does Sony pay for PlayStation bugs?

Sony said in 2020 that critical PS4 vulnerabilities had bounties starting at $50,000. This is a historical launch figure, not a promise about current rewards or a stated maximum PS4 payout. TechCrunch reported at launch that the HackerOne page showed more than $170,000 paid to researchers and an average bounty of around $400. Those figures describe the program at that time; they are not the current payout table.

Rewards are discretionary and governed by the program’s policy. Eligibility, severity, report quality and other policy terms can affect whether a submission earns a reward. Read the live policy rather than relying on launch-era coverage or figures.

How to submit a PlayStation bug bounty report

  1. Read the live policy first. Open the PlayStation program on HackerOne and check the current in-scope assets, accepted software versions, exclusions, testing limits and disclosure rules.
  2. Test only an eligible target, with minimal impact. Avoid disrupting services, accessing other users’ data or expanding testing beyond what the policy permits.
  3. Document a reproducible finding. Explain the affected target and conditions, then provide clear steps that allow the security team to verify the issue. Include relevant evidence without exposing third-party personal data.
  4. Submit privately through the program’s HackerOne report flow. Do not publicly disclose the vulnerability unless Sony’s policy authorizes disclosure or Sony has coordinated a disclosure with you.
  5. Respond to follow-up questions through the report. Sony’s Secure@Sony page says reporters can expect a response within 5 business days and a status update within 30 business days. These are stated targets, not a guarantee of resolution or payment by those dates.

HackerOne’s disclosure guidance recommends clear, reproducible reports and says not to include third-party personal data. It also explains that rewards are discretionary and determined by each program’s policy. Sony’s reporting information is on Secure@Sony.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can anyone participate?

The program was publicly opened to the security research community, gamers and anyone else, rather than remaining limited to Sony’s selected private researchers. Public availability does not mean every kind of testing is allowed or every report qualifies for a reward. Anyone considering participation should follow the current HackerOne policy and applicable law, and should avoid testing accounts, devices or information they do not own or have permission to assess.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.