The Internet Bug Bounty was announced in 2013 as a community-funded effort to reward discoveries in open-source software and shared Internet infrastructure. Dark Reading reported that Microsoft and Facebook sponsored its initial round under HackerOne, with rewards that varied by the type of flaw. Those figures and terms describe the announcement era; they are not verified current rates or proof that the program is still active.
What the Internet Bug Bounty was
In a November 7, 2013 report, Dark Reading described the Internet Bug Bounty as a newly launched community bug bounty program administered under HackerOne and initially funded by Microsoft and Facebook. The goal was to encourage disclosure of vulnerabilities in components used across many products and services, rather than focus only on a single company’s software. Facebook product security lead Alex Rice called it “a broader community effort” involving participants from different backgrounds. Dark Reading’s launch report is the source for the program details below.
What the launch-era scope included
Dark Reading listed three broad categories of targets. The examples below reflect the 2013 report, not a confirmed current scope.
- Open-source software: OpenSSL, Python, Ruby, PHP, Django, Rails, Perl, Phabricator, Nginx, and Apache httpd. The source article printed “Ngix”; Nginx is the standard spelling.
- Sandbox technologies: The report included sandbox flaws as a separate category but did not name particular technologies in the cited account.
- Shared Internet infrastructure: Examples included DNS, SSL, and PKI.
The emphasis on shared components helps explain the program’s rationale: a vulnerability in a widely used project or protocol can affect multiple products and many users.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesWhat rewards Dark Reading reported in 2013
The following amounts were reported at launch by Dark Reading in 2013. They should be read as historical figures, not as present-day offers.
#1 Best Overall
- Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities
- No Starch Press
- ABIS BOOK
| Reported category | Announcement-era amount |
|---|---|
| Qualifying new vulnerabilities in the listed open-source projects | $300 to $2,500 |
| Working flaws in sandbox technologies | Minimum $5,000 |
| Qualifying flaws in Internet infrastructure such as DNS, SSL, or PKI | Minimum $5,000 |
The article also described two rewards associated with a bug: one for finding it and one for fixing it. It did not provide a complete schedule establishing that every accepted finding led to two payments, so the statement should not be treated as a universal doubling rule.
Which findings could qualify
The 2013 report said Internet-related bugs could qualify when they affected multiple products, affected a significant number of users, or were severe or novel. These are broad criteria as reported at launch, not a complete submission checklist. A finding in a named project did not automatically qualify merely because the project appeared in the article.
Rank #2
Who was involved in the launch
Dark Reading described a volunteer panel that included security staff from Microsoft and Facebook, Chrome’s Chris Evans, iSec Partners’ Jesse Burns, and Etsy’s Zane Lackey. Microsoft security strategy lead Katie Moussouris characterized the effort as support for coordinated disclosure of critical vulnerabilities in shared Internet components. These are launch-era governance details from the 2013 report, not confirmation of the program’s current administration.
What to check before treating it as a current bounty
The 2013 announcement does not establish whether the Internet Bug Bounty remains active, what it currently covers, or how much it pays. HackerOne’s Vulnerability Disclosure Standards, version 1.3 updated July 27, 2026, provide general platform guidance rather than Internet Bug Bounty-specific terms. They say each security team publishes its own policy for scope and participation, and that researchers should consult that policy because it may supersede general guidance. The standards also call for detailed reports with reproducible steps or a working proof of concept; monetary rewards are not guaranteed, and the security team decides whether to offer one and at what amount.
Accordingly, do not rely on the old scope list or dollar amounts to submit a current finding or expect payment. Verify the specific program policy and its current status first.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

