What the programmes
are actually doing
National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program led with 21 accepted findings, 12 programmes opened up, 10 went quiet.
The window moves active now, what just opened, where nobody is looking and what changed pace. The money, targets, severity and researcher reads are marked whole corpus and do not move with it: a week holds too few of each to read.
Where findings are landing
Programmes that accepted the most in the last 7 days, with the two things that separate a busy programme from a crowded one: how many different people are landing findings, and whether the platform showed money against any of them.
| Programme | Accepted | Finders | Crit/high | Paid | Last seen |
|---|---|---|---|---|---|
| National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program | 21 | 15 +5 withheld | 6 | not set | yesterday |
| Bitdefender | 15 | 12 +2 withheld | 7 | $25,000 | yesterday |
| City of Vienna Managed Bug Bounty | 13 | 8 +2 withheld | 6 | $10,725 | 4 days ago |
| Petpooja Vulnerability Disclosure Program | 10 | 5 | 2 | not set | 3 days ago |
| Atlassian | 10 | 5 +5 withheld | 2 | $825 | 2 days ago |
| US Environmental Protection Agency Vulnerability Disclosure | 10 | 4 +1 withheld | not set | not set | 2 days ago |
| Intercom | 10 | 1 +8 withheld | 2 | not set | 4 days ago |
| United Airlines | 9 | 2 +5 withheld | 5 | not set | yesterday |
| Mastercard Public Bug Bounty | 8 | 4 +3 withheld | 2 | $630 | 2 days ago |
| State of California VDP | 8 | 2 +5 withheld | 3 | not set | 2 days ago |
| Department of Homeland Security: Vulnerability Disclosure Program | 6 | 3 | 2 | not set | 3 days ago |
| ClickHouse | 6 | 1 +5 withheld | not set | not set | 2 days ago |
What the work has paid whole corpus
Every figure here is built only from amounts a platform actually printed, and only in US dollars, the one currency with enough rows to sum honestly. Because a single week carries only a handful of published awards, this is the picture across everything on file, not the selected window.
A shown amount is rare. Bugcrowd seldom publishes a figure at all, and HackerOne shows one only on the minority of reports both sides later disclosed. So these 1,493 awards are the ones that happened to be printed, out of 6,728 events, and every total here is a floor. A programme with no amount against it may pay very well and simply never say so.
How large the shown awards were
- under $250 390 26%
- $250–999 623 42%
- $1k–5k 349 23%
- $5k–10k 64 4%
- $10k and up 67 4%
What a shown award was worth, by severity
Read as "when a finding at this severity was paid and the amount was published, here is the spread". It is not what a severity pays in general: the rows that carried no figure are not in it.
| Severity | Awards shown | Low | Typical | High | Total |
|---|---|---|---|---|---|
| Critical | 192 | $300 | $7,886 | $133,700 | $1,514,180 |
| High | 268 | $100 | $3,462 | $80,000 | $927,700 |
| Medium | 581 | $50 | $640 | $10,000 | $371,845 |
| Low | 438 | $20 | $197 | $1,000 | $86,409 |
| None | 8 | $25 | $163 | $500 | $1,300 |
| Unrated | 6 | $100 | $4,150 | $12,500 | $24,900 |
How the platforms differ in what they show
| Platform | Accepted | Amounts shown | Disclosed | Total shown |
|---|---|---|---|---|
| bugcrowd | 5,807 | 1,426 (25%) | 538 | $2,802,670 |
| hackerone | 921 | 67 (7%) | 921 | $123,664 |
The gap between "accepted" and "amounts shown" is mostly publication policy, not generosity. HackerOne rows are here only because a report was disclosed at all, so its "disclosed" count matches its accepted count by construction; Bugcrowd discloses a subset and prints an amount on fewer still.
Programmes seen to pay in the open
Programmes with at least one published award, most paid-out first. "Shown" is how many of their acceptances carried a visible figure, so a low ratio next to a high acceptance count means "shows money rarely", not "pays rarely".
| Programme | Accepted | Shown | Largest | Total shown |
|---|---|---|---|---|
| T-Mobile | 134 | 32 (24%) | $133,700 | $878,900 |
| Atlassian | 406 | 118 (29%) | $12,000 | $171,425 |
| OpenSea Managed Bug Bounty Program | 71 | 37 (52%) | $50,000 | $150,600 |
| City of Vienna Managed Bug Bounty | 150 | 88 (59%) | $3,500 | $112,425 |
| Fireblocks MPC Managed Bug Bounty Engagement | 13 | 3 (23%) | $80,000 | $90,300 |
| Tesla | 95 | 40 (42%) | $10,000 | $82,961 |
| Indeed | 173 | 73 (42%) | $10,000 | $75,950 |
| Auth0 by Okta | 41 | 19 (46%) | $50,000 | $65,250 |
| Aiven Managed Bug Bounty | 52 | 13 (25%) | $15,000 | $52,315 |
| Keeper Security Public Bounty Program | 112 | 21 (19%) | $11,000 | $50,400 |
The largest single awards on file
Open any of these for the full record: the asset it landed against, who found it, what state it is in, and whether a figure this size is normal for that programme.
-
T-Mobile $133,700 critical
-
T-Mobile $133,700 critical
-
Fireblocks MPC Managed Bug Bounty Engagement $80,000 high
-
T-Mobile $55,000 critical
-
T-Mobile $55,000 critical
-
Auth0 by Okta $50,000 critical
-
OpenSea Managed Bug Bounty Program $50,000 critical
-
OpenSea Managed Bug Bounty Program $50,000 critical
Which assets are producing findings whole corpus
The specific assets that accepted findings have landed against, and how serious those findings were. This is the highest-resolution signal on the site, and one nobody else publishes: an asset that keeps producing criticals is a very different prospect from one producing only lows.
In this data the named asset comes from Bugcrowd alone. HackerOne's disclosed reports do not carry the asset, so a HackerOne programme is simply absent from this table rather than under-hunted. We do not cross-reference these against the scope list: our scope data is HackerOne's and the targets here are Bugcrowd's, so the two never meet on one row, and a fuzzy match across that gap would invent a signal we cannot stand behind.
| Asset | Accepted | Finders | Crit | Crit/high | Last seen |
|---|---|---|---|---|---|
| https://nasa.gov | 413 | 253 +51 withheld | 73 | 97 | yesterday |
| https://github.com/ClickHouse/ClickHouse | 247 | 77 +77 withheld | 1 | 19 | 2 days ago |
| Public Others Target | 111 | 24 +62 withheld | 6 | 21 | 2 days ago |
| *.wien.gv.at | 84 | 29 +13 withheld | 24 | 35 | 4 days ago |
| *.indeed.com | 72 | 26 +34 withheld | 2 | 4 | 8 days ago |
| Petpooja Production Web Applications & APIs | 57 | 20 +7 withheld | 3 | 20 | 3 days ago |
| *.comcast.com | 53 | 15 +31 withheld | 11 | 15 | 2 months ago |
| *.tesla.com | 52 | 20 +18 withheld | 5 | 11 | 2 days ago |
| https://bugcrowd-*your-own-instance*.cloud.mattermost.com/ | 51 | 19 +9 withheld | 0 | 2 | 2 days ago |
| *.ca.gov | 48 | 10 +35 withheld | 8 | 13 | 2 days ago |
| Confluence Data Center | 47 | 14 +31 withheld | 1 | 14 | 11 days ago |
| *.staging.gearset.com | 46 | 11 +33 withheld | 0 | 1 | 3 days ago |
Who accepts the serious findings whole corpus
Where the criticals and highs are actually landing. A programme that has never accepted anything above medium is telling you what it is worth your time for, and one that takes criticals is worth a harder look regardless of its volume.
| Programme | Critical | High | Accepted | Finders |
|---|---|---|---|---|
| National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program | 89 | 30 | 500 | 307 |
| T-Mobile | 41 | 45 | 134 | 36 |
| City of Vienna Managed Bug Bounty | 36 | 20 | 150 | 46 |
| Comcast Xfinity Vulnerability Disclosure Program | 25 | 9 | 71 | 8 |
| Comcast Xfinity Bug Bounty | 24 | 7 | 100 | 29 |
| Monash University Bug Bounty | 23 | 6 | 56 | 22 |
| Imperva - Thales Bug Bounty | 22 | 8 | 63 | 3 |
| Atlassian | 18 | 79 | 406 | 105 |
| State of Maryland Vulnerability Disclosure Program | 18 | 4 | 34 | 17 |
| curl | 17 | 45 | 354 | 228 |
| Keeper Security Public Bounty Program | 15 | 37 | 112 | 37 |
| Unity Technologies | 15 | 3 | 61 | 15 |
Severity is the platform's own label, and roughly one event in fourteen carries no severity at all: those are counted nowhere here rather than assumed harmless.
Open ground, or a private garden whole corpus
A programme where a dozen different people are landing findings is ground a newcomer can plausibly break into. One where a single finder holds most of the accepted work may be effectively farmed, or may just have one prolific specialist. The numbers are here; the judgement is yours.
| Programme | Finders | Accepted | Most by one finder |
|---|---|---|---|
| National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program | 307 | 500 | 3% |
| curl | 228 | 354 | 20% |
| Atlassian | 105 | 406 | 13% |
| ClickHouse | 96 | 314 | 9% |
| Indeed | 67 | 173 | 6% |
| City of Vienna Managed Bug Bounty | 46 | 150 | 19% |
| Opera Public Bug Bounty | 45 | 96 | 14% |
| Node.js | 42 | 48 | 6% |
| Tesla | 41 | 95 | 11% |
| Nextcloud | 41 | 64 | 11% |
| Mattermost Public Bug Bounty Engagement | 39 | 114 | 27% |
| Keeper Security Public Bounty Program | 37 | 112 | 16% |
The share is the busiest single named finder as a fraction of the named events only. A withheld name is unknown, not one more entry for the same person, so it never inflates or deflates the figure; where withholding is heavy the row notes it and the share is a floor.
What just opened
Programmes the directory sync caught launching, switching bounties on, or reopening submissions. A programme in its first weeks has the shallowest queue it will ever have.
-
DataCamp Reopened submissions
Nothing accepted on it in our sample yet. Pays up to $1,500.
-
Venly Reopened submissions
Nothing accepted on it in our sample yet. Pays up to $5,000.
-
TrueLayer Reopened submissions
Nothing accepted on it in our sample yet. Pays up to $6,000.
-
Visma Reopened submissions
Nothing accepted on it in our sample yet. Pays up to $7,500.
-
UZ Leuven Reopened submissions
Nothing accepted on it in our sample yet. Pays up to $5,000.
-
Omarchy Launched
Nothing accepted on it in our sample yet. Pays.
-
Mateco VDP Launched
Nothing accepted on it in our sample yet.
-
Bloompeak's Bug Bounty Launched
Nothing accepted on it in our sample yet. Pays up to $1,500.
-
AI | Apps+ Marketplace Bug Bounty Program Launched
Nothing accepted on it in our sample yet. Pays up to $1,500.
-
Meetical Launched
Nothing accepted on it in our sample yet. Pays up to $1,500.
-
NxtPort VDP Launched
Nothing accepted on it in our sample yet.
-
Vinted Bug Bounty Launched
1 accepted finding since. Pays up to $4,000.
Where nobody is looking
Two different kinds of quiet, kept apart because the evidence behind them is not the same strength. The first list is programmes whose output fell: they used to produce findings and have slowed. The second is live, bounty-paying programmes where we have seen nothing at all.
Quiet is an opportunity signal, not a promise, and it has at least three causes we cannot tell apart from here: the programme may be genuinely under-hunted; it may be hard, or narrow enough in scope that there is little to find; or it may be picked clean, in which case everyone before you already took the easy ground. A silent programme can also just mean the platform stopped publishing its activity, and a HackerOne row here is measuring how often that programme discloses, which is a policy decision more than a hunting one. Use this as a shortlist to go and look at, and read the scope before you read anything into the number.
Output fell away
-
Comcast Xfinity Bug Bounty Pays
100 events on record from 29 named finders over 135 days, about 10.4 in a normal 14 days for it. It had none. Last one 2 months ago.
-
curl
354 events on record from 228 named finders over 410 days, about 12.1 in a normal 14 days for it. It had 3. Last one 7 days ago.
-
Resolution Pays
37 events on record from 13 named finders over 78 days, about 6.6 in a normal 14 days for it. It had none. Last one 17 days ago.
-
Comcast Xfinity Vulnerability Disclosure Program
71 events on record from 8 named finders over 159 days, about 6.3 in a normal 14 days for it. It had none. Last one 1 month ago.
-
eToro Managed Bug Bounty Engagement Pays
72 events on record from 35 named finders over 173 days, about 5.8 in a normal 14 days for it. It had none. Last one 25 days ago.
-
Imperva - Thales Bug Bounty Pays
63 events on record from 3 named finders over 160 days, about 5.5 in a normal 14 days for it. It had none. Last one 1 month ago.
-
OpenSea Managed Bug Bounty Program Pays
71 events on record from 14 named finders over 186 days, about 5.3 in a normal 14 days for it. It had none. Last one 19 days ago.
-
AB InBev Vulnerability Disclosure Program
24 events on record from 8 named finders over 47 days, about 7.1 in a normal 14 days for it. It had 2. Last one 10 days ago.
-
Centers for Medicare & Medicaid Services - Public Bug Bounty Program 2026 Pays
42 events on record from 11 named finders over 119 days, about 4.9 in a normal 14 days for it. It had none. Last one 1 month ago.
-
New Balance VDP
17 events on record from 3 named finders over 42 days, about 5.7 in a normal 14 days for it. It had 2. Last one 9 days ago.
Live, paying, nothing seen
Open, bounty-paying, and nothing in our sample for 14 days. That can mean the platform does not publish this programme's activity at all. Check before you read it as an opening.
-
OpenSea Managed Bug Bounty Program
71 events on record, none recently. Pays up to $3,000,000.
-
Swiss Post - E-Voting
Nothing on record at all. Pays up to $230,000.
-
Fireblocks MPC Managed Bug Bounty Engagement
13 events on record, none recently. Pays up to $150,000.
-
Intel®
Nothing on record at all. Pays up to $100,000.
-
SpaceX/Starlink
5 events on record, none recently. Pays up to $100,000.
-
Okta
28 events on record, none recently. Pays up to $75,000.
-
Capture Our Flag
Nothing on record at all. Pays up to $51,337.
-
Doctolib
Nothing on record at all. Pays up to $50,000.
-
Kiteworks
Nothing on record at all. Pays up to $50,000.
-
Zendesk Managed Bug Bounty Engagement
Nothing on record at all. Pays up to $50,000.
What changed pace
The last 7 days against the 7 before them, for programmes with enough events for a change to mean anything.
Rising
-
Bitdefender
+15 · 0 to 15 (no prior activity on record)
-
National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
+10 · 11 to 21 (91%)
-
Department of Homeland Security: Vulnerability Disclosure Program
+6 · 0 to 6 (no prior activity on record)
-
US Environmental Protection Agency Vulnerability Disclosure
+6 · 4 to 10 (150%)
-
Intercom
+5 · 5 to 10 (100%)
-
lululemon
+5 · 0 to 5 (no prior activity on record)
Falling
-
ClickHouse
-8 · 14 to 6 (-57%)
-
City of Vienna Managed Bug Bounty
-6 · 19 to 13 (-32%)
-
Mercedes-Benz Vulnerability Disclosure Engagement
-6 · 6 to 0 (-100%)
-
Arlo Cash Rewards
-5 · 6 to 1 (-83%)
-
Home Depot Vulnerability Disclosure Engagement
-5 · 7 to 2 (-71%)
-
Sophos
-5 · 7 to 2 (-71%)
How this is built. Two scheduled jobs read the platforms' own public feeds (Bugcrowd's CrowdStream and HackerOne's disclosed reports) a few pages at a time, and store one row per published event. There are no report titles here and no vulnerability details: those feeds do not carry them and we do not go looking. Where a platform withheld the finder's name we store it as withheld and leave it that way. Counts are a floor on activity, never a measurement of it: a programme can be busy and publish nothing, and money is only ever printed where a platform printed it first. Last ingest today.