Early access: the directory is still filling out, and every rating here is a reported experience.
The brief · 3 October 2026

What the programmes
are actually doing

National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program led with 21 accepted findings, 12 programmes opened up, 10 went quiet.

Built from 6,728 public events across 317 programmes (5,807 bugcrowd, 921 hackerone). Bugcrowd publishes acceptances, HackerOne publishes disclosures months later, so this is a sample of what happens, never a census of it. The oldest event on file is 3523 days back. We have been collecting for 52 days, so older windows are sampled more thinly than recent ones. 2,173 events name no finder because the platform withheld it; we store that as withheld and never fill it in.

The window moves active now, what just opened, where nobody is looking and what changed pace. The money, targets, severity and researcher reads are marked whole corpus and do not move with it: a week holds too few of each to read.

01 · Active now

Where findings are landing

Programmes that accepted the most in the last 7 days, with the two things that separate a busy programme from a crowded one: how many different people are landing findings, and whether the platform showed money against any of them.

270Events
53critical
44high
102medium
64low
3none
4unrated
$159,407 57 awards shown
$700Median award
Programme Accepted Finders Crit/high Paid Last seen
National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program bugcrowd · nasa-vdp 21 15 +5 withheld 6 not set yesterday
Bitdefender bugcrowd · bitdefender 15 12 +2 withheld 7 $25,000 yesterday
City of Vienna Managed Bug Bounty bugcrowd · city-of-vienna-mbb-og 13 8 +2 withheld 6 $10,725 4 days ago
Petpooja Vulnerability Disclosure Program bugcrowd · petpooja-vdp-pro 10 5 2 not set 3 days ago
Atlassian bugcrowd · atlassian 10 5 +5 withheld 2 $825 2 days ago
US Environmental Protection Agency Vulnerability Disclosure bugcrowd · epa-vdp 10 4 +1 withheld not set not set 2 days ago
Intercom bugcrowd · intercom 10 1 +8 withheld 2 not set 4 days ago
United Airlines bugcrowd · united-vdp 9 2 +5 withheld 5 not set yesterday
Mastercard Public Bug Bounty bugcrowd · mastercard 8 4 +3 withheld 2 $630 2 days ago
State of California VDP bugcrowd · cdt-vdp-pro 8 2 +5 withheld 3 not set 2 days ago
Department of Homeland Security: Vulnerability Disclosure Program bugcrowd · dhs-vdp 6 3 2 not set 3 days ago
ClickHouse bugcrowd · clickhouse 6 1 +5 withheld not set not set 2 days ago
02 · Money

What the work has paid whole corpus

Every figure here is built only from amounts a platform actually printed, and only in US dollars, the one currency with enough rows to sum honestly. Because a single week carries only a handful of published awards, this is the picture across everything on file, not the selected window.

$2,926,334 1,493 awards shown
$500Median
$1,960Mean
$133,700Largest
$20Smallest

A shown amount is rare. Bugcrowd seldom publishes a figure at all, and HackerOne shows one only on the minority of reports both sides later disclosed. So these 1,493 awards are the ones that happened to be printed, out of 6,728 events, and every total here is a floor. A programme with no amount against it may pay very well and simply never say so.

How large the shown awards were

  • under $250 390 26%
  • $250–999 623 42%
  • $1k–5k 349 23%
  • $5k–10k 64 4%
  • $10k and up 67 4%

What a shown award was worth, by severity

Read as "when a finding at this severity was paid and the amount was published, here is the spread". It is not what a severity pays in general: the rows that carried no figure are not in it.

Severity Awards shown Low Typical High Total
Critical 192 $300 $7,886 $133,700 $1,514,180
High 268 $100 $3,462 $80,000 $927,700
Medium 581 $50 $640 $10,000 $371,845
Low 438 $20 $197 $1,000 $86,409
None 8 $25 $163 $500 $1,300
Unrated 6 $100 $4,150 $12,500 $24,900

How the platforms differ in what they show

Platform Accepted Amounts shown Disclosed Total shown
bugcrowd 5,807 1,426 (25%) 538 $2,802,670
hackerone 921 67 (7%) 921 $123,664

The gap between "accepted" and "amounts shown" is mostly publication policy, not generosity. HackerOne rows are here only because a report was disclosed at all, so its "disclosed" count matches its accepted count by construction; Bugcrowd discloses a subset and prints an amount on fewer still.

Programmes seen to pay in the open

Programmes with at least one published award, most paid-out first. "Shown" is how many of their acceptances carried a visible figure, so a low ratio next to a high acceptance count means "shows money rarely", not "pays rarely".

Programme Accepted Shown Largest Total shown
T-Mobile bugcrowd · t-mobile 134 32 (24%) $133,700 $878,900
Atlassian bugcrowd · atlassian 406 118 (29%) $12,000 $171,425
OpenSea Managed Bug Bounty Program bugcrowd · opensea 71 37 (52%) $50,000 $150,600
City of Vienna Managed Bug Bounty bugcrowd · city-of-vienna-mbb-og 150 88 (59%) $3,500 $112,425
Fireblocks MPC Managed Bug Bounty Engagement bugcrowd · fireblocks-mbb-og2 13 3 (23%) $80,000 $90,300
Tesla bugcrowd · tesla 95 40 (42%) $10,000 $82,961
Indeed bugcrowd · indeed 173 73 (42%) $10,000 $75,950
Auth0 by Okta bugcrowd · auth0-okta 41 19 (46%) $50,000 $65,250
Aiven Managed Bug Bounty bugcrowd · aiven-mbb-og 52 13 (25%) $15,000 $52,315
Keeper Security Public Bounty Program bugcrowd · keepersecurity 112 21 (19%) $11,000 $50,400

The largest single awards on file

Open any of these for the full record: the asset it landed against, who found it, what state it is in, and whether a figure this size is normal for that programme.

  • T-Mobile $133,700 critical

    bugcrowd · t-mobile · T&P Servers (Temporarily Out of Scope) · 18 days ago
  • T-Mobile $133,700 critical

    bugcrowd · t-mobile · T&P Servers (Temporarily Out of Scope) · 18 days ago
  • Fireblocks MPC Managed Bug Bounty Engagement $80,000 high

    bugcrowd · fireblocks-mbb-og2 · github.com/fireblocks/mpc-lib · found by ZeroXBits · 5 months ago
  • T-Mobile $55,000 critical

    bugcrowd · t-mobile · *.t-mobile.com · 3 months ago
  • T-Mobile $55,000 critical

    bugcrowd · t-mobile · *.t-mobile.com · found by tess · 4 months ago
  • Auth0 by Okta $50,000 critical

    bugcrowd · auth0-okta · *.cic-bug-bounty.auth0app.com · found by rexnets · 5 days ago
  • OpenSea Managed Bug Bounty Program $50,000 critical

    bugcrowd · opensea · opensea.io · found by nitesh_dhanjani · 2 months ago
  • OpenSea Managed Bug Bounty Program $50,000 critical

    bugcrowd · opensea · opensea.io · found by nitesh_dhanjani · 5 months ago
03 · Targets

Which assets are producing findings whole corpus

The specific assets that accepted findings have landed against, and how serious those findings were. This is the highest-resolution signal on the site, and one nobody else publishes: an asset that keeps producing criticals is a very different prospect from one producing only lows.

In this data the named asset comes from Bugcrowd alone. HackerOne's disclosed reports do not carry the asset, so a HackerOne programme is simply absent from this table rather than under-hunted. We do not cross-reference these against the scope list: our scope data is HackerOne's and the targets here are Bugcrowd's, so the two never meet on one row, and a fuzzy match across that gap would invent a signal we cannot stand behind.

Asset Accepted Finders Crit Crit/high Last seen
https://nasa.gov bugcrowd · National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program 413 253 +51 withheld 73 97 yesterday
https://github.com/ClickHouse/ClickHouse bugcrowd · ClickHouse 247 77 +77 withheld 1 19 2 days ago
Public Others Target bugcrowd · Mastercard Public Bug Bounty 111 24 +62 withheld 6 21 2 days ago
*.wien.gv.at bugcrowd · City of Vienna Managed Bug Bounty 84 29 +13 withheld 24 35 4 days ago
*.indeed.com bugcrowd · Indeed 72 26 +34 withheld 2 4 8 days ago
Petpooja Production Web Applications & APIs bugcrowd · Petpooja Vulnerability Disclosure Program 57 20 +7 withheld 3 20 3 days ago
*.comcast.com bugcrowd · Comcast Xfinity Bug Bounty 53 15 +31 withheld 11 15 2 months ago
*.tesla.com bugcrowd · Tesla 52 20 +18 withheld 5 11 2 days ago
https://bugcrowd-*your-own-instance*.cloud.mattermost.com/ bugcrowd · Mattermost Public Bug Bounty Engagement 51 19 +9 withheld 0 2 2 days ago
*.ca.gov bugcrowd · State of California VDP 48 10 +35 withheld 8 13 2 days ago
Confluence Data Center bugcrowd · Atlassian 47 14 +31 withheld 1 14 11 days ago
*.staging.gearset.com bugcrowd · Gearset: Managed Bug Bounty 46 11 +33 withheld 0 1 3 days ago
04 · Severity

Who accepts the serious findings whole corpus

Where the criticals and highs are actually landing. A programme that has never accepted anything above medium is telling you what it is worth your time for, and one that takes criticals is worth a harder look regardless of its volume.

Programme Critical High Accepted Finders
National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program bugcrowd · nasa-vdp 89 30 500 307
T-Mobile bugcrowd · t-mobile 41 45 134 36
City of Vienna Managed Bug Bounty bugcrowd · city-of-vienna-mbb-og 36 20 150 46
Comcast Xfinity Vulnerability Disclosure Program bugcrowd · comcastvdp 25 9 71 8
Comcast Xfinity Bug Bounty bugcrowd · comcast-mbb 24 7 100 29
Monash University Bug Bounty bugcrowd · monash-mbb 23 6 56 22
Imperva - Thales Bug Bounty bugcrowd · imperva-mbb 22 8 63 3
Atlassian bugcrowd · atlassian 18 79 406 105
State of Maryland Vulnerability Disclosure Program bugcrowd · maryland-vdp-pro 18 4 34 17
curl hackerone · curl 17 45 354 228
Keeper Security Public Bounty Program bugcrowd · keepersecurity 15 37 112 37
Unity Technologies bugcrowd · unity 15 3 61 15

Severity is the platform's own label, and roughly one event in fourteen carries no severity at all: those are counted nowhere here rather than assumed harmless.

05 · Researchers

Open ground, or a private garden whole corpus

A programme where a dozen different people are landing findings is ground a newcomer can plausibly break into. One where a single finder holds most of the accepted work may be effectively farmed, or may just have one prolific specialist. The numbers are here; the judgement is yours.

Programme Finders Accepted Most by one finder
National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program bugcrowd · nasa-vdp · 64 withheld 307 500
curl hackerone · curl 228 354
Atlassian bugcrowd · atlassian · 178 withheld 105 406
ClickHouse bugcrowd · clickhouse · 116 withheld 96 314
Indeed bugcrowd · indeed · 76 withheld 67 173
City of Vienna Managed Bug Bounty bugcrowd · city-of-vienna-mbb-og · 41 withheld 46 150
Opera Public Bug Bounty bugcrowd · opera · 26 withheld 45 96
Node.js hackerone · nodejs 42 48
Tesla bugcrowd · tesla · 34 withheld 41 95
Nextcloud hackerone · nextcloud 41 64
Mattermost Public Bug Bounty Engagement bugcrowd · mattermost-mbb-public · 23 withheld 39 114
Keeper Security Public Bounty Program bugcrowd · keepersecurity · 50 withheld 37 112

The share is the busiest single named finder as a fraction of the named events only. A withheld name is unknown, not one more entry for the same person, so it never inflates or deflates the figure; where withholding is heavy the row notes it and the share is a floor.

06 · New

What just opened

Programmes the directory sync caught launching, switching bounties on, or reopening submissions. A programme in its first weeks has the shallowest queue it will ever have.

  • DataCamp Reopened submissions

    Nothing accepted on it in our sample yet. Pays up to $1,500.

    intigriti · datacamp · yesterday
  • Venly Reopened submissions

    Nothing accepted on it in our sample yet. Pays up to $5,000.

    intigriti · arkanenetwork · yesterday
  • TrueLayer Reopened submissions

    Nothing accepted on it in our sample yet. Pays up to $6,000.

    intigriti · truelayer · yesterday
  • Visma Reopened submissions

    Nothing accepted on it in our sample yet. Pays up to $7,500.

    intigriti · visma · yesterday
  • UZ Leuven Reopened submissions

    Nothing accepted on it in our sample yet. Pays up to $5,000.

    intigriti · uzleuven · yesterday
  • Omarchy Launched

    Nothing accepted on it in our sample yet. Pays.

    hackerone · omarchy · 2 days ago
  • Mateco VDP Launched

    Nothing accepted on it in our sample yet.

    intigriti · matecovdp · 2 days ago
  • Bloompeak's Bug Bounty Launched

    Nothing accepted on it in our sample yet. Pays up to $1,500.

    bugcrowd · bloompeak · 2 days ago
  • AI | Apps+ Marketplace Bug Bounty Program Launched

    Nothing accepted on it in our sample yet. Pays up to $1,500.

    bugcrowd · apps-plus2 · 2 days ago
  • Meetical Launched

    Nothing accepted on it in our sample yet. Pays up to $1,500.

    bugcrowd · meetical · 2 days ago
  • NxtPort VDP Launched

    Nothing accepted on it in our sample yet.

    intigriti · nxtportvdp · 2 days ago
  • Vinted Bug Bounty Launched

    1 accepted finding since. Pays up to $4,000.

    bugcrowd · vinted-uab-mbb · 3 days ago
07 · Quiet

Where nobody is looking

Two different kinds of quiet, kept apart because the evidence behind them is not the same strength. The first list is programmes whose output fell: they used to produce findings and have slowed. The second is live, bounty-paying programmes where we have seen nothing at all.

Quiet is an opportunity signal, not a promise, and it has at least three causes we cannot tell apart from here: the programme may be genuinely under-hunted; it may be hard, or narrow enough in scope that there is little to find; or it may be picked clean, in which case everyone before you already took the easy ground. A silent programme can also just mean the platform stopped publishing its activity, and a HackerOne row here is measuring how often that programme discloses, which is a policy decision more than a hunting one. Use this as a shortlist to go and look at, and read the scope before you read anything into the number.

Output fell away

  • Comcast Xfinity Bug Bounty Pays

    100 events on record from 29 named finders over 135 days, about 10.4 in a normal 14 days for it. It had none. Last one 2 months ago.

    bugcrowd · comcast-mbb · submissions open
  • curl

    354 events on record from 228 named finders over 410 days, about 12.1 in a normal 14 days for it. It had 3. Last one 7 days ago.

    hackerone · curl · submissions open
  • Resolution Pays

    37 events on record from 13 named finders over 78 days, about 6.6 in a normal 14 days for it. It had none. Last one 17 days ago.

    bugcrowd · resolutionde · submissions open
  • Comcast Xfinity Vulnerability Disclosure Program

    71 events on record from 8 named finders over 159 days, about 6.3 in a normal 14 days for it. It had none. Last one 1 month ago.

    bugcrowd · comcastvdp · submissions open
  • eToro Managed Bug Bounty Engagement Pays

    72 events on record from 35 named finders over 173 days, about 5.8 in a normal 14 days for it. It had none. Last one 25 days ago.

    bugcrowd · etoro-mbb-og · submissions open
  • Imperva - Thales Bug Bounty Pays

    63 events on record from 3 named finders over 160 days, about 5.5 in a normal 14 days for it. It had none. Last one 1 month ago.

    bugcrowd · imperva-mbb · submissions open
  • OpenSea Managed Bug Bounty Program Pays

    71 events on record from 14 named finders over 186 days, about 5.3 in a normal 14 days for it. It had none. Last one 19 days ago.

    bugcrowd · opensea · submissions open
  • AB InBev Vulnerability Disclosure Program

    24 events on record from 8 named finders over 47 days, about 7.1 in a normal 14 days for it. It had 2. Last one 10 days ago.

    bugcrowd · abinbev-vdp
  • Centers for Medicare & Medicaid Services - Public Bug Bounty Program 2026 Pays

    42 events on record from 11 named finders over 119 days, about 4.9 in a normal 14 days for it. It had none. Last one 1 month ago.

    bugcrowd · cms-bbpublic · submissions open
  • New Balance VDP

    17 events on record from 3 named finders over 42 days, about 5.7 in a normal 14 days for it. It had 2. Last one 9 days ago.

    bugcrowd · newbalance-vdppro

Live, paying, nothing seen

Open, bounty-paying, and nothing in our sample for 14 days. That can mean the platform does not publish this programme's activity at all. Check before you read it as an opening.

  • OpenSea Managed Bug Bounty Program

    71 events on record, none recently. Pays up to $3,000,000.

    bugcrowd · opensea · submissions open
  • Swiss Post - E-Voting

    Nothing on record at all. Pays up to $230,000.

    yeswehack · swiss-post-evoting · submissions open
  • Fireblocks MPC Managed Bug Bounty Engagement

    13 events on record, none recently. Pays up to $150,000.

    bugcrowd · fireblocks-mbb-og2 · submissions open
  • Intel®

    Nothing on record at all. Pays up to $100,000.

    intigriti · 10eb5e95-08e2-4f4e-8d22-f8c600a7acff · submissions paused
  • SpaceX/Starlink

    5 events on record, none recently. Pays up to $100,000.

    bugcrowd · spacex · submissions open
  • Okta

    28 events on record, none recently. Pays up to $75,000.

    bugcrowd · okta · submissions open
  • Capture Our Flag

    Nothing on record at all. Pays up to $51,337.

    intigriti · 04aab402-3eb7-41b8-b146-b9344efc89ce · submissions open
  • Doctolib

    Nothing on record at all. Pays up to $50,000.

    yeswehack · doctolib-public-bug-bounty-program · submissions open
  • Kiteworks

    Nothing on record at all. Pays up to $50,000.

    yeswehack · kiteworks-public-bug-bounty-program-1 · submissions open
  • Zendesk Managed Bug Bounty Engagement

    Nothing on record at all. Pays up to $50,000.

    bugcrowd · zendesk · submissions open
08 · Movers

What changed pace

The last 7 days against the 7 before them, for programmes with enough events for a change to mean anything.

Rising

  • Bitdefender

    +15 · 0 to 15 (no prior activity on record)

    bugcrowd · bitdefender
  • National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program

    +10 · 11 to 21 (91%)

    bugcrowd · nasa-vdp
  • Department of Homeland Security: Vulnerability Disclosure Program

    +6 · 0 to 6 (no prior activity on record)

    bugcrowd · dhs-vdp
  • US Environmental Protection Agency Vulnerability Disclosure

    +6 · 4 to 10 (150%)

    bugcrowd · epa-vdp
  • Intercom

    +5 · 5 to 10 (100%)

    bugcrowd · intercom
  • lululemon

    +5 · 0 to 5 (no prior activity on record)

    bugcrowd · lululemon

Falling

  • ClickHouse

    -8 · 14 to 6 (-57%)

    bugcrowd · clickhouse
  • City of Vienna Managed Bug Bounty

    -6 · 19 to 13 (-32%)

    bugcrowd · city-of-vienna-mbb-og
  • Mercedes-Benz Vulnerability Disclosure Engagement

    -6 · 6 to 0 (-100%)

    bugcrowd · mercedes-benz-vdp-ess
  • Arlo Cash Rewards

    -5 · 6 to 1 (-83%)

    bugcrowd · arlo
  • Home Depot Vulnerability Disclosure Engagement

    -5 · 7 to 2 (-71%)

    bugcrowd · home-depot-vdp-pro
  • Sophos

    -5 · 7 to 2 (-71%)

    bugcrowd · sophos

How this is built. Two scheduled jobs read the platforms' own public feeds (Bugcrowd's CrowdStream and HackerOne's disclosed reports) a few pages at a time, and store one row per published event. There are no report titles here and no vulnerability details: those feeds do not carry them and we do not go looking. Where a platform withheld the finder's name we store it as withheld and leave it that way. Counts are a floor on activity, never a measurement of it: a programme can be busy and publish nothing, and money is only ever printed where a platform printed it first. Last ingest today.