Skip to main content
Before any bounty can be paid to you, you need to save valid payment information in your account. Hackrate supports two payment methods — bank transfer and PayPal — and the setup takes only a few minutes. Keeping your payment details accurate and current ensures that when a company awards you a bounty, the transfer can proceed without delay. To access your payment settings, go to Account Settings and select the Payment tab. This page shows you two things: your saved payment details (if any have been entered) and a history of payment transactions associated with your account.
You must be signed in as a researcher to access the Payment settings page. Program administrators use a separate payments workflow.

Choosing a payment method

Hackrate supports two active payment methods. Select the one that best fits your situation:
Bank transfer sends your bounty directly to a bank account. To use this method, you will need to provide:
  • Account holder name — the full legal name on the bank account
  • Bank account number — your IBAN or account number depending on your country
  • Bank name — the name of your financial institution
  • Bank country — the country where your bank account is held
  • Country of residence — your current country of residence
Bank transfers are well suited to larger bounties and to researchers in countries with well-connected banking infrastructure.
Double-check all payment details before saving. Errors in account numbers or email addresses can result in failed or misdirected transfers that are difficult to reverse. You are responsible for the accuracy of the information you provide.

Individual vs. company payments

When entering your payment details, you can indicate whether you are receiving payment as an individual or as a company. This affects how your payout is processed and how invoicing is handled in some jurisdictions. If you operate as a freelance security consultant through a registered business entity, select the company option and ensure the account holder name matches your registered business name.

Identity verification requirement

Your identity must be verified before your first bounty payout can be processed. This is a platform-wide requirement designed to comply with financial regulations and to protect both researchers and companies.
1

Complete identity verification

Go to Account Settings → Verification and complete the identity verification flow. You will need a government-issued photo ID, a proof of address document, and a camera for a live photo. See Verification for full instructions.
2

Save your payment details

Return to Account Settings → Payment and enter your chosen payment method. You can save payment details before verification is complete, but the payout will not be initiated until your identity is confirmed.
3

Receive your bounty

Once a company awards a bounty and your identity is verified, the transfer is initiated. You will see the transaction appear in your payment history on this page.

Currency considerations

Bounties are denominated in the currency chosen by the program — either USD ($) or EUR (€). The program currency is displayed in the program brief before you start testing.
  • If you are paid via bank transfer, your bank may apply a currency conversion fee if your account is held in a different currency. Check with your bank for their international transfer rates.
  • If you are paid via PayPal, PayPal’s currency conversion rates and fees apply when the funds arrive in a currency different from your PayPal balance’s default.
Consider holding a EUR or USD account if you participate frequently in programs denominated in those currencies — conversion fees can add up across multiple bounties.

Keeping your payment information up to date

Your payment details are not updated automatically if you change banks or switch PayPal accounts. You are responsible for keeping this information current. Outdated details can result in failed transactions.
Update your payment information any time you:
  • Change your bank account or close an existing account
  • Update the email address on your PayPal account
  • Move to a different country of residence
  • Switch between individual and company payment status
If a payment transfer fails due to incorrect details, the funds are typically returned to the program. Contact Hackrate support as soon as possible with your corrected payment information so the transfer can be re-initiated. Providing accurate details at the outset avoids this delay.

Security tips for your payment data

Your payment information is sensitive. Treat it with the same care you would any financial credential:
  • Never share your account settings credentials with anyone, including other researchers. Hackrate staff will never ask for your password.
  • Enable two-factor authentication on your Hackrate account to protect against unauthorized access to your payment details. See Verification for 2FA setup instructions.
  • Use a dedicated email address for PayPal that is not easily guessable or linked to your public hacker identity.
  • Review your transaction history regularly on the Payment page. If you see a transaction you do not recognize, contact support immediately.
  • Notify support promptly if you suspect your account has been compromised, especially before any pending bounties are paid out.