How bounties are calculated
Each bug bounty program defines its own payout table. The two main factors that determine your bounty are:- Severity — how critical the vulnerability is, rated across levels such as Informational, Low, Medium, High, and Critical.
- Target tier — the relative importance of the affected asset within the program (for example, a core production API typically falls in a higher tier than a staging environment or a marketing subdomain).
Programs display their bounty table in the program brief. Always review it before you start testing so you know what payouts to expect for each combination of severity and target tier.
Bonus payments
In addition to the standard bounty, a program may award a bonus on top of your base payout. Bonuses are discretionary and are typically granted when a finding is especially impactful, demonstrates exceptional research quality, or comes with a particularly thorough write-up and proof of concept. A bonus is issued as a separate bounty record and appears as its own reward entry in your account activity log alongside the original bounty.When bounties are paid
Bounties are awarded by the company after your report reaches Accepted or Resolved status. The timeline looks like this:1
Submit your report
Write up your finding and submit it through the program’s report form. The report enters a pending or triaging state.
2
Triage and review
The security team reviews your report, may ask clarifying questions, and confirms reproducibility. Severity may be adjusted at this stage.
3
Report accepted or resolved
Once the company accepts the validity of your finding or marks it resolved, the report moves to a qualifying status. This is the trigger for a bounty award.
4
Bounty awarded
The company sets the bounty amount. You receive a notification and the reward appears in your account activity log.
5
Payment processed
Your payment is processed to the method you have configured in your account. Make sure your payment information is up to date before this step.
Currency
Programs on Hackrate denominate their bounties in either USD ($) or EUR (€). The currency used is set by the company and is shown in the program brief. You will be paid in the program’s designated currency, so factor this into your expectations when participating in programs across different regions.Non-monetary awards
Not every recognition on Hackrate takes the form of a cash payout. Companies can issue Awards — named acknowledgements tied to a specific program and linked to your profile. Awards are visible on your public hacker profile and contribute to your standing on the platform.Thanks Awards
A thanks award is a lightweight acknowledgement from a company — often given for a report that was informational or out of scope but still considered valuable feedback.
Named Program Awards
Program-specific awards carry the name chosen by the company and can represent milestones such as “First Blood,” “Most Creative Finding,” or program-specific recognition tiers.
Your shareable bounty page
Each bounty you earn has a unique, publicly shareable page. You can access it from your account activity log by clicking the bounty entry. This page displays:- Your nickname and profile picture
- The bounty amount and currency
- The name of the program (or “a private program” if the program is private)
- The date the bounty was awarded