Blog What Happened to HackerOne? 7 August 2026 Author Joel Margolis Security Engineer at Phantom. Before that, AppSec at Match Group, Tinder, and Uber. Bug Bounty Hunter since 2017. Former Co-Host of the Critical Thinking Bug Bounty Podcast. Table of Contents Background The Golden Age of HackerOne and Live Hacking Events The Profit Problem The AI Era The Enshittification of HackerOne Your Reports Are Yours, We Promise Just Kidding They Never Were The Boiling Point We Must Calm the Masses Conclusion Table of Contents Background The Golden Age of HackerOne and Live Hacking Events The Profit Problem The AI Era The Enshittification of HackerOne Your Reports Are Yours, We Promise Just Kidding They Never Were The Boiling Point We Must Calm the Masses Conclusion So…what’s going on at HackerOne lately? It might be time for a wellness check.
But as a properly washed-up bug bounty hunter who lived through the golden era of HackerOne, I think it’s time to address the elephant in the room.
For some context, I started as a hacker on HackerOne in 2017. When I began working in tech, that hands-on experience was extremely useful for managing a bug bounty program, since I knew what researchers wanted, and how to interact with them.
As a result, I have managed multiple large bug bounty programs on HackerOne across various companies from 2018 to 2025 and I’ve been on both sides of the equation.
What I’m about to talk about comes from first-hand experience, both as a researcher and as a bug bounty program manager, and many, many years of direct conversations with HackerOne, both publicly and privately.
This article was aggregated automatically by CyberWire Daily's newsfeed engine. Original reporting: blog.teknogeek.io.
