• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

This $40 Million Investment Shows How ‘Bug Bounties’ Are Becoming Mainstream

By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
February 8, 2017, 8:00 AM ET

Until recently, the phrase “bug bounty” only popped up in tech and security circles. Now, it’s becoming an everyday term as companies like Starbucks and GM, and even the U.S. Army, are making bug bounty programs part of their operations.

The phrase refers to rewards (the bounties) paid to hackers who warn companies about flaws in their computer systems the (bugs). It’s long been a popular concept at places like Google, but most non-tech firms opposed it, partly out of fear that a cash-for-hacking program would lead to trouble.

The recent change in attitude is coming as more corporate executives realize many hackers are not malicious, and are instead a valuable early warning system for compromised computer code.

Marten Mickos, the CEO of a startup called HackerOne, knows this better than anyone. The firm works with a large network of hackers, who, amongst them, have discovered over 38,000 vulnerabilities and received more than $14 million in prize money from HackerOne clients, including the likes of Uber and Starbucks.

HackerOne’s client list is growing quickly. As part of a plan to meet demand, the company on Wednesday announced a $40 million Series C funding round, led by Dragoneer Investment Group, a firm that has also invested in startups like Airbnb and Atlassian (TEAM).

“Bug bounty are now an essential part of the software life cycle,” Mickos told Coins2Day in a phone interview. “You have to be software-powered to benefit—but is anyone not software-powered these days?”

Get Data Sheet, Coins2Day ’s technology newsletter.

He also explained that the bug bounty support that HackerOne provides varies from company to company. While tech-intensive firms like Uber want to interact directly with the hackers who find vulnerabilities, retail firms are more likely to ask HackerOne to act as an intermediary.

HackerOne also acts as a market-maker of sorts, helping to decide what a particular tip is worth: The average is around $500, but one recent payout came to as much as $30,000.

In the eyes of Mickos, any of these amounts far outweigh the alternative: of ignoring hackers’ help to then discover that someone else found the vulnerability and decided to exploit it for criminal ends.

The HackerOne announcement comes as other developments have increasingly raised the profile and popularity of bug bounties. These include Google’s recent revelation that it boosted its bug bounty outlays to $3 million last year, and Apple’s decision to finally adopt a bug bounty program of its own in 2016.

About the Author
By Jeff John RobertsEditor, Finance and Crypto
LinkedIn iconTwitter icon

Jeff John Roberts is the Finance and Crypto editor at Coins2Day, overseeing coverage of the blockchain and how technology is changing finance.

See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.