Not by HackerOne per se but the companies using the platform.
A better title would be “$100M in bounties paid to ethical hackers by companies via HackerOne”.
To be fair, the original message on Twitter reads much better than the title of the article:
> HackerOne is proud to announce that hackers have earned $100 Million in bug bounties by hacking for good on our platform.
I was on both sides of this: leading the security team at a company paying bug bounties via HackerOne and also reporting security problems to other companies as a freelancer. To be honest, the experience was always bad in both cases. I wasted several hours triaging bugs reported by “hackers” that often disregarded the conditions of our bug bounty program. People reporting the most trivial things and we would have to pay them anyway just to move on, otherwise they would end up ranting for days.
On the other side, as a bug bounty hunter, the experience is also awful. One of the biggest problems is the fact that you have no way to know if other person has reported the same issue, so you spend hours if not days documenting a vulnerability and creating proof of concepts (PoC) and it is only after your submission that you get a message saying “closed: duplicate issue”. Add to that all the back-and-forth trying to justify more complex issues that are slightly more difficult to prove without damaging the system you are testing.
I am glad so many companies and people are still onboard with this service, but I wouldn’t blame anyone for closing their account after all the bad experiences I had.