> $5K seems like an absolute steal compared to paying contracted security experts to find such bugs.
Big companies who run these programs don’t use them as their only security. It’s a bonus program. They have internal employees and often third parties doing testing too.
> I'm surprised these programs aren't pushed harder, as the potential ROI seems fantastic.
I have some exposure to managing one of these programs, which was started by someone who left the company abruptly (right after it went on their resume as an achievement).
It’s a huge amount of work. We got an unbelievable number of bad reports before AI was available. Now it’s just a nightmare. The ratio of bad reports to actual payout-worthy reports was out of control.
Most submitters also tried to inflate the severity of their submission to get to the higher tiers. This created a problem where people were withholding small bugs while they’d try to find a way to chain it or elevate privileges. You could tell because as soon as you detected and closed their exploit, they would hurriedly submit a rushed report to try to claim it and then argue with you for not paying out because it was fixed before they submitted it.
We had payouts that went to larger numbers, but honestly I think it would have been better off if we didn’t. This makes bystanders irate, but honestly the incentives get bad when the payouts are large and everyone is spamming LLM bots at your service.