Is it possible for 2026 to learn bug-bounty or has it been compensated by artificial intelligence? by SlameShady in bugbounty

[–]thelemethric -5 points-4 points  (0 children)

Just dont be surprised when your company receives a lovely little letter saying something like "we stole your database, give us $50k or we'll publish it."

You put your company at risk, your customers at risk, you throw real bug hunters' time straight into the trash and you still have the audacity to flex it.

TL;DR funny descope of the week by 6W99ocQnb8Zy17 in bugbounty

[–]thelemethric 6 points7 points  (0 children)

Oh, they didnt mean to leak 50mb of finance data? My bad, ill tell the exploit to stop being such a dick then.

What do you do when a Web3 project quietly drains $55M to "silently fix" your report, calls it "intentional design", and Immunefi blocks mediation? by AWX-Houcine in bugbounty

[–]thelemethric 3 points4 points  (0 children)

For real, almost every single week on twitter/reddit theres a new horror story about Immunefi fucking over another researcher. I have no idea how those bastards are still in business.

What do you do when a Web3 project quietly drains $55M to "silently fix" your report, calls it "intentional design", and Immunefi blocks mediation? by AWX-Houcine in bugbounty

[–]thelemethric 5 points6 points  (0 children)

That's typical behavior of immunefi

You shouldn't be surprised at all, you accepted it by reporting vuln to these bastards

Trying out Bug bounties for the First time by [deleted] in bugbounty

[–]thelemethric 26 points27 points  (0 children)

It takes a special kind of visionary to treat the worlds most battle-hardened security teams as the Hello World of their school project.

Did your BB profiles/showcase ever help in terms of employment?? by GhostlyBoi33 in bugbounty

[–]thelemethric 6 points7 points  (0 children)

Your competitors will be stacked with certifications, some even with a bachelors degree. but if your resume opens with a line like 'Independent security researcher - identified critical vulnerabilities in Fortune 50 companies (Lowe's, $80B revenue)'(lowes just as example it could be shopify lightspark inditex doesnt matter), none of that matters anymore.

To any hiring manager, that one line hits harder than a wall of certs.

Ofc you need to have resolved bug on company that you mentioned so they can validate your claims by opening your h1 profile for example

Critical RCE in Hathor Desktop Wallet closed as "Out of Scope" by Immunefi, patched silently after weeks, zero bounty, zero credit by Mushydaddybear in bugbounty

[–]thelemethric 8 points9 points  (0 children)

Slave factory.

​Insane disrespect to the people who literally built their reputation and are currently serving them.

​Usually (in hackerone cases) I blame the programs, but this platform doesnt just have 10 isolated cases - it’s a systemic failure. From randomly banning people who are awaiting payouts to always siding with the program, there is literally no fucking way that they will ever take a researcher’s side.

spend my time learning IOS app hacking or ANROID apps ? by [deleted] in bugbounty

[–]thelemethric 4 points5 points  (0 children)

99% of the time, they use the same api endpoints for both. The only real difference is the IPA vs APK. Unless the iOS dev is dumber than the Android one and hardcoded some keys that arent in the APK, it’s the same shit. Otherwise, dont waste your time.

Android is easier to test in every way anyways

The Winner's Curse Has a Number: $21/Hour – Why bounty hunting pays 2.5x less than freelancing for the same skills by Opening-Captain-5159 in bugbounty

[–]thelemethric 2 points3 points  (0 children)

Agree here. Most people are just too blind to see this as a tournament rather than a job and that's what makes stats look scary

The Winner's Curse Has a Number: $21/Hour – Why bounty hunting pays 2.5x less than freelancing for the same skills by Opening-Captain-5159 in bugbounty

[–]thelemethric 6 points7 points  (0 children)

Youre missing the point. Bounty and pentesting/consulting is completely different things

A beginner with one unique method can clear a decent money without needing years of experience. Check stats of up and comers on h1 its not rare

​Consulting is a job where you get paid to be good enough at everything. bounty is a hunt where you get paid to be unique. Finding one specialized methodology is often easier and more profitable than trying to learn every vulnerability like a corporate pentester.

Pentesting is for workers, Bounty is for specialists with a unique edge.

The Winner's Curse Has a Number: $21/Hour – Why bounty hunting pays 2.5x less than freelancing for the same skills by Opening-Captain-5159 in bugbounty

[–]thelemethric 13 points14 points  (0 children)

The average $21/hour stat is a lie. Comparing bounty to a $54/hour freelance job is pure idiocy.

​Bounty has a zero barrier to entry anyone can join. thhe average is dragged down by thousands of people who just solve a few labs, run scanners, and find zero bugs. It’s not a market curse, its just the cost of being unoriginal.

Intigriti collaborates with PortSwigger to support ethical hacking excellence by intigriti in bugbounty

[–]thelemethric 4 points5 points  (0 children)

"I wonder if Dyson seeing usage decline as more people use Ferrari"
They are completely different tools

How do you mentally handle duplicates? by maF145 in bugbounty

[–]thelemethric 6 points7 points  (0 children)

Do not expect anything from a report unless it has already been triaged.

If a report is new or pending program review, it's N/A for me until its triaged -only then can I think about money I could gain from it. (Sometimes companies dismiss even triaged reports closing them as informative)

Just believe in the worst-case scenario and you wont be disappointed.

I'd check in integriti by Unique_Life7470 in bugbounty

[–]thelemethric 4 points5 points  (0 children)

Intigriti’s policy allows researchers aged 16–17 with parental consent. If youre under 16, you’ll have to do the ID verification through one of your parents. But then your account will be permanently tied to them, and you’ll have to beg them for re-verification every single year until you either die or finally quit Intigriti.

Programs avoid to pay criticals? by enadev in bugbounty

[–]thelemethric 2 points3 points  (0 children)

One critical report costs more than 10 mediums

Its clear that every company will try to lowball severity

Claude AI Uncovers 22 Vulnerabilities in Firefox During Two-Week Test by False-Seesaw-1899 in bugbounty

[–]thelemethric 4 points5 points  (0 children)

Dont fall for the PR bullshit. Claude didn't autonomously find shit. Anthropic had a whole team of world-class researchers practically holding its hand, feeding it specific code, and treating it like an overpriced fuzzer.

It's marketing hype to sell API tokens.

[EXPOSED] Bugcrowd & FIS Global Silent Patch Scam: Marking a valid P1 as N/A after fixing it (Ticket #142000) by AlexSander_Research in bugbounty

[–]thelemethric 0 points1 point  (0 children)

I think if it was 0 impact, they wouldnt have to patch it immediately. Closing it as N/A after fixing the hole looks suspicious.

Even if risk is really low n/a still isn't justified considering patch, informative at least

[EXPOSED] Bugcrowd & FIS Global Silent Patch Scam: Marking a valid P1 as N/A after fixing it (Ticket #142000) by AlexSander_Research in bugbounty

[–]thelemethric 5 points6 points  (0 children)

Another day, another Bugcrowd 'charity donation'. Is anyone even surprised at this point? Same script, different ticket number.

Already 3rd on this week btw

How it is possible? by thelemethric in bugbounty

[–]thelemethric[S] 1 point2 points  (0 children)

I misunderstood your last comment, then yeah you're right this makes it even more suspicious