Guide
Reading a bounty scope
what to read before you spend a token
Open the tracker: 1,178 programmes measured · ceilings, safe harbour, the clock, and each programme's AI rule

Key facts
- 1,178seven platforms, measured
- Programmes
- $4,000Bugcrowd, 273 of 278
- Median ceiling
- 71 of 278Bugcrowd, one in four
- Below full safe harbour
- 222HackerOne median, n 212
- Hours to a bounty
- 14 of 51live Cantina programmes
- Scope in prose only
- 19 Sep 2026mirror pulled 11 Sep
- Measured
A scope is three lists, and the one a beginner skips is the one that decides whether the month's work earns anything. Read the asset list as data, read the safe-harbour field as law, read the AI clause as a contract, and read the response medians as a cash-flow forecast, in that order, before a model reads a line of the target.
A scope is three lists
A programme’s scope is what is in, what is out, and what is already known, and the third list is the one a beginner reads last. Everything in it is worth zero. The Code4rena contest repository for Monetrix, opened on 10 September 2026, heads it “Publicly known issues” and states that anything included “is considered a publicly known issue and is therefore ineligible for awards” (CONFIRMED, file opened). The same repository carries a section headed “V12 findings”, naming Zellic’s in-house AI auditor, with the line “All issues found by V12 will be judged as out of scope and ineligible for awards” (CONFIRMED). A sponsor now runs an autonomous auditor over the code first and publishes what it found, so a hunter who runs their own agent over the scope and submits its first output is submitting into a pool that has already been cleared of exactly that.
Sherlock encodes the same information as trust assumptions. Its Tare contest README closes the scope in one sentence: “Any value or array-length input reachable by an untrusted party (Borrower, Investor, or an arbitrary caller) that is not adequately bounded is in scope” (CONFIRMED, opened). Everything reachable only by a trusted role is out.
An asset is a row of data, and some programmes keep theirs in prose
The five platforms mirrored by arkadiyt/bounty-targets-data publish scope as machine-readable asset lists, and on 11 September 2026 they held 957 public programmes with 46,707 in-scope entries: HackerOne 449 programmes and 41,328 assets, Bugcrowd 278 and 2,984, Intigriti 137 and 1,649, YesWeHack 58 and 647, Federacy 35 and 99 (CONFIRMED by parse). HackerOne’s assets split into seventeen types, led by URL at 34,954, WILDCARD at 2,713 and OTHER at 1,371; SOURCE_CODE appears in 63 programmes, which is the case where a model reading a repository does the work it is best at, because the code is in scope by the programme’s own definition. SMART_CONTRACT appears in five, which is why web3 work concentrates on Immunefi and Cantina instead: Immunefi alone carried 5,225 smart-contract assets across 170 live programmes on 19 September 2026 (CONFIRMED, endpoint read).
The asset list understates the real scope on some programmes, and the tracker says so on every count. The SpaceX/Starlink engagement on Bugcrowd carries one in-scope entry whose text reads “SpaceX and Starlink assets (target information and rewards detailed above on the brief)”, so a pipeline reading only the JSON points at nothing (CONFIRMED, record opened). Cantina shows the same shape at scale: 14 of its 51 live programmes had zero asset groups on 19 September 2026, with scope written only as prose inside the instructions field (CONFIRMED). Any published count built from structured fields counts machine-readable assets, never programme scope, and a hunter reading a scope should open the programme page beside the data.
Safe harbour is the field that makes the work lawful
Bug bounty work is legal because a published policy says it is, and the canonical wording is the disclose.io safe-harbour template, whose four tenets separate full safe harbour from partial: authorisation against anti-hacking law, exemption from anti-circumvention law, exemption from the organisation’s own terms of service, and an acknowledgement of good faith (CONFIRMED, file opened 10 September 2026). The protection covers claims under the control of the organisation publishing the policy, and it applies to research conducted according to the policy, which is what makes scope a legal boundary rather than a scoring rule.
Bugcrowd publishes the state as a field on every programme, and on 11 September 2026 it read full on 207, partial on 50 and null on 21, so 71 of 278, one in four, give less than full (CONFIRMED by parse). That is the field to read before pointing any automated tool at a target. Testing something adjacent to the scope removes the protection that made the work lawful in the first place, and a finding on an out-of-scope asset earns nothing.
For AI systems specifically, HackerOne announced a Good Faith AI Research Safe Harbor on 20 January 2026, a framework adopters attach alongside the 2022 Gold Standard Safe Harbor (CONFIRMED, press release dateline read 19 September 2026).
Read the AI clause every time
Fifteen programmes with a written rule on AI-assisted reports were read at the policy page for the Bounty Economics tracker, and four things recur across them. A named declaration of the tool and what it did; a reproducer the reporter has run; a report in the reporter’s own words; and a statement of what went untested. A submission carrying all four satisfies every published rule reached.
The clauses vary in where they bite. curl asks for the declaration in bold: “If you asked an AI tool to find problems in curl, you must make sure to reveal this fact in your report”, and bans made-up reports immediately (CONFIRMED, repository file). The Linux kernel changes the embargo: “If you resorted to AI assistance to identify a bug, you must treat it as public”, on the team’s experience that model-found bugs surface across several researchers on the same day (CONFIRMED). HackerOne permits and encourages AI use, keeps the member fully accountable for validating every output, and states that “Hackbots must not operate in a fully autonomous manner” (CONFIRMED, Code of Conduct read 19 September 2026). Bugcrowd reviews any account that submits ten consecutive invalid reports and suspends for 30 days where the submissions are attributable to unvalidated automated or AI output, on a queue that rose more than 334 per cent in three weeks (CONFIRMED, policy post of 10 March 2026). Immunefi prohibits AI-generated or automated scanner reports that lack the impact information the programme requires, with suspension or a permanent ban as the sanction (CONFIRMED, rules page). The strictest clauses sit at unpaid open-source projects and the loosest at the platforms paying most.
Check the clock before you spend compute
Inference bills the moment it runs, and the programme pays on its own schedule. HackerOne publishes responsiveness per programme, and the medians across the 449-programme dump on 11 September 2026 are the numbers any costed plan needs: 9 hours to a first response across 410 programmes reporting, 222 hours to a bounty awarded across 212, 1,174.5 hours to a report resolved across 300, and 85 per cent response efficiency across 443 (CONFIRMED by parse). A submission gets an answer in under half a day, money in nine days, and closure in seven weeks. Anyone running agents continuously finances roughly 49 days of working capital against a distribution whose median programme ceiling is $4,000.
The programme record carries the same fields per programme, so the check is one lookup. Anthropic’s own programme answers in 13 hours against the 9-hour median and runs at 97 per cent response efficiency against 85, and classes its API and SDKs as an AI_MODEL asset pointed at a staging hostname (CONFIRMED, record opened).
The ceiling is a ceiling
Across the 273 of 278 Bugcrowd programmes publishing a maximum payout, the median is $4,000, the 10th percentile $1,500, the 75th $6,500, the 90th $12,000 and the 95th $25,000, against a $3,000,000 top at OpenSea that carries the mean to $18,598 (CONFIRMED by recomputation). A ceiling is what a critical finding earns, and a medium earns a fraction of it. Web3 sits an order of magnitude higher: Immunefi’s 170 live programmes advertised a median ceiling of $100,000 and a top of $15,000,000 at LayerZero on 19 September 2026, and the advertised figure is rarely the payable amount, because 140 of 747 reward rows cap a critical at 10 per cent of the funds at risk (CONFIRMED, endpoint read). Intigriti’s figures are three currencies and are kept apart: €2,500 median across 50 programmes, $9,250 across 18, one at £12,500 (CONFIRMED by parse).
Set the ceiling against the cost of reading. One full pass over a 120,000-line project costs about $81 on Claude Opus 5 at RealVuln’s measured $0.0678 per 100 lines (CONFIRMED from the dashboard), and the 188 findings such a pass returns at the measured precision take about 15.7 hours to read at five minutes each, which is the larger bill. The $4,000 median buys 49 passes and about 4.4 complete triage passes at a $57.64 penetration-tester hourly rate (SINGLE, ZipRecruiter August 2026). Compute is spent against the median, and the median is $4,000.
Reproduce the figures yourself
The mirror refreshes every thirty minutes and carries an MIT licence, so the figures above are one pull and one parse away, and the Bounty Economics tracker carries the command beside its method. Pull bugcrowd_data.json from raw.githubusercontent.com/arkadiyt/bounty-targets-data/main/data/, take max_payout where it is non-zero, and the median lands on $4,000 with the maximum at $3,000,000. Immunefi and Cantina publish an unauthenticated bulk endpoint each; the counts move every week, which is why each measurement is kept as history rather than overwritten.
Questions people ask
- What does safe harbour mean on a bug bounty programme?
- A published promise that research conducted according to the policy is authorised under anti-hacking law, exempt from anti-circumvention law and the organisation's own terms of service, and treated as good faith. The disclose.io template that most policies derive from lists those four tenets; a policy carrying a good-faith commitment and missing one of them is classed partial. On Bugcrowd 207 of 278 public programmes state full safe harbour, 50 partial and 21 state none, measured 11 September 2026.
- How long does a bug bounty take to pay?
- On HackerOne the median programme awards a bounty 222 hours after submission, about nine days, across the 212 public programmes reporting that metric, and resolves the report at 1,174.5 hours, about 49 days, across 300, measured 11 September 2026 from the platform's own directory data. The first response arrives in 9 hours at the median.
- Do bug bounty programmes allow AI-assisted reports?
- Among the 15 programmes whose written rule this desk read at the policy page, none bans AI-assisted submissions outright, 4 require the AI use declared (curl, the Linux kernel, Django and Intigriti), 10 put the validation duty on the reporter, and 11 sanction unverified or fabricated output, from closure without response to a permanent ban, as of 19 September 2026. The strictest clauses sit at unpaid open-source projects and the loosest at the platforms paying most.
More in AI security
All AI Security →- Anthropic, OpenAI, Google, MetaModel safeguardsthe refusal contract, the fallback and the programmes
- KolegaRealVulna pinned corpus, a hashed prompt, a published cost
- Google DeepMind and Project ZeroGoogle Big Sleepthe vulnerability agent with the largest confirmed ledger
- Stanford CRFMCybench40 capture-the-flag tasks, and the number that goes beside each score