Tools Bounty Economics bugcrowd
Platform record
Bugcrowd: what its public programmes pay, measured
- Programmes
- 278
- Publishing a ceiling
- 273
- In-scope assets
- 2,984
- Median ceiling
- $4,000
- Top ceiling
- $3,000,000 (OpenSea Managed Bug Bounty Program)
- Safe harbour
- 207 full · 50 partial · 21 none stated
- Measured
- 2026-09-11
- Confidence
- CONFIRMED
What happened
Bugcrowd lists 278 public programmes in the mirror, 273 of them publishing a maximum payout. The median ceiling is $4,000, the mean $18,598 and the top of the table $3,000,000 at OpenSea. 207 programmes give full safe harbour, 50 partial and 21 state none, so 71 of 278 give less than full. Measured 11 September 2026 from the platform's own data as mirrored.
Every Bugcrowd record in the mirror carries managed_by_bugcrowd: true and a safe_harbor field. The ceiling ladder runs p10 $1,500, p50 $4,000, p75 $6,500, p90 $12,000, p95 $25,000, and one crypto custody programme carries the mean to $18,598. The SpaceX/Starlink record shows the limit of the machine-readable scope: its single in-scope entry reads 'SpaceX and Starlink assets (target information and rewards detailed above on the brief)', so the real scope sits in prose on the engagement page.
Sources
- Bugcrowd data, bounty-targets-data mirror (MIT)raw.githubusercontent.com/arkadiyt/bounty-targets-data/main/…
- Mirror licence, MITraw.githubusercontent.com/arkadiyt/bounty-targets-data/main/…
On YFarmX
- Reference pageyfarmx.com/ai/security/reading-a-bounty-scope/
One record from the Bounty Economics, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026