What Happened to HackerOne?
- ID
- 12609
- Status
- summarized
- Published
- 10 Aug 2026, 10:23 AM
- Fetched
- 12 Aug 2026, 11:11 AM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://blog.teknogeek.io/posts/what-happened-to-hackerone/
- Source URL
- https://hnrss.org/best
Summary
- Score
- 6.0
- Created
- 12 Aug 2026, 11:12 AM
- Tags
- Audience
- developerssaas_founders
What happened
Joel Margolis, a bug bounty hunter since 2017 and former bug bounty program manager at multiple large companies, writes a critical retrospective on HackerOne's trajectory from its founding in 2011 by Jobert Abma and Michiel Prins through what he describes as a 'golden age' of live hacking events to its current state, which he frames as needing a 'wellness check.' The piece draws on years of direct experience on both sides of bug bounty programs and private conversations with HackerOne.
Why it matters
If you run or are considering running a bug bounty program on HackerOne, this first-hand account from a long-time program manager signals platform-level issues worth investigating before committing budget or researcher relationships. Builders in Malaysia who rely on HackerOne for vulnerability disclosure should evaluate whether the platform's current trajectory affects program quality, researcher engagement, and payout reliability.
Discussion angle
Whether bug bounty platforms are still worth the cost for Malaysian startups versus alternatives like direct VDPs, and what signals from this article suggest about platform risk when relying on a single intermediary for security research.