How VC Pressure Turned HackerOne from a Hacker Haven into a Sales Machine
A veteran bug bounty hunter who worked both sides of HackerOne — as a researcher since 2017 and as a program manager through 2025 — argues the platform has lost the plot. HackerOne began in 2011 as a way to give ethical hackers legal cover and fair pay at a time when reporting a vulnerability could land you in court. For its first five-plus years it was run by people close to the hacker community, and from 2017 to 2020 its Live Hacking Events became the platform’s signature draw: top researchers flown to a target for a few days would surface more critical bugs than a program saw all year, while forming the personal networks that seeded much of today’s infosec community. Custom posters, challenge coins, regional clubs, and hacker ambassadors reinforced that community-first identity.
The author traces the decline to a single business reality that surfaced around 2020–2021: HackerOne had run largely on venture money, raising roughly $160M between 2014 and 2022, and its investors wanted returns. VCs holding board seats and leverage pushed the obvious growth lever — more customers. The founding CEO was swapped for a corporate one, the pricing model moved from a percentage cut of bounties to capacity-based fees and multi-year contracts, and the culture reoriented around a fast-growing sales team incentivized to lock customers into discounted long-term deals. Meanwhile the core product stagnated: a tired UI, weak performance, and little technical innovation.
The piece is less a data-driven exposé than a firsthand lament, but it captures a familiar pattern in venture-backed platforms — a mission-aligned community product getting reengineered for predictable recurring revenue. For the researchers who supplied HackerOne’s value, the visible symptoms are community programs fizzling out, cheaper event production, layoffs of the people who built the culture, and increasingly gamified, exclusive event invitations. The trade-off it describes matters to anyone who depends on vulnerability disclosure programs: when the incentives shift toward locking in buyers rather than serving hackers, the quality of the security research pipeline is what erodes.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.