BugBountyScam is a community-run publishing platform where security researchers can share first-hand accounts of their experiences with bug bounty programs. We are not affiliated with, endorsed by, or connected to HackerOne, Bugcrowd, Intigriti, YesWeHack, Synack, or any other bug bounty platform. We are not a court, an arbitrator, or a regulator — we publish researcher-submitted accounts and make them searchable.
Bug bounty platforms hold most of the leverage. Researchers spend hours or days on a finding and have little recourse when a program decides not to honor it. Individual complaints scattered across social media are easy to ignore and easy to bury. Collected in one place, they become a public record that helps researchers make informed decisions about where to invest their time.
Every submission is reviewed before publishing:
Publication is not a legal finding of wrongdoing. Every report is one researcher's account of their own experience, and readers should treat it accordingly.
Any company or program named in a report can submit an official response. Responses appear alongside the original report and are clearly labelled. To submit one, email admin@bugbountyscam.com with the report URL, your company name, and verifiable contact details. See the full Resolution Policy for how disputes, corrections, and status changes are handled.
If a report contains a factual error, submit a dispute through the Resolution Policy process. Reports are updated or annotated when errors are confirmed. Reports are only removed where required by law or where the original submitter withdraws voluntarily. Legal removals are marked as such rather than silently deleted, so the public record reflects that a report existed.
This project is run anonymously by volunteer editors. Editorial decisions are made by more than one editor where possible, and appeals of status decisions are reviewed by a second editor. We do not accept payment to publish, edit, or remove reports.
BugBountyScam.com · Contact: admin@bugbountyscam.com