September 3, 2026
Is Manual Bug Bounty Hunting Still Worth It in 2026?
Everyone keeps asking this question. Nobody gives an honest answer. So here are the real numbers.

By Abhishek meena
4 min read
The mods of r/bugbounty delete this question now.
Not because it breaks any rule. But because people ask it so many times that it counts as a repeated topic.
Beginners ask it after their first month of finding only duplicate bugs. Full-time hunters ask it after months of reports closed without payment.
This August, a security analyst with three years of experience asked it. The thread was deleted before lunch.
Everyone is asking the same question: is manual bug bounty hunting still worth it?
Nobody is answering.
Not HackerOne. Not Bugcrowd. Not even the companies that cut their payouts this year. I have been watching this question pile up for months. That silence itself tells you something.
Big programs are shutting down or paying less
Let's start with curl, a free software project used by almost everyone on the internet.
Its creator, Daniel Stenberg, started getting AI-written bug reports faster than his team could review them. At one point, only 1 report out of 20 was a real bug. The other 19 were junk.
So he shut down the bounty program. He said it openly: the goal was "to remove the incentive for people to submit crap."
Other programs followed.
The Internet Bug Bounty paused its payments in April. Node.js ended its bounty the same month.
In July, GitHub cut its public payouts by 67 to 85 percent. A critical bug that paid $30,000 before now pays $10,000. Some new hunters get T-shirts instead of money.
In August, Apple added a limit on how many reports you can send, with a 30-day wait between reports.
One Italian security company, Bynario, found a real and serious flaw in macOS. On the black market, it would sell for $100,000 to $200,000.
They could not report it. Apple had already blocked them from sending more reports.
The inbox was full of AI junk. A real vulnerability never got submitted.
How much do hunters actually make?
In May 2026, a researcher named Alex Rhickey studied HackerOne's data. He put numbers on what everyone already suspected:
- About 95 percent of people who submit reports never earn a single dollar.
- The hunters who do earn something make about $1,620 per year on average.
- The top 1 percent of hunters earn more than the bottom 90 percent combined.
And in that same period, Google paid out a record $17.1 million in bounties.
Both facts are true at the same time. Read that again if you need to.
A tiny group is making record money. Almost everyone else is making close to nothing. The middle is disappearing.
here's the real straight answer of this situation
"Worth it" depends on your other options. And a platform has no idea what your other options are.
HackerOne cannot tell you that a simple junior security job pays five times more than the average hunter makes.
Bugcrowd will not tell you that after duplicates and slow reviews, your hourly earnings might be lower than minimum wage.
They sell a market. Asking them if hunting is worth your time is like asking a casino if you will win.
So you have to build the answer yourself. And the data says the answer depends on one thing.
What AI can already do better than you
In June 2025, an AI agent called XBOW became the number one researcher in the US on HackerOne. It found more than a thousand vulnerabilities.
Another AI agent reached a top-3 spot with a reported budget of $5,000 per month.
Over three weeks this spring, Bugcrowd saw its report queues grow by 334% percent. One program received 3,000 reports in 90 days.
So what are these AI agents good at?
Simple bugs on single endpoints. Known patterns. Things a scanner can find: reflected XSS, missing headers, obvious IDORs on big public programs.
Any bug you can find without understanding what the application is supposed to do.
And where do they fail?
Attack chains. Business logic. Bugs where you must understand what the app should do, and notice that it doesn't.
One hunter on r/bugbounty said he has "PTSD from explaining complex attack chains" to the people reviewing reports. Humans already struggle to get chains approved. AI cannot write them at all.
So the line is drawn. And it is not where most hunters think it is.
You should do this as a bug bounty hunter
If your manual hunting finds the same bugs a scanner would find, you are now competing with software that costs almost nothing to run.
That fight is already lost.
Four changes that actually fix the math:
Stop hunting where robots hunt. Big wide-open programs with thousands of hunters. The easy bugs there are not easy anymore. Robots pick them at machine speed, and their duplicate reports bury your valid report before a human even opens it.
Hunt where deep understanding matters. Small niche programs. Apps full of business logic. Places where you need weeks of learning before you can even see what is wrong. Deep knowledge of one program beats shallow testing of a hundred.
Write reports for tired humans. HackerOne now limits new researchers to about four reports until they show real skill. Your report competes with a thousand junk reports for one tired reviewer. Finding the bug is half the work. Writing the report well is the other half.
Count your money like a business.
Some programs now charge you to report.
Solana's Alpenglow hunt takes 0.5 SOL per submission.
Immunefi keeps its fees even when your report is a duplicate.
One valid bug took 362 days to get an answer, and the answer was "informative," which means no bounty. Track what you really earn per hour, not the payouts you dream about.