October 9, 2026
Bug Bounty Just Paid a Record $89 Million. Here’s the Number Nobody’s Celebrating.
HackerOne’s latest report shows exposure debt is up 131%. The bugs are being found. They’re not being fixed.

By Riya Limba
4 min read
HackerOne's latest report shows exposure debt is up 131%. The bugs are being found. They're not being fixed.
I read the HackerOne report on a Thursday morning and felt something I hadn't expected: discomfort.
The headline was everything the bug bounty community wanted to hear. Organisations using the H1 Platform awarded researchers a record $89 million between July 2025 and June 2026 — an 18% increase on the previous year, and the platform's highest annual total ever.
The pie got bigger. The bounties got paid. The researchers got rewarded.
Then I scrolled to the next line.
Exposure debt rose 131%.
I sat with that for a moment. Because I'd been reading about record payouts all year. I'd been writing about them. Celebrating them, even.
Nobody told me about the debt.
What "Exposure Debt" Actually Means
I had to read the report twice to understand what the number was measuring.
Exposure debt isn't a financial metric. It's the accumulated gap between vulnerabilities discovered and vulnerabilities fixed. Every confirmed bug that doesn't get patched sits in that debt. Every report that gets triaged but never remediated. Every finding that enters a backlog and never leaves.
A 131% increase means the debt more than doubled in a single year.
The bugs are being found. At record rates. By record numbers of researchers. The AI tools that flood triage queues with slop are also helping find real vulnerabilities faster than ever before.
But fixing isn't keeping up.
The Numbers That Tell the Real Story
HackerOne's data from earlier this year laid the groundwork. Submissions jumped 76% year-over-year through March 2026. The percentage of valid findings held steady at about 25%.
That means the absolute number of confirmed bugs grew proportionally. More submissions. More real vulnerabilities. More triage work than anyone can handle.
Meanwhile, remediation throughput improved by only about 19%.
Do the math. Discovery up 76%. Fixing up 19%. The gap compounds every quarter.
The 131% exposure debt figure is what that gap looks like after twelve months.
Why This Should Matter to Every Beginner
I've written before about the numbers that make bug bounty feel hopeless. Intel closing its program. curl ending its bounty entirely. Google pausing its OSS VRP after AI-generated reports overwhelmed the team.
Those closures were about intake — the volume of reports coming in.
Exposure debt is about something different: what happens after intake.
A report that gets triaged and confirmed is a success for the researcher. A payout. A reputation boost. A line on a resume.
But for the organisation, that confirmed bug is now a liability. It's in the backlog. It's waiting for a developer to fix it. And if the developer never gets to it, the bug is still there — still exploitable, still dangerous.
The HackerOne report doesn't just say more bugs are being found. It says more bugs are sitting unfixed.
The Patch Capacity Crisis Nobody Talks About
I came across a Cloud Security Alliance analysis earlier this month that reframed everything.
CSA's Project Glasswing analysis found that AI-driven discovery identified more than 10,000 high and critical vulnerabilities in its first month. Only 97 had been confirmed patched — about 6%.
The bugs are real. The patches aren't happening.
Microsoft's July and August 2026 Patch Tuesday releases contained 570 and 398 fixes respectively. Palo Alto Networks' NOVA system reported 14,090 previously unknown open-source vulnerabilities in two months.
14,090. In two months. From one system.
And AI-generated patches? CSA notes they fail or introduce defects more than half the time.
The same tools that find the bugs can't reliably fix them.
What This Means for Me
I've found one confirmed bug. I'm waiting to be paid. I'm still learning how to write reports that don't get closed in four minutes.
Reading the exposure debt number, I felt something shift.
The question I'd been asking myself was: "How do I find bugs that AI can't find?"
The better question — the one the data is pointing to — is: "How do I find bugs that someone can actually fix?"
A report for a bug that enters a backlog and never leaves is a paycheck for me and a liability for everyone else. The vulnerability is still there. The data is still exposed. The system is still vulnerable.
I don't want to contribute to exposure debt. I want to contribute to remediation.
What I'm Doing Differently
I can't fix the remediation crisis. I can't force organisations to patch faster. I can't solve the maintainer capacity problem that the CSA analysis describes so clearly.
But I can change three things.
First, I'm looking at remediation history, not just bounty size. A program that pays well but never patches is a program that's accumulating debt. A program with lower payouts but active patching is contributing to actual security. I'd rather help the second one.
Second, I'm treating "reproducible" as a higher bar than "valid." A valid bug that takes an hour to reproduce is less useful than a valid bug with a one-line PoC. The kernel's guidance asks for reports with reproduction evidence and ideally a tested patch. That's the standard now. The easier I make it for a developer to fix the bug, the more likely it actually gets fixed.
Third, I'm remembering that the bottleneck isn't me. The CSA analysis says the unit of risk is the maintainer's time. My job isn't just to find bugs. It's to make the maintainer's job easier. Clear reproduction. Specific impact. Suggested fix. The thing that gets acted on, not the thing that gets added to a backlog.
The Uncomfortable Truth
Bug bounty just paid a record $89 million. That's genuinely good news for researchers. It means the work is valued. It means companies are still investing in finding bugs before attackers do.
But the 131% exposure debt increase tells a different story. It says the system is finding faster than it's fixing. It says the gap is growing. It says the record payouts are a symptom of a deeper problem, not a solution.
The bugs I find aren't just entries in my report history. They're entries in someone's backlog. And if that backlog keeps growing, the whole system — the programs, the payouts, the researchers — becomes unsustainable.
I don't have a CVE. I've found one confirmed bug. I'm still learning.
But I know what exposure debt means now. And I don't want to add to it.
If you're also learning bug bounty in a system where discovery outruns remediation, I write about what I'm actually figuring out — numbers included. Follow for more field notes from the bottom of the learning curve.