September 22, 2026
100 Days of Bug Bounty — Day 1 🐞
Today, I’m starting something I’ve wanted to do for a while: 100 days of bug bounty.

By Zubair Ahmed
Over the past few weeks, I had some success with Vulnerability Disclosure Programs (VDPs). That gave me a little confidence that I'm actually getting somewhere with web security, so I decided it was time to start exploring paid bug bounty programs.
Day 1
I spent some time looking through different bug bounty platforms and eventually found a program that looked interesting.
I didn't want to rush into testing everything I could find. Instead, I started with the basics:
• Understanding the program scope • Identifying the main assets • Basic subdomain and endpoint reconnaissance • Looking at the technologies being used • Getting a feel for how the application is structured
Nothing major happened on the first day, and that's okay.
For me, the goal of these 100 days isn't to find a critical vulnerability every day. It's about showing up consistently, learning from every target, and becoming better at finding real vulnerabilities.
Day 1 complete.
99 days to go.