Who earns best in the world of technology today? Not always the creator of the application, but those who can “spoil” them. Legally. Hackerone – the largest Bug Bounty platform – in the last 12 months has paid ethical hackers prizes with a total value of $ 81 million. In addition to the dizzying amount, it is also a sign of time: cyber security in the era of artificial intelligence enters a new phase.
What you need to know:
Bug Bounty programs are an open invitation to security researchers: find a gap, report it, receive a prize. In 2025, Hackerone already served nearly two thousand programs for Githuba, Goldman Sachs, Uber and … the US Department of Defense. Awards are growing – On average, in the active program, participants can count on 42 thousand. dollars a yeara The best and most prolific hunters exceed six -digit amounts. In addition to earnings, however, the nature of the threats itself changes.
AI is the fastest growing gap in systems
Only a few years ago classic errors dominated: XSS and SQL Injection. Today, their participation is falling. There are problems related to access control and INSECURE Direct Object reference. However, what really attracts attention is an explosion of AI threats.
The Hackerone report shows that the number of susceptibility in artificial intelligence systems increased by over 200% per year. The Prompt Injection category is developing the fastest – i.e. manipulating the commands given by language models – where an increase of as much as 540%was recorded. If anyone still doubted that AI is opening new cyberbathers, these data dispens down illusions.
Man and AI in tandem
Among the over 1,800 researchers surveyed by Hackerone, as much as 70% admits that they use AI in their daily work. We are dealing with a strong trend: a new category of specialists is created, whose company describes “bionic hackers”. They combine their own experience with the possibilities of tools based on artificial intelligence. This is how a larger scale of analyzes and faster error detection and reporting are created.
Interestingly, AI works here on both sides of the barricade. On the one hand, it makes it easier to create more resistant systems. On the other – it gives hackers tools for automatic hunting for susceptibility. Take, for example, Pen-Testerów: they massively use AI in analyzing susceptibility in their clients’ infrastructures. Faster and more detailed data means greater revenues resulting from the ability to expand the scale of served customers. It’s exactly like the marketing industry I know. While conceptualization, advanced operations requiring precision and this most creative part of the strategy must be driven by “human sense”, so monotonous, more analytical operations, can be successfully taken over by AI.
Read also: Burger King in trouble. Hackers make fun of security
The future of security
The year 2025 shows that cybersecurity is no longer only a domain only to occupy IT specialists enclosed in server rooms. This sphere is growing into corporations, governments and independent researchers from around the world. It is worth noting that only this year over a thousand Bug Bounty programs covered AI technologies – this is an increase of 270% year on year. Code safety becomes as important as physical security. Bug Bounty allows you to protect the critical nodes of our infrastructure and … to earn well to those who “embrace” such magic.
