Bug bounties,
without the dead ends.
A source-linked record of vulnerability programs last observed as public and paid. Every listing points to an official platform or the organization’s own policy—not a copied aggregator page. Live-permitted sources are rechecked every 12 hours; retained snapshots stay visibly dated.
- First-party policies
- 47
- Source groups
- 9
- Last attempt
- 0m ago
- Complete live inventories
- 2 / 9
01 / DIRECTORY
Find your next scope.
1087 matching programs
02 / SOURCE COVERAGE
Traceable by design.
No community aggregator is accepted as evidence.
HackerOne
Live directory 2026-10-05
Bugcrowd
Snapshot 2026-08-06 · permission-limited
Intigriti
Snapshot 2026-08-06 · permission-limited
YesWeHack
Snapshot 2026-08-06 · permission-limited
HackenProof
Snapshot 2026-08-06 · permission-limited
Immunefi
Snapshot 2026-08-06 · permission-limited
Cantina
Snapshot 2026-08-06 · permission-limited
Sherlock
Live directory 2026-10-05 · 39 raw → 37 unique
First-party
47/60 eligible · 30 reachable · 4 failure types
03 / METHOD
What “open” means here.
There is no universal registry for bug bounties. This index treats completeness as a verifiable process: cover authoritative directories, follow first-party disclosures, and keep uncertainty visible.
- 01
Money is explicit
Reward language or a bounty table must be present. Unpaid VDPs are excluded.
- 02
The door is open
Public submission must be available now. Private, paused, invite-only, and ended programs are excluded.
- 03
Evidence is primary
Accepted evidence is an official platform page or the organization’s own domain.
- 04
Failures remain visible
A source outage never silently deletes a program. Permission-gated directories stay labeled as snapshots instead of being crawled against their rules.
- 05
Records stay minimal
Platform descriptions, scopes, logos, and reward tables are not reproduced. Follow the official link for current terms.