Skip to main content

Hacker Milestone Rewards Program

Hackers: Details on HackerOne’s new milestone-based rewards and point system.

Updated this week

Overview

HackerOne has launched the Hacker Milestone Rewards Program, a new achievement-based system that recognizes researchers for validated vulnerabilities. The program replaces the old reputation-only model, introducing a more inclusive, results-driven approach. In partnership with PortSwigger and PentesterLab, HackerOne now rewards researchers with milestone points, licenses, and exclusive swag.

Points System

Researchers earn milestone points based on the severity of valid reports. The first five duplicate reports for a vulnerability are also eligible for points.

Point breakdown:

  • Low Severity: 3 points

  • Medium Severity: 15 points

  • High Severity: 25 points

  • Critical Severity: 50 points

  • Duplicate: 2 points

Milestone levels:

Level

Points Required

1

10

2

20

3

50

4

100

5

200

6

300

7

400

8

500

9

1000

10

2000

Rewards and Partnerships

HackerOne has partnered with leading security and training organizations to offer practical, skill-building rewards.

Exclusive Rewards Include:

  • Burp Suite licenses (1- and 3-month increments) from PortSwigger, a premier web security toolkit developer.

  • PentesterLab licenses, giving access to hands-on web security training exercises.

  • Custom HackerOne profile badges recognizing milestones.

  • Exclusive HackerOne swag, including branded apparel and gear.

Program Details

  • The Hacker Milestone Rewards Program launches September 10, 2025.

  • All researchers begin at zero points at the start of each season.

  • The first season will last 16 months, with subsequent seasons running annually.

  • Reward notifications will be sent to researchers’ wearehackerone.com email addresses.

Why It Matters

This new reward structure acknowledges the breadth of contributions from the hacker community—not just the first to find issues, but all valid submissions. It highlights a shift toward rewarding consistent, quality research and encourages skill growth across all experience levels.

Next Steps

To participate, start submitting valid vulnerabilities through your HackerOne profile. Track your progress toward milestones and watch for reward notifications as you climb the levels. For more details, visit HackerOne’s blog announcement.

Did this answer your question?