Skip to main content

Hacker Milestone Rewards Program

Hackers: Details on HackerOne’s new milestone-based rewards and point system.

Overview

HackerOne has launched the Hacker Milestone Rewards Program, a new achievement-based system that recognizes researchers for validated vulnerabilities. The program replaces the old reputation-only model, introducing a more inclusive, results-driven approach. In partnership with PortSwigger and PentesterLab, HackerOne now rewards researchers with milestone points, licenses, and exclusive swag.

Points System

Researchers earn milestone points based on the severity of valid reports. The first five duplicate reports for a vulnerability are also eligible for points.

Point breakdown:

  • Low Severity: 3 points

  • Medium Severity: 15 points

  • High Severity: 25 points

  • Critical Severity: 50 points

  • Duplicate: 2 points

Milestone levels:

Level

Points Required

1

10

2

20

3

50

4

100

5

200

6

300

7

400

8

500

9

1000

10

2000

Rewards and Partnerships

HackerOne has partnered with leading security and training organizations to offer practical, skill-building rewards.

Exclusive Rewards Include:

  • Burp Suite licenses from PortSwigger, a premier web security toolkit developer.

  • PentesterLab licenses, giving access to hands-on web security training exercises.

  • Custom HackerOne profile badges recognizing milestones.

  • Exclusive HackerOne swag, including branded apparel and gear.

Program Details

  • The Hacker Milestone Rewards Program launches September 10, 2025.

  • All researchers begin at zero points at the start of each season.

  • The first season will last 16 months, with subsequent seasons running annually.

  • Reward notifications will be sent to researchers’ wearehackerone.com email addresses.

Why It Matters

This new reward structure acknowledges the breadth of contributions from the hacker community - not just the first to find issues, but all valid submissions. It highlights a shift toward rewarding consistent, quality research and encourages skill growth across all experience levels.

Important Notes

Points Are Not Awarded for VDP Submissions

Points toward the Milestone Rewards Program are earned through bounty programs only including LHEs and Challenges. Submissions made to Vulnerability Disclosure Programs (VDPs) do not count toward your milestone points total.

Whitelist Milestone Reward Emails

Milestone reward notification emails are sent from HackerOne's Milestone program (milestone@hackerone.com). To ensure you receive these emails, we recommend adding the sender to your allowlist/whitelist. Milestone emails may otherwise be filtered into your spam or junk folder, or automatically deleted depending on your email provider's settings.

Customs Fees & Import Taxes for Physical Swag

All items are shipped from the United States. Depending on your location, customs fees, duties, or import taxes may apply upon delivery. These charges are the recipient's responsibility and are not reimbursed by HackerOne. Please estimate any potential customs charges before placing your order.

Issues With Shipping or Physical Swag Delivery

If you experience any issues with your shipment - such as delays, missing packages, or damaged items - please reach out directly to the shipping courier using the tracking information provided in your confirmation email. For issues related to the swag item itself, contact SwagPro directly for assistance.

Next Steps

To participate, start submitting valid vulnerabilities through your HackerOne profile. Track your progress toward milestones and watch for reward notifications as you climb the levels. For more details, visit HackerOne’s blog announcement.

Did this answer your question?