Skip to main content

External Payments

Hackers: Receive bounties if you don't have a HackerOne account

If you're a hacker who submitted a valid vulnerability without a HackerOne account, you can still receive bounties for your valid vulnerabilities.

To receive your bounty as an external hacker:

  1. Click Claim your bounty in the bounty notification email.

  2. Review the bounty invitation. If there isn't an account associated with your email address, you'll be prompted to create a new account.

  3. Sign up for a HackerOne account.

  4. Choose to accept or reject the bounty.

  5. Complete the pre-requisite steps that you have not yet completed in this view before completing your tax form by selecting the relevant button. For more information about each action:

Note: You are eligible to verify your identity if you’ve submitted at least one report or received a reward.

Once the button is active, click Sign tax form and fill out the tax form. You'll be sent a tax form via HelloSign to fill out, and once it's complete, it'll go through a review process. The review process will take about 48 hours, and once that's complete, you'll receive an email notification and will be able to receive payment.

After you set your payout preferences Settings > Rewards and payments > Preferences, the payment will be sent to your account.

Did this answer your question?