What Happened to HackerOne?
HackerOne, once celebrated as the nexus for ethical hacking, has become a cautionary tale of corporate 'enshittification' under VC influence, losing its hacker-first ethos. The author, a seasoned bug bounty hunter, chronicles its decline from a vibrant community to a sales-driven entity, culminating in a controversial AI strategy and perceived dishonesty regarding researcher data usage. This expose highlights the tension between mission and profit, sparking a critical discussion on corporate integrity and the future of cybersecurity platforms.
The Lowdown
This story meticulously details the transformation and perceived decline of HackerOne, a prominent bug bounty platform, from its idealistic origins to its current profit-focused state. Written from the perspective of a veteran bug bounty hunter, it laments the loss of the company's original values and its impact on the hacker community.
- Golden Age Genesis: HackerOne was founded by ethical hackers in 2011 to provide a safe, legitimate space for security researchers to report vulnerabilities without legal fear. Its "golden age" (2017-2020) was marked by a strong focus on hackers, fostering a vibrant community through exclusive Live Hacking Events (LHEs), community groups, and direct engagement.
- The Profit Problem Emerges: Around 2020-2021, fueled by $160M in VC funding, HackerOne shifted priorities. The initial CEO was replaced, the business model moved to capacity-based fees and multi-year contracts, and sales became the primary driver. This shift led to product stagnation and a degradation of experience for triagers, hackers, and customers alike.
- Flawed Fixes and Neglected Features: The introduction of the "Hacker Success Program" (HSP) aimed to support top hackers but inadvertently created a two-tiered system and failed to address the platform's core issue: a lack of feature development despite a decade-long backlog of user feedback.
- The AI Era and "Enshittification": HackerOne rebranded to "Continuous Threat Exposure Management" (CTEM) and launched an AI assistant, Hai, which the author describes as a superficial OpenAI wrapper that ignored fundamental platform improvements. This period also saw the marginalization of the original co-founders.
- AI Data Usage Controversy: In February 2026, concerns arose after ToS updates suggested researcher data could be used for AI training. Despite repeated denials from executives, subsequent internal communications and product descriptions revealed that an AI system was indeed "learning" from report outcomes, a distinction the author found disingenuous.
- Community Outcry and Damage Control: Public pushback from top hackers led to co-founders issuing vague, "AI slop" responses and quickly altering product page language, further eroding trust and reinforcing the perception that HackerOne was being dishonest.
The author concludes by expressing disillusionment with HackerOne's changed identity, urging founders to move on, hackers to recognize their value, companies to consider self-hosting, and entrepreneurs to build the platform HackerOne could have been.
The Gossip
Enshittification Echoes
Many commenters resonate with the author's narrative of HackerOne's decline, attributing it to the corrupting influence of VC money and a shift from a hacker-centric mission to pure profit. The image of sales teams enjoying tropical vacations while the core product stagnates is frequently cited as a symbol of this corporate rot. Discussions delve into the broader pattern of once-idealistic companies losing their soul when financial viability overtakes user value.
Payment Problem & Platform Pitfalls
A significant thread discusses the practical challenge of paying international hackers, acknowledging that HackerOne's payment system is a key value proposition. While the author suggests companies could build their own platforms, many commenters highlight the complexity and administrative burden of global payments. Alternatives like stablecoins are proposed but met with skepticism regarding their corporate feasibility and tax implications, underscoring the enduring need for a robust payment intermediary.
AI's Ambiguous Answers
The use of AI and HackerOne's contradictory statements about data usage spark heated debate. Some commenters argue that the distinction between 'training' and 'learning' from reports is a semantic trick, while others defend HackerOne, stating the two are technically different. The broader impact of AI is also discussed, with many noting that LLMs have led to an influx of low-quality 'slop' reports, making triage more difficult, and raising concerns about AI potentially displacing human hackers.
Reporting Roadblocks
Hackers share personal anecdotes of frustration with bug bounty programs, echoing the article's sentiment about declining report quality and triage experience. Common complaints include exploits being dismissed, severity downgraded, or companies failing to resolve reported issues for years. This highlights a perceived erosion of trust and effectiveness in the bug bounty ecosystem, suggesting that the problems extend beyond HackerOne to other platforms as well.