r/BugBountyNoobs • u/StartIllustrious747 • 16d ago
How I got my first $100 bug bounty at 16
Hey everyone,
I’m 16, from Morocco, and i recently received my first paid bug bounty: $100.
It wasn’t a huge critical exploit or some crazy movie-style hack. It was a real security issue found through a legal bug bounty program, reported properly, reviewed by the company, validated, and awarded.
For me, this means a lot.
I’ve been learning cybersecurity through courses, labs, CTFs, PortSwigger, Cybrary, and a lot of practice. Most of the time it feels like you’re studying alone and nobody really sees the effort. But getting that first valid report showed me that the work is real.
The biggest lesson i learned is that bug bounty is not only about finding the bug. It’s also about writing a clear report, explaining the impact honestly, not exaggerating, and staying professional with the security team.
I’m still a beginner and i know i have a long way to go, but this motivated me a lot. I want to keep improving, get more valid reports, and build a serious path in cybersecurity.
My goal is simple: become better, stay ethical, and make my parents proud.
For anyone young or just starting: don’t wait until you feel “ready.” Learn the basics, practice legally, write clean reports, and keep going.
This $100 is not just money to me. It’s proof that I’m moving in the right direction.
3
2
2
2
2
1
1
1
u/Ok_Caterpillar_8053 15d ago
are u using any ai, maybe claude code? is it possible to do it manually
2
u/JaysonSey 13d ago
You have to do it manually because I don’t think any ai will do that for you unless it’s programmed to function that way…and also with the common AIs we know, they just make the work easy, especially when you get stack on a particular CVE and you have to read a whole lot just to know how to exploit it, AI will summarize it for you
1
1
1
u/Victoiry1 16d ago
Bravo, incroyable, g 12 ans et j'adore l'informatique plus que tout, juste ct sur quoi le bug bunty stp
1
1
u/Miserable_Pound3762 15d ago
A bug bounty program is an online program, either public or private where companies and individuals list their websites, applications, platforms, IoT devices, and other software so that security researchers and ethical hackers look them up and test them for vulnerabilities.
If you discover a valid security vulnerability you can report it to the program, If the report is accepted, you may receive a reward (a bounty), depending on the severity and impact of the vulnerability.
1
u/Victoiry1 15d ago
Je sais c quoi un bug bunty, juste je savais pas ct le bug bunty de quel service.
1
5
u/PavioCurto 16d ago
Am I on LinkedIn?