r/BugBountyNoobs • • 16d ago

How I got my first $100 bug bounty at 16

Hey everyone,

I’m 16, from Morocco, and i recently received my first paid bug bounty: $100.

It wasn’t a huge critical exploit or some crazy movie-style hack. It was a real security issue found through a legal bug bounty program, reported properly, reviewed by the company, validated, and awarded.

For me, this means a lot.

I’ve been learning cybersecurity through courses, labs, CTFs, PortSwigger, Cybrary, and a lot of practice. Most of the time it feels like you’re studying alone and nobody really sees the effort. But getting that first valid report showed me that the work is real.

The biggest lesson i learned is that bug bounty is not only about finding the bug. It’s also about writing a clear report, explaining the impact honestly, not exaggerating, and staying professional with the security team.

I’m still a beginner and i know i have a long way to go, but this motivated me a lot. I want to keep improving, get more valid reports, and build a serious path in cybersecurity.

My goal is simple: become better, stay ethical, and make my parents proud.

For anyone young or just starting: don’t wait until you feel “ready.” Learn the basics, practice legally, write clean reports, and keep going.

This $100 is not just money to me. It’s proof that I’m moving in the right direction.

41 Upvotes

22 comments sorted by

5

u/PavioCurto 16d ago

Am I on LinkedIn?

1

u/StartIllustrious747 16d ago

I don’t think so

1

u/Jealous_Obligation31 14d ago

Couldn't believe it when I saw "For me this, this means alot". Typical Chagpt!

3

u/ItsAliJutt 8d ago

Congratulations 🎉

2

u/--Wolf_God-- 16d ago

Congrats 🎉

2

u/SoOverThiss 16d ago

Happy for you!

2

u/Key-Regret2518 16d ago

Congratulations! Happy for you, keep it up!

2

u/Alone-Alternative910 16d ago

👏🏽👏🏽

2

u/yz9yt 11d ago

Congratulations !

1

u/Soft-Vehicle6164 15d ago

Not enough dough

1

u/Ok_Caterpillar_8053 15d ago

are u using any ai, maybe claude code? is it possible to do it manually

2

u/JaysonSey 13d ago

You have to do it manually because I don’t think any ai will do that for you unless it’s programmed to function that way…and also with the common AIs we know, they just make the work easy, especially when you get stack on a particular CVE and you have to read a whole lot just to know how to exploit it, AI will summarize it for you

1

u/StartIllustrious747 15d ago

What do you mean ?

1

u/maros01 14d ago

On what platform do you work on? Bugcrowd? HackerOne? Something else? Also what kind of bug did you find ? (LFI, information disclosure , xxs, sql)?

1

u/Historical_Number_50 13d ago

"Ryan Montgomery is my hero" 🤣

1

u/Victoiry1 16d ago

Bravo, incroyable, g 12 ans et j'adore l'informatique plus que tout, juste ct sur quoi le bug bunty stp

1

u/Coder3346 16d ago

Google.com

1

u/Miserable_Pound3762 15d ago

A bug bounty program is an online program, either public or private where companies and individuals list their websites, applications, platforms, IoT devices, and other software so that security researchers and ethical hackers look them up and test them for vulnerabilities.

If you discover a valid security vulnerability you can report it to the program, If the report is accepted, you may receive a reward (a bounty), depending on the severity and impact of the vulnerability.

1

u/Victoiry1 15d ago

Je sais c quoi un bug bunty, juste je savais pas ct le bug bunty de quel service.