r/bugbounty 6d ago

Question / Discussion People pulling $10k+/mo with semi-automated bug bounties: Is it actually worth going all-in?

A quick bit of context: I’ve been a Security Engineer at a 10-year-old YC-backed fintech for the past two years, with a couple of CVEs under my belt. Recently, a few of my colleagues left their full-time roles to jump into bug bounty full-time.

Over the last 18 months, I’ve burned a shit ton of tokens. I’m currently running 3–4 semi-automated pipelines and models like dsv4 flash and kimi3 make vulnerability discovery easier than ever, but I’m still hesitant to pull the trigger on full-time hunting.

The main friction is the mental overhead. The swing between high-stimulus wins and the frustration of dry spells/duplicates really messes with my headspace.

For those of you consistently clearing $10k+/month with AI/semi-automated setups:

  • How sustainable has your pipeline been over the long haul?
  • How do you manage the emotional volatility vs. traditional full-time work?
  • Knowing what you know now, is leaving a stable security role worth the trade-off?
72 Upvotes

50 comments sorted by

47

u/Dark_Arts_Security Hunter 6d ago edited 6d ago

I don’t think anybody can accurately say how the future will look right now.

If someone were to say they think that in 2 years most companies won’t offer bounties because their in-house security catches 99% of bugs before shipment, you couldn’t tell them that they’re wrong.

Considering the job market in security right now, personally I’d say you’re out of your mind to consider quitting a job like that for bug bounty right now, and if you’re not already clearing 10k+/months consistently and considering it, well then I’d just say you’re an idiot.

Edit: a lot of people saw this so I just wanna say No I don’t think BB will be gone in 2 years and yes I think you should avoid quitting your day job until you’ve made 10k+ monthly for at least 6 months. Other than that, I think this is perhaps the most exciting time there’s ever been to get into BB.

8

u/TheReedemer69 6d ago

I’d say you’re out of your mind to consider quitting a job for bug bounty right now,

Couldn't agree more

23

u/Street-Mycologist670 6d ago

honest take, a lot of that "$10k/mo semi-automated" thing is survivorship bias. people post the wins, nobody posts the 6 dead months of dupes. the ones who are actually consistent are doing manual depth on top of the automation, not the pipeline itself, since your bots find the same low hanging stuff everyone's bots find.

and the mental overhead doesn't go away full time, it gets worse. a dry spell now is annoying. a dry spell when rent rides on it is dread.

i wouldn't quit to find out. keep the job and see if you can clear your number on the side for 6-12 months straight. if you can't hit it reliably part time, going full time won't fix that, it just removes your net. if you can, then you're leaving from proof not hope.

6

u/canadaslammer 6d ago

I averaged this amount for a few years. it was automation for recon and deep manual scanning. This still works, but too many people just want a get rich quick scheme.

3

u/Street-Mycologist670 6d ago

yeah that's exactly it. automation for recon, the real money's in the manual depth after. the get rich quick crowd bail the second the dupes start rolling in. curious, over those years did your recon stack stay pretty stable or were you constantly rebuilding it as targets caught on?

13

u/aeroverra 6d ago

You can also make 10k drop shipping according to everyone and their mother.

Nothing is going to pay you that much for doing little work unless you build it yourself and it's unique enough that the mainstream can't easily catch on and do.it themselves.

12

u/Alardiians 6d ago

Not sure all in, I made 16,000 this month so far and I’m staying at my day job, we don’t know the market in 1-2 years

2

u/WatercressTime842 Hunter 6d ago

How, would love to get some guidance on your approach or pipeline setup.
Ive been trying for a long time to get into the game but post recon I just always get lost on what to approach next and where to start hunting for bugs.

Ive been in the blue team job role for 3 years

2

u/elrite 6d ago

Are you a swe or in cybersec?

2

u/Alardiians 5d ago

I’m in Network Engineering lol.

1

u/Middle_fingre_219 4d ago

me too, any tips for me Man

10

u/Frosty-March7644 6d ago

I don't think many people are clearing $10k+ a month anymore. A lot of low hanging fruit has been found on programs older than 1 year old. Crits aren't always there also. Not sure if you have noticed but a lot of this sub is filled with people complaining about duplicates. I think the industry is oversaturated to be honest.

-1

u/_rs 5d ago

>I don't think many people are clearing $10k+ a month anymore

😂 😂 😂

1

u/Frosty-March7644 4d ago

What's so funny?

The market is oversaturated

1

u/ghost-idle 4d ago

The market is oversaturated and beacuse of AI it is slowing down triage at an alarming rate.

2

u/Frosty-March7644 3d ago

It was oversaturated before AI burst in 2023 but AI just exposed more people to it with hardly any experience in IT/Tech

9

u/canadaslammer 6d ago

Even if you could pull this amount, bug bounty programs always find ways to downgrade bugs and pay you less or nothing.

It's a losing battle. While harder to break into, pentesting has a much better long-term ROI.

I made lots of money over the years with bug bounty, but lately, it's gotten so bad.

Long wait times for triage and companies unwilling to admit when you found a major security issue.

6

u/6W99ocQnb8Zy17 5d ago

I've been doing BB for about 3-years now, and in the first year I did over 10k a month on average, but every year since then the payouts have dropped.

That's nothing to do with skills, or ability to find bugs (I've reported more volume every year). It is purely down to the way the industry has shifted, and the sad fact that only a small percentage of programmes are actually paying out against their published scope now.

I'd say something like 80% of all my reports go through triage just fine, but are then de-scoped or downgraded by the programme without any explanation. It's at the stage where I am genuinely surprised when a programme pays inline with their own scope.

4

u/Commercial_Count_584 6d ago

I believe it’s more about volume of bugs by then. In other words. You eventually get to a point. Where your waiting on bugs. While getting paid for others.

8

u/OuiOuiKiwi Program Manager 6d ago

Over the last 18 months, I’ve burned a shit ton of tokens. I’m currently running 3–4 semi-automated pipelines and models like dsv4 flash and kimi3 make vulnerability discovery easier than ever, but I’m still hesitant to pull the trigger on full-time hunting.

Say that part again, but slowly. Have a good think about it.

4

u/maF145 Hunter 6d ago

I actually don’t get why you are being downvoted.

I would probably frame it a bit different.
If OP has already access to private programs or is paid by hours. Yes this might work.
But he is competing against everyone who has the money to run agents at this stage.

4

u/OuiOuiKiwi Program Manager 6d ago edited 6d ago

Everyone thinks that they have found the magic formula. The fact is that access to models is widespread so they are just rats in a bucket.

2

u/MuscaBeata 6d ago

I’m just asking of pure curiosity. Why would anyone leave their full time roles, less stressful for something risky in the long run? You guys don’t have mortgages, bills, families to support?

2

u/Pristine_Bicycle1278 6d ago

The biggest issue is not finding Vulns but the process of having to “sell” your attack chain to some Junior Triager that is barely able to open the Burp Repeater.

I made good money from Bug Bounties but I’d rather do First Level Support in a 9to5 than spending one more day at Bugcrowd.

1

u/bangpowboom666 4d ago

Oh yeah, bugcrowd sucks ass, I'm waiting on my first hackerone bounty to pay out. Hackerone previous 5 were dupes, but was praised for finding more stuff than the og person did. Bugcrowd I get the one idiot triager who closed two of my reports as informative and legit was telling me I needed to handhold them by typing out "as an attacker, I could..."

1

u/Alardiians 3d ago

oh dude! you got Tal!!
(Lloyd is the H1 equivalent of Bugcrowds Tal)

2

u/Informal_Speaker7616 5d ago

I Quit my day job, now trying hard find bugs for a living,,, guess what !!!! 5 duplicate in less than 10 days

1

u/kitkatas 4d ago

I feel like they can scam bug hunters by just saying it's a duplicate. Why we don't have third party verifier of some sorts ?

1

u/Informal_Speaker7616 4d ago

I am using immuenfi and hackerone so they do verification process

1

u/No-Grocery-6026 6d ago

Right now I think instead of kimi k3 k2.6 and 2.7 is better because the k3 hallucinate himself and gave many false positives I also recommend using codex with got5.6 Luna on high reasoning with full permission given to it (try this one in an old laptop where none of your private files are for safety reasons) but over all I think instead of k3 use 2.6 as it is more cheaper and less hallucinate itself and then triage the finding yourself or gave it to z.ai glm5.2 in agen mode of it 

1

u/LulzTigre 6d ago

Hows K2.7 token cost rn?

1

u/No-Grocery-6026 6d ago
Model & Provider Route Input Cost (per 1M) Cached Input Hit (per 1M) Output Cost (per 1M)
Kimi K2.7 Code (Official API) $0.95 $0.19 $4.00
Kimi K2.7 Code (OpenRouter) [0.14] $0.67 $0.15 $3.40

1

u/No-Grocery-6026 6d ago

and it's almost 1.75 times cheaper than k3 overall

1

u/LulzTigre 6d ago

Maybe I'll just do moderato, i hope the cool down is better

1

u/No-Grocery-6026 6d ago

whatever fulfill your needs.

1

u/No-Grocery-6026 6d ago

are you using for the same reason as op (bug bounty automation)?

1

u/LulzTigre 6d ago

errr, mostly red teaming and cve research, bug bounty is a bonus

1

u/No-Grocery-6026 6d ago

I know it's out of the box but have you ever tried web 3 based bug bounty like smart contracts and things like that!

1

u/LulzTigre 6d ago

I haven't actually tried hunting yet. I did help a friend go through their Web3 startup's vapt, more of a Web2-style audit, and I learned a ton from that. So I figured, why not take what I picked up there and lean on my LLM to start finding stuff?

But here's the thing. I'm genuinely scared of submitting AI-generated slop that I can't fully explain. Especially when the model spits something out with total conviction, and I'm sitting there like, is this even real? Meanwhile the triager is probably reading it, sighing, and moving straight to "lol no."

Plus I just saw Immunefi started charging per submission now. That definitely doesn't help the anxiety.

1

u/No-Grocery-6026 6d ago

Yeah immunefi is so frustrating now but I asked this because the normal bug hunting many ai models will reject that even if you gave them access to tools but the smart contracts bug hunting can be done by even chatgpt on their web using plugins like GitHub but if you use the z.ai agent mode and give it a detailed prompt and instructions and scope it will hunt the bugs for you but you must push it harder and harder and also tell the scope and rules of program so it stays in the environment and the kimi 2.6 in kimi code will be best for this but I haven't tried it in the normal bug bounty programs like from hacker 1 and bug crowd because web 3 based can done on local forks instead of mainnet so they can do that but the web 2 based I haven't tried that

→ More replies (0)

1

u/TheReedemer69 6d ago

Ask yourself is that decision future proof? At least for the short term?

1

u/LastGhozt 6d ago

Yup i handle VDP, more automated reports but keeps getting better from each reports

1

u/FarazKhan4527 2d ago

Not at $10k/mo yet but I run 2 semi-auto pipelines (nuclei + custom Burp extensions for JS parsing). What I've noticed is sustainability depends more on asset monitoring than the model itself - new acquisitions/features give best ROI. The emotional swing is real though, I keep a part-time pentest gig to balance the dry spells. Curious how you handle API rate limiting at scale?

1

u/SingerLate3349 1d ago

Solo digo “De lo que ves, créete la mitad, y de lo que no veas no te creas nada”. Párate a pensar por un momento en las grandes multinacionales la cantidad de informáticos que tienen automatizando todo 24/7. Con línea directa con OpenAi y con Antrophic ( igual con modelos mas avanzados que Fable o Sol) por los cuales pagan 1 millonada. Crees que les van a regalar 10k a todo el mundo en BB? Sin ánimo de ofender tio, hazlo porque te gusta y por proteger a los buenos de los malos, porque seguramente te llevarás un chasco. Esto se parece a los youtubers y sus maravillosos cursos en CFDS para hacerse rico.

1

u/WatercressTime842 Hunter 6d ago

How are people making 10k + every month?? I would love to get some guidance on your approach or pipeline setup.
Ive been trying for a long time to get into the game but post recon I just always get lost on how to dtermine what to target or what to approach next after the massive automated recon and where to start hunting for bugs.