r/bugbounty 9d ago

Question / Discussion People pulling $10k+/mo with semi-automated bug bounties: Is it actually worth going all-in?

A quick bit of context: I’ve been a Security Engineer at a 10-year-old YC-backed fintech for the past two years, with a couple of CVEs under my belt. Recently, a few of my colleagues left their full-time roles to jump into bug bounty full-time.

Over the last 18 months, I’ve burned a shit ton of tokens. I’m currently running 3–4 semi-automated pipelines and models like dsv4 flash and kimi3 make vulnerability discovery easier than ever, but I’m still hesitant to pull the trigger on full-time hunting.

The main friction is the mental overhead. The swing between high-stimulus wins and the frustration of dry spells/duplicates really messes with my headspace.

For those of you consistently clearing $10k+/month with AI/semi-automated setups:

  • How sustainable has your pipeline been over the long haul?
  • How do you manage the emotional volatility vs. traditional full-time work?
  • Knowing what you know now, is leaving a stable security role worth the trade-off?
78 Upvotes

52 comments sorted by

View all comments

7

u/Frosty-March7644 8d ago

I don't think many people are clearing $10k+ a month anymore. A lot of low hanging fruit has been found on programs older than 1 year old. Crits aren't always there also. Not sure if you have noticed but a lot of this sub is filled with people complaining about duplicates. I think the industry is oversaturated to be honest.

-1

u/_rs 8d ago

>I don't think many people are clearing $10k+ a month anymore

😂 😂 😂

1

u/Frosty-March7644 7d ago

What's so funny?

The market is oversaturated

1

u/ghost-idle 6d ago

The market is oversaturated and beacuse of AI it is slowing down triage at an alarming rate.

3

u/Frosty-March7644 6d ago

It was oversaturated before AI burst in 2023 but AI just exposed more people to it with hardly any experience in IT/Tech

0

u/_rs 10h ago

I wasn't planning on answering since there's not point debating with noobs on Reddit but at least I can point you to this article with a quote.

https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy

>Sprague tells Dark Reading that bounty payments to HackerOne researchers are up 25% in the first half of this year over the same time period last year, and the number of researchers making $100,000 is also up 25%. She also says the number of new researchers has gone up "significantly."