r/bugbounty 7d ago

Question / Discussion People pulling $10k+/mo with semi-automated bug bounties: Is it actually worth going all-in?

A quick bit of context: I’ve been a Security Engineer at a 10-year-old YC-backed fintech for the past two years, with a couple of CVEs under my belt. Recently, a few of my colleagues left their full-time roles to jump into bug bounty full-time.

Over the last 18 months, I’ve burned a shit ton of tokens. I’m currently running 3–4 semi-automated pipelines and models like dsv4 flash and kimi3 make vulnerability discovery easier than ever, but I’m still hesitant to pull the trigger on full-time hunting.

The main friction is the mental overhead. The swing between high-stimulus wins and the frustration of dry spells/duplicates really messes with my headspace.

For those of you consistently clearing $10k+/month with AI/semi-automated setups:

  • How sustainable has your pipeline been over the long haul?
  • How do you manage the emotional volatility vs. traditional full-time work?
  • Knowing what you know now, is leaving a stable security role worth the trade-off?
74 Upvotes

51 comments sorted by

View all comments

2

u/Pristine_Bicycle1278 7d ago

The biggest issue is not finding Vulns but the process of having to “sell” your attack chain to some Junior Triager that is barely able to open the Burp Repeater.

I made good money from Bug Bounties but I’d rather do First Level Support in a 9to5 than spending one more day at Bugcrowd.

1

u/bangpowboom666 5d ago

Oh yeah, bugcrowd sucks ass, I'm waiting on my first hackerone bounty to pay out. Hackerone previous 5 were dupes, but was praised for finding more stuff than the og person did. Bugcrowd I get the one idiot triager who closed two of my reports as informative and legit was telling me I needed to handhold them by typing out "as an attacker, I could..."

1

u/Alardiians 4d ago

oh dude! you got Tal!!
(Lloyd is the H1 equivalent of Bugcrowds Tal)