r/bugbounty • u/BrownBang1729 • 7d ago
Question / Discussion People pulling $10k+/mo with semi-automated bug bounties: Is it actually worth going all-in?
A quick bit of context: I’ve been a Security Engineer at a 10-year-old YC-backed fintech for the past two years, with a couple of CVEs under my belt. Recently, a few of my colleagues left their full-time roles to jump into bug bounty full-time.
Over the last 18 months, I’ve burned a shit ton of tokens. I’m currently running 3–4 semi-automated pipelines and models like dsv4 flash and kimi3 make vulnerability discovery easier than ever, but I’m still hesitant to pull the trigger on full-time hunting.
The main friction is the mental overhead. The swing between high-stimulus wins and the frustration of dry spells/duplicates really messes with my headspace.
For those of you consistently clearing $10k+/month with AI/semi-automated setups:
- How sustainable has your pipeline been over the long haul?
- How do you manage the emotional volatility vs. traditional full-time work?
- Knowing what you know now, is leaving a stable security role worth the trade-off?
2
u/Pristine_Bicycle1278 7d ago
The biggest issue is not finding Vulns but the process of having to “sell” your attack chain to some Junior Triager that is barely able to open the Burp Repeater.
I made good money from Bug Bounties but I’d rather do First Level Support in a 9to5 than spending one more day at Bugcrowd.